{
    "summary": {
        "snap": {
            "added": [],
            "removed": [],
            "diff": []
        },
        "deb": {
            "added": [
                "libproc2-1:ppc64el",
                "libssl4:ppc64el",
                "libtss2-esys-3.0.2-0t64:ppc64el",
                "libtss2-mu-4.0.1-0t64:ppc64el",
                "libtss2-rc0t64:ppc64el",
                "libtss2-sys1t64:ppc64el",
                "libtss2-tcti-cmd0t64:ppc64el",
                "libtss2-tcti-device0t64:ppc64el",
                "libtss2-tcti-mssim0t64:ppc64el",
                "libtss2-tcti-swtpm0t64:ppc64el",
                "linux-headers-7.2.0-5",
                "linux-headers-7.2.0-5-generic",
                "linux-image-7.2.0-5-generic",
                "linux-main-modules-zfs-7.2.0-5-generic",
                "linux-modules-7.2.0-5-generic",
                "linux-tools-7.2.0-5",
                "linux-tools-7.2.0-5-generic",
                "python3-charset-normalizer",
                "sqv",
                "tpm-udev"
            ],
            "removed": [
                "busybox-initramfs",
                "linux-headers-7.0.0-14",
                "linux-headers-7.0.0-14-generic",
                "linux-image-7.0.0-14-generic",
                "linux-main-modules-zfs-7.0.0-14-generic",
                "linux-modules-7.0.0-14-generic",
                "linux-tools-7.0.0-14",
                "linux-tools-7.0.0-14-generic"
            ],
            "diff": [
                "adduser",
                "apparmor",
                "apport",
                "apport-core-dump-handler",
                "appstream",
                "apt",
                "bash",
                "bind9-dnsutils",
                "bind9-host",
                "bind9-libs:ppc64el",
                "bpftool",
                "btrfs-progs",
                "busybox-static",
                "ca-certificates",
                "chrony",
                "coreutils",
                "coreutils-from-uutils",
                "cpio",
                "cryptsetup",
                "cryptsetup-bin",
                "debianutils",
                "dhcpcd-base",
                "dirmngr",
                "distro-info-data",
                "dracut",
                "dracut-core",
                "dracut-install",
                "dracut-network",
                "ethtool",
                "exfatprogs",
                "ftp",
                "gcc-16-base:ppc64el",
                "gettext-base",
                "gir1.2-girepository-3.0:ppc64el",
                "gir1.2-glib-2.0:ppc64el",
                "git",
                "git-man",
                "gnu-coreutils",
                "gnupg",
                "gnupg-l10n",
                "gnupg-utils",
                "gpg",
                "gpg-agent",
                "gpg-wks-client",
                "gpgconf",
                "gpgsm",
                "gpgv",
                "htop",
                "initramfs-tools-bin",
                "initramfs-tools-core",
                "jq",
                "kmod",
                "kpartx",
                "krb5-locales",
                "libapparmor1:ppc64el",
                "libappstream5:ppc64el",
                "libapt-pkg7.0:ppc64el",
                "libatomic1:ppc64el",
                "libbrotli1:ppc64el",
                "libbytesize-common",
                "libbytesize1:ppc64el",
                "libc-bin",
                "libc-dev-bin",
                "libc-gconv-modules-extra:ppc64el",
                "libc6:ppc64el",
                "libc6-dev:ppc64el",
                "libcrypt1:ppc64el",
                "libcryptsetup12:ppc64el",
                "libevent-core-2.1-7t64:ppc64el",
                "libexpat1:ppc64el",
                "libffi8:ppc64el",
                "libfido2-1:ppc64el",
                "libfreetype6:ppc64el",
                "libgcc-s1:ppc64el",
                "libgirepository-2.0-0:ppc64el",
                "libglib2.0-0t64:ppc64el",
                "libglib2.0-bin",
                "libglib2.0-data",
                "libgnutls30t64:ppc64el",
                "libgssapi-krb5-2:ppc64el",
                "libgstreamer1.0-0:ppc64el",
                "libisns0t64:ppc64el",
                "libjq1:ppc64el",
                "libjs-sphinxdoc",
                "libk5crypto3:ppc64el",
                "libkmod2:ppc64el",
                "libkrb5-3:ppc64el",
                "libkrb5support0:ppc64el",
                "libldap-common",
                "libldap2:ppc64el",
                "libmpathcmd0",
                "libmpathpersist0",
                "libmultipath0",
                "libncurses6:ppc64el",
                "libncursesw6:ppc64el",
                "libnetplan1:ppc64el",
                "libnghttp2-14:ppc64el",
                "libnss-systemd:ppc64el",
                "libnss3:ppc64el",
                "libnvme1t64:ppc64el",
                "libopeniscsiusr",
                "libp11-kit0:ppc64el",
                "libpam-systemd:ppc64el",
                "libpcap0.8t64:ppc64el",
                "libplymouth5:ppc64el",
                "libpsl5t64:ppc64el",
                "libsasl2-2:ppc64el",
                "libsasl2-modules:ppc64el",
                "libsasl2-modules-db:ppc64el",
                "libselinux1:ppc64el",
                "libsemanage-common",
                "libsemanage2:ppc64el",
                "libsqlite3-0:ppc64el",
                "libssh2-1t64:ppc64el",
                "libstdc++6:ppc64el",
                "libsystemd-shared:ppc64el",
                "libsystemd0:ppc64el",
                "libtinfo6:ppc64el",
                "libudev1:ppc64el",
                "libudisks2-0:ppc64el",
                "linux-base",
                "linux-headers-generic",
                "linux-headers-virtual",
                "linux-image-virtual",
                "linux-libc-dev:ppc64el",
                "linux-perf",
                "linux-sysctl-defaults",
                "linux-tools-common",
                "linux-virtual",
                "locales",
                "multipath-tools",
                "ncurses-base",
                "ncurses-bin",
                "ncurses-term",
                "netplan-generator",
                "netplan.io",
                "open-iscsi",
                "openssh-client",
                "openssh-server",
                "openssh-sftp-server",
                "openssl",
                "openssl-provider-legacy",
                "os-prober",
                "plymouth",
                "plymouth-theme-ubuntu-text",
                "procps",
                "publicsuffix",
                "python3-apport",
                "python3-certifi",
                "python3-click",
                "python3-distupgrade",
                "python3-gi",
                "python3-httplib2",
                "python3-idna",
                "python3-jinja2",
                "python3-jsonpatch",
                "python3-lazr.restfulclient",
                "python3-magic",
                "python3-markupsafe",
                "python3-more-itertools",
                "python3-netplan",
                "python3-packaging",
                "python3-pexpect",
                "python3-problem-report",
                "python3-pygments",
                "python3-requests",
                "python3-urllib3",
                "rsync",
                "rsyslog",
                "rust-coreutils",
                "strace",
                "sudo",
                "sudo-rs",
                "systemd",
                "systemd-cryptsetup",
                "systemd-resolved",
                "systemd-sysv",
                "tcpdump",
                "thin-provisioning-tools",
                "tmux",
                "tnftp",
                "ubuntu-kernel-accessories",
                "ubuntu-keyring",
                "ubuntu-minimal",
                "ubuntu-release-upgrader-core",
                "ubuntu-server",
                "ubuntu-standard",
                "udev",
                "udisks2",
                "update-notifier-common",
                "wget",
                "wireless-regdb"
            ]
        }
    },
    "diff": {
        "deb": [
            {
                "name": "adduser",
                "from_version": {
                    "source_package_name": "adduser",
                    "source_package_version": "3.153ubuntu1",
                    "version": "3.153ubuntu1"
                },
                "to_version": {
                    "source_package_name": "adduser",
                    "source_package_version": "3.157ubuntu1",
                    "version": "3.157ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153280
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153280). Remaining changes:",
                            "    - extrausers support for adduser and gpasswd (LP #1323732)",
                            "    - Add support for ZFS home directories (LP #1873263)",
                            "    - Enable private home directories by default (LP #48734)",
                            "      Set DIR_MODE=0750 and SYS_DIR_MODE=0750 in the default adduser.conf,",
                            "      and match those in the check_octal fallback for invalid values.",
                            "    Dropped changes:",
                            "    - Add support for encrypting home directories (MR: !87)",
                            "      (upstreamed in Debian 3.157)",
                            "    - Regenerate po4a translation catalogs (build artefacts)",
                            ""
                        ],
                        "package": "adduser",
                        "version": "3.157ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153280
                        ],
                        "author": "Nadzeya Hutsko <nadzeya@ubuntu.com>",
                        "date": "Mon, 13 Jul 2026 13:48:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Marc Haber ]",
                            "  * add script that runs the testsuite without autopkgtest",
                            "    (Closes: #1101457)",
                            "  * add a NOTE to adduser.8 regarding group membership (Closes: #1103776)",
                            "  * implement adduser --force-home.",
                            "    Thanks to Jeff Hanson (Closes: #472820)",
                            "  * Add new Romanian program and man page translation.",
                            "    Thanks to Remus-Gabriel Chelu (Closes: #1137603, #1137602)",
                            "  * update dutch program translation.",
                            "    Thanks to Frans Spiesschaert (Closes: #1118210, #1133696)",
                            "",
                            "  [ Dustin Kirkland ]",
                            "  * Add support for encrypting home directories",
                            "    * adduser: Add --encrypt-home option, which calls ecryptfs-setup-private",
                            "      for the hard work.",
                            "    * doc/adduser.8: document the --encrypt-home option",
                            "    * debian/control: suggest ecryptfs-utils >= 67-1",
                            "    * deluser: remove all of /var/lib/ecryptfs/$user with --remove-home",
                            "",
                            "  [ Mateus Rodrigues de Morais ]",
                            "  * Add encrypted home tests with isolation-machine restriction",
                            ""
                        ],
                        "package": "adduser",
                        "version": "3.157",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Haber <mh+debian-packages@zugschlus.de>",
                        "date": "Wed, 17 Jun 2026 22:36:50 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * ignore extra fields at the end of pool file lines",
                            "  * streamline log level names. (Closes: #1132881)",
                            "  * demote \"crontab not found\" warning to info",
                            "    it is now perfectly normal to run a system that doesn't have cron",
                            ""
                        ],
                        "package": "adduser",
                        "version": "3.156",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Haber <mh+debian-packages@zugschlus.de>",
                        "date": "Mon, 01 Jun 2026 07:06:57 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Marc Haber ]",
                            "  * remove GROUPHOMES and LETTERHOMES configuration options",
                            "  * remove SETGID_HOME configuration option",
                            "  * remove deprecated QUOTAUSER configuration option",
                            "  * remove debian/tests/f/cronjack.t",
                            "    useradd won't allow adding that user name any more",
                            "  * Depend on passwd 1:4.19.0-2. Remove cronjack.t test",
                            "    (Closes: #1124993)",
                            "  * Give chpasswd test values that it will accept (Closes: 1124992)",
                            "  * give Matt's work on existing_*_ okay another simplifying brush-up",
                            "  * po: Add Georgian translation.",
                            "    Thanks to Temuri Doghonadze",
                            "  * allow /etc/skel to contain files with UTF-8 file names.",
                            "    This moves home dir creation to a new module AdduserCreateHomedir",
                            "    Thanks to Mert Ok (Closes: #1125681)",
                            "  * copy over find_unused_* functions from upstream testsuites",
                            "    (Closes: #1015781)",
                            "  * man page improvements for adduser.8.",
                            "    Thanks to Bjarni Ingi Gislason (Closes: #1124790)",
                            "  * apply correcting patch from #1105900.",
                            "    Thanks to Bjarni Ingi Gislason (Closes: #1105900)",
                            "  * write test cases to trigger #1125601",
                            "  * Updated German man page translation.",
                            "    Thanks to Helge Kreutzmann (Closes: #1125135)",
                            "  * Updated Portuguese man page and program translation.",
                            "    Thanks to Américo Monteiro (Closes: #1118370)",
                            "  * Updated Dutch man page translation.",
                            "    Thanks to Frans Spiesschaert (Closes: #1118209)",
                            "",
                            "  [ Matt Barry ]",
                            "  * Add adduser --unlock [--system] and deluser --lock [--system]",
                            "    (Closes: #1008082, #1008083, #1008084)",
                            ""
                        ],
                        "package": "adduser",
                        "version": "3.155",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Haber <mh+debian-packages@zugschlus.de>",
                        "date": "Sat, 28 Mar 2026 10:16:28 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * The Happy New Year 2026 Release",
                            "",
                            "  [ Matt Barry ]",
                            "  * add --no-copy-skel option (Closes: #1099633)",
                            "  * document --no-copy-skel",
                            "  * refactor existing_*_ok",
                            "",
                            "  [ Marc Haber ]",
                            "  * make deluser --group work as documented.",
                            "  * have delgroup reject user-specific command line options.",
                            "  * correctly sanitize names in deluser.",
                            "    Thanks to Dagfinn Ilmari Mannsåker (Closes: #1109329)",
                            "  * update Swedish program and man page translation.",
                            "    Thanks to Daniel Nylander <daniel@danielnylander.se>",
                            "  * make adduser error out if --system and account has a password",
                            "    (Closes: #1099734)",
                            ""
                        ],
                        "package": "adduser",
                        "version": "3.154",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Haber <mh+debian-packages@zugschlus.de>",
                        "date": "Thu, 01 Jan 2026 00:00:10 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "apparmor",
                "from_version": {
                    "source_package_name": "apparmor",
                    "source_package_version": "5.0.2-0ubuntu1",
                    "version": "5.0.2-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "apparmor",
                    "source_package_version": "6.0.0~alpha1-0ubuntu1",
                    "version": "6.0.0~alpha1-0ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * debian/control: add iwyu, pytest, pytest-xdist to Build-Depends",
                            "  * Drop patches that were applied upstream:",
                            "    - d/p/u/0001-parser-add-more-reserved-mediation-classes.patch",
                            "  * Refresh patches for new release:",
                            "    - d/p/u/0007-Set-parser-network.h-ip_conds-ptrs-to-null-in-its-fr.patch",
                            "  * Update patches for new release:",
                            "    - d/p/u/profiles-use-coreutils-tunable.patch",
                            "    - d/p/u/profiles_add_more_consoles_workaround.patch",
                            "    - d/p/u/profiles_disable_free.patch",
                            "  * Add patches to install a confining loupe profile:",
                            "    - d/p/u/0001-profiles-add-a-glycin-tunable.patch",
                            "    - d/p/u/0002-profiles-begin-adding-abstractions-for-the-XDG-Deskt.patch",
                            "    - d/p/u/0003-profiles-rewrite-the-loupe-profile.patch",
                            "  * debian/apparmor.install: add glycin tunables",
                            ""
                        ],
                        "package": "apparmor",
                        "version": "6.0.0~alpha1-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ryan Lee <ryan.lee@canonical.com>",
                        "date": "Thu, 20 Aug 2026 12:05:00 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "apport",
                "from_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.35.0-0ubuntu2",
                    "version": "2.35.0-0ubuntu2"
                },
                "to_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.36.0-0ubuntu1",
                    "version": "2.36.0-0ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-77113",
                        "url": "https://ubuntu.com/security/CVE-2026-77113",
                        "cve_description": "",
                        "cve_priority": "n/a",
                        "cve_public_date": ""
                    }
                ],
                "launchpad_bugs_fixed": [
                    2161697,
                    2163744,
                    2109979,
                    2156405
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-77113",
                                "url": "https://ubuntu.com/security/CVE-2026-77113",
                                "cve_description": "",
                                "cve_priority": "n/a",
                                "cve_public_date": ""
                            }
                        ],
                        "log": [
                            "",
                            "  [ Benjamin Drung ]",
                            "  * New upstream release.",
                            "    - SECURITY UPDATE: path traversal during report extraction (LP: #2161697)",
                            "      + problem_report: validate key names in ProblemReport.load",
                            "      + CVE-2026-77113",
                            "    - apport_python_hook: support dbus-broker (LP: #2163744)",
                            "    - Fix partial writes for coredumps larger than 2 GiB (LP: #2109979)",
                            "  * autopkgtest: remove unneeded dirmngr dependency",
                            "  * Drop patches applied upstream and refresh remaining patches",
                            "  * python3-apport: Tighten python3-problem-report dependency to >= 2.36",
                            "  * Let python3-problem-report break apport << 2.36 (for apport-unpack)",
                            "",
                            "  [ Kat Kuo ]",
                            "  * oem-getlogs: Remove Ubuntu Report call and get DCD directly (LP: #2156405)",
                            ""
                        ],
                        "package": "apport",
                        "version": "2.36.0-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161697,
                            2163744,
                            2109979,
                            2156405
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 16:48:31 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "apport-core-dump-handler",
                "from_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.35.0-0ubuntu2",
                    "version": "2.35.0-0ubuntu2"
                },
                "to_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.36.0-0ubuntu1",
                    "version": "2.36.0-0ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-77113",
                        "url": "https://ubuntu.com/security/CVE-2026-77113",
                        "cve_description": "",
                        "cve_priority": "n/a",
                        "cve_public_date": ""
                    }
                ],
                "launchpad_bugs_fixed": [
                    2161697,
                    2163744,
                    2109979,
                    2156405
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-77113",
                                "url": "https://ubuntu.com/security/CVE-2026-77113",
                                "cve_description": "",
                                "cve_priority": "n/a",
                                "cve_public_date": ""
                            }
                        ],
                        "log": [
                            "",
                            "  [ Benjamin Drung ]",
                            "  * New upstream release.",
                            "    - SECURITY UPDATE: path traversal during report extraction (LP: #2161697)",
                            "      + problem_report: validate key names in ProblemReport.load",
                            "      + CVE-2026-77113",
                            "    - apport_python_hook: support dbus-broker (LP: #2163744)",
                            "    - Fix partial writes for coredumps larger than 2 GiB (LP: #2109979)",
                            "  * autopkgtest: remove unneeded dirmngr dependency",
                            "  * Drop patches applied upstream and refresh remaining patches",
                            "  * python3-apport: Tighten python3-problem-report dependency to >= 2.36",
                            "  * Let python3-problem-report break apport << 2.36 (for apport-unpack)",
                            "",
                            "  [ Kat Kuo ]",
                            "  * oem-getlogs: Remove Ubuntu Report call and get DCD directly (LP: #2156405)",
                            ""
                        ],
                        "package": "apport",
                        "version": "2.36.0-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161697,
                            2163744,
                            2109979,
                            2156405
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 16:48:31 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "appstream",
                "from_version": {
                    "source_package_name": "appstream",
                    "source_package_version": "1.1.5-1",
                    "version": "1.1.5-1"
                },
                "to_version": {
                    "source_package_name": "appstream",
                    "source_package_version": "1.1.6-1",
                    "version": "1.1.6-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version: 1.1.6",
                            "  * Update symbols file",
                            ""
                        ],
                        "package": "appstream",
                        "version": "1.1.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klumpp <mak@debian.org>",
                        "date": "Wed, 12 Aug 2026 16:32:34 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "apt",
                "from_version": {
                    "source_package_name": "apt",
                    "source_package_version": "3.2.0",
                    "version": "3.2.0"
                },
                "to_version": {
                    "source_package_name": "apt",
                    "source_package_version": "3.3.3",
                    "version": "3.3.3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158000,
                    2150631
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  This release introduces initial interactive help output for apt(8)",
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * cmdline: add declarative option help printer",
                            "  * mirror: Scale fan-out with the square root of the number of files",
                            "",
                            "  [ Simon Johnsson ]",
                            "  * cmdline: add command-specific help texts",
                            "",
                            "  [ Zara Grigoryan ]",
                            "  * cmdline: render declarative options in command help",
                            "  * cmdline: mark option descriptions for translation",
                            "  * cmdline: refine command-specific help rendering",
                            "",
                            "  [ Andriy Pysyk ]",
                            "  * Fix fuzzy entries in Ukrainian translation for APT 3.3.2 + terminology consistency improvements",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Fri, 14 Aug 2026 17:51:56 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * Document and test combined `build-dep --arch-only --indep-only`",
                            "  * ftparchive: fix heap overflow in ContentsExtract::DoItem",
                            "  * deb: guard against unsigned underflow when trimming control newlines",
                            "  * gpgv: don't advance past the null terminator in PushEntryWithKeyID",
                            "  * ftparchive: replace ContentsExtract's manual buffer with std::vector<char>",
                            "  * test: Limit valgrind to 1024 open files",
                            "  * hashes: Fix lingering OpenSSL error (Closes: #1140227)",
                            "  * test: use `gnurm` where available",
                            "  * Convert command-line option-parsing to declarative format",
                            "  * Fix crash when an aux file request is redirected",
                            "  * Reply to aux requests with the original URI if redirected",
                            "  * debian/apt-daily.service: Add timeouts.",
                            "    30 mins for apt-daily.service, 12 hours for apt-daily-upgrade.service",
                            "    should be sufficient. (LP: #2158000)",
                            "",
                            "  [ наб ]",
                            "  * apt-transport-https(1): document host-specific SSLCert, SSLKey, Verify-Host with host:: instead of ::host",
                            "",
                            "  [ David Kalnischkies ]",
                            "  * aptwebserver: Refuse client immediately on TLS handshake",
                            "",
                            "  [ Américo Monteiro ]",
                            "  * Portuguese manpages translation update (Closes: #1133965)",
                            "",
                            "  [ Frans Spiesschaert ]",
                            "  * Dutch program translation update (Closes: #1135221)",
                            "  * Dutch manpages translation update (Closes: #1135222)",
                            "",
                            "  [ Remus-Gabriel Chelu ]",
                            "  * Romanian program translation update (Closes: #1139336)",
                            "",
                            "  [ Mark Atwood ]",
                            "  * hashes: include <span> for std::span",
                            "  * hashes: don't crash on an unavailable digest",
                            "  * test: exercise hashes with a disabled digest",
                            "",
                            "  [ dongshengyuan ]",
                            "  * Fix installing a deb with colon in path",
                            "",
                            "  [ Simon Johnsson ]",
                            "  * apt-pkg: rename \"OpenPGP signature verification failed\" to \"Signature verification failed\"",
                            "",
                            "  [ Andreas Noteng ]",
                            "  * Norwegian Bokmål (nb) translation update",
                            "",
                            "  [ Temuri Doghonadze ]",
                            "  * po: Add Georgian translation",
                            "",
                            "  [ Andriy Pysyk ]",
                            "  * Update Ukrainian translation for 3.3.1",
                            "",
                            "  [ Mikhail Khachayants ]",
                            "  * srvrec: reject res_query answers bigger than our buffer",
                            "",
                            "  [ Ramesh Adhikari ]",
                            "  * tagfile: fix unbounded backward scan in Fill()'s trailing-newline check",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2158000
                        ],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 22:43:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * solver3: Follow installed Suggests earlier",
                            "  * Fix `noexcept` as pointed out by gcc",
                            "  * Fix wrongful std::make_unique conversion",
                            "  * Fix regression in dirstream (Closes: #1136441)",
                            "",
                            "  [ Varun Varma ]",
                            "  * Warn if auth.conf is unreadable (LP: #2150631)",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2150631
                        ],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Sun, 17 May 2026 21:21:50 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Anders Kaseorg ]",
                            "  * Fix Phased-Update-Percentage probability mistake",
                            "",
                            "  [ Simon Johnsson ]",
                            "  * Scale history-list to screen width",
                            "  * Optimize ShortenCommand",
                            "  * Change GetKindString to not use .data() call",
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * Drop warning about unstable CLI interface.",
                            "    A specific CLI version can now be requested using the --cli-version",
                            "    flag, and old versions can be deprecated on a reasonable cadence.",
                            "    Therefore, a warning is no longer necessary.",
                            "  * hashes: Use std::span instead of std::basic_string_view",
                            "  * sources.list(5): Document Contact/Bugs/Description fields.",
                            "    Thanks to josch for the suggestion",
                            "  * Require sqv for builds on supported archs and !pkg.apt.nosqv",
                            "",
                            "  [ Zheyu Shen ]",
                            "  * fix apt patterns parsing bug for pre-depends",
                            "",
                            "  [ Herman Semenoff ]",
                            "  * apt: funcs called with a string literal consisting of a single character",
                            "  * apt-pkg/acquire: use range based for loop C++17",
                            "  * apt: push to emplace C++11 if possible",
                            "  * apt: modernize to make_unique C++17",
                            "  * apt-pkg: methods: fixed many minor memleaks",
                            "",
                            "  [ наб ]",
                            "  * sources.list(5): th[r]ough typo",
                            "",
                            "  [ Sebastian Krzyszkowiak ]",
                            "  * acquire-item: Fix up the error message on committing aborted transaction",
                            "  * pkgAcqMetaClearSig: Abort transaction when pkgAcquire::Run has been cancelled",
                            "    (Closes: #1078608)",
                            "  * pkgAcqMetaBase: Commit InRelease after other transaction items",
                            "    (Closes: #1078608)",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Fix bug reference",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.0",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Fri, 01 May 2026 18:40:52 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "bash",
                "from_version": {
                    "source_package_name": "bash",
                    "source_package_version": "5.3-2ubuntu1",
                    "version": "5.3-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "bash",
                    "source_package_version": "5.3-3ubuntu1",
                    "version": "5.3-3ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153285
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable (LP: #2153285). Remaining changes:",
                            "    - d/skel.bashrc: Run lesspipe.",
                            "    - d/skel.bashrc: Enable ls aliases.",
                            "    - d/skel.bashrc: Set options in ll alias to -alF.",
                            "    - d/skel.bashrc: Define an alert alias.",
                            "    - d/skel.bashrc: Enable colored grep aliases.",
                            "    - d/p/deb-bash-config.diff: Set the default path to comply with",
                            "      Debian policy.",
                            "    - d/tests: Add autopkgtest for the built-in path.",
                            "    - d/rules: Use /usr/bin/bash as SHELL.",
                            ""
                        ],
                        "package": "bash",
                        "version": "5.3-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153285
                        ],
                        "author": "Zineb Zaadoud <zineb.zaadoud@canonical.com>",
                        "date": "Mon, 10 Aug 2026 11:37:44 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Build with -O1 on sh4 (Adrian Glaubitz). Addresses: #1130485.",
                            ""
                        ],
                        "package": "bash",
                        "version": "5.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 03 May 2026 21:28:45 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "bind9-dnsutils",
                "from_version": {
                    "source_package_name": "bind9",
                    "source_package_version": "1:9.20.23-1ubuntu1",
                    "version": "1:9.20.23-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "bind9",
                    "source_package_version": "1:9.20.24-1ubuntu3",
                    "version": "1:9.20.24-1ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-10723",
                        "url": "https://ubuntu.com/security/CVE-2026-10723",
                        "cve_description": "BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-10822",
                        "url": "https://ubuntu.com/security/CVE-2026-10822",
                        "cve_description": "If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit.  BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11331",
                        "url": "https://ubuntu.com/security/CVE-2026-11331",
                        "cve_description": "An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11605",
                        "url": "https://ubuntu.com/security/CVE-2026-11605",
                        "cve_description": "The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11622",
                        "url": "https://ubuntu.com/security/CVE-2026-11622",
                        "cve_description": "A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11721",
                        "url": "https://ubuntu.com/security/CVE-2026-11721",
                        "cve_description": "It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-12617",
                        "url": "https://ubuntu.com/security/CVE-2026-12617",
                        "cve_description": "The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. Or, if a client queries for a CNAME and A record for the same name to the resolver, and the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME, the same failure may occur. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-13204",
                        "url": "https://ubuntu.com/security/CVE-2026-13204",
                        "cve_description": "If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-13321",
                        "url": "https://ubuntu.com/security/CVE-2026-13321",
                        "cve_description": "The BIND resolver accepts validly-signed NSEC records where the \"Next Domain Name\" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2157486
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-10723",
                                "url": "https://ubuntu.com/security/CVE-2026-10723",
                                "cve_description": "BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-10822",
                                "url": "https://ubuntu.com/security/CVE-2026-10822",
                                "cve_description": "If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit.  BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11331",
                                "url": "https://ubuntu.com/security/CVE-2026-11331",
                                "cve_description": "An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11605",
                                "url": "https://ubuntu.com/security/CVE-2026-11605",
                                "cve_description": "The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11622",
                                "url": "https://ubuntu.com/security/CVE-2026-11622",
                                "cve_description": "A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11721",
                                "url": "https://ubuntu.com/security/CVE-2026-11721",
                                "cve_description": "It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-12617",
                                "url": "https://ubuntu.com/security/CVE-2026-12617",
                                "cve_description": "The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. Or, if a client queries for a CNAME and A record for the same name to the resolver, and the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME, the same failure may occur. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-13204",
                                "url": "https://ubuntu.com/security/CVE-2026-13204",
                                "cve_description": "If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-13321",
                                "url": "https://ubuntu.com/security/CVE-2026-13321",
                                "cve_description": "The BIND resolver accepts validly-signed NSEC records where the \"Next Domain Name\" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Incorrect acceptance of NSEC3 records",
                            "    - debian/patches/CVE-2026-10723-1.patch: Check NSEC3 signer matches the",
                            "      owning zone in lib/dns/dnssec.c, lib/isc/result.c.",
                            "    - debian/patches/CVE-2026-10723-2.patch: Reproducer for #5874 NSEC3",
                            "      impersonation in bin/tests/system/repro_5874_nsec3_parent/ans1/ans.py,",
                            "      bin/tests/system/repro_5874_nsec3_parent/ns2/named.conf.j2,",
                            "      bin/tests/system/repro_5874_nsec3_parent/server.py,",
                            "      bin/tests/system/repro_5874_nsec3_parent/tests_repro_5874_nsec3_parent.py.",
                            "    - debian/patches/CVE-2026-10723-3.patch: Update reproducer #5874 in",
                            "      bin/tests/system/nsec3_impersonation/ans1/ans.py,",
                            "      bin/tests/system/nsec3_impersonation/ns2/named.conf.j2,",
                            "      bin/tests/system/nsec3_impersonation/tests_nsec3_impersonation.py.",
                            "    - CVE-2026-10723",
                            "  * SECURITY UPDATE: Key Record using PRIVATEDNS algorithm may lead to",
                            "    unexpected exit",
                            "    - debian/patches/CVE-2026-10822-1.patch: Check that dns_name_fromwire",
                            "      honours the active region in tests/dns/name_test.c.",
                            "    - debian/patches/CVE-2026-10822-2.patch: Fix the yaml query zone name code",
                            "      in dnstap-read in bin/tools/dnstap-read.c.",
                            "    - debian/patches/CVE-2026-10822-3.patch: Fix dns_name_fromwire to honour the",
                            "      active region in lib/dns/name.c.",
                            "    - debian/patches/CVE-2026-10822-4.patch: Make it clearer that decompression",
                            "      is not allowed here in lib/dns/rdata.c.",
                            "    - debian/patches/CVE-2026-10822-5.patch: Check that a short PRIVATEDNS",
                            "      record is rejected in tests/dns/rdata_test.c.",
                            "    - CVE-2026-10822",
                            "  * SECURITY UPDATE: Potential wildcard CNAME RPZ policy bypass",
                            "    - debian/patches/CVE-2026-11331-1.patch: Fix TTL extraction from A/AAAA",
                            "      record in bin/tests/system/rpz/tests.sh.",
                            "    - debian/patches/CVE-2026-11331-2.patch: Check rpz name too long wildcard",
                            "      CNAME expansion handling in bin/tests/system/rpz/ns2/tld2.db,",
                            "      bin/tests/system/rpz/ns4/tld4.db, bin/tests/system/rpz/tests.sh.",
                            "    - debian/patches/CVE-2026-11331-3.patch: Properly handle rpz name to long",
                            "      wildcard expansion in lib/ns/query.c.",
                            "    - CVE-2026-11331",
                            "  * SECURITY UPDATE: Unnecessary validation of DNSSEC signed records",
                            "    - debian/patches/CVE-2026-11605-1.patch: Limit DNSSEC denial proof",
                            "      validation per fetch in lib/dns/validator.c.",
                            "    - CVE-2026-11605",
                            "  * SECURITY UPDATE: Potential memory usage beyond configured limits",
                            "    - debian/patches/CVE-2026-11622.patch: Make the dns_slabheaders in the cache",
                            "      reference counted in bin/tests/system/reclimit/tests.sh,",
                            "      lib/dns/include/dns/rdataslab.h, lib/dns/qpcache.c, lib/dns/qpzone.c,",
                            "      lib/dns/rbt-cachedb.c, lib/dns/rbtdb.c, lib/dns/rbtdb_p.h,",
                            "      lib/dns/rdataslab.c.",
                            "    - CVE-2026-11622",
                            "  * SECURITY UPDATE: Cache poisoning possible with label count discrepancy,",
                            "    RRSIG, and wildcards",
                            "    - debian/patches/CVE-2026-11721-1.patch: Don't sign out of zone records in",
                            "      dnssec-signzone in bin/dnssec/dnssec-signzone.c.",
                            "    - debian/patches/CVE-2026-11721-2.patch: Invalid signed wildcard records",
                            "      were being accepted in lib/dns/dnssec.c, lib/dns/rdata/generic/rrsig_46.c.",
                            "    - debian/patches/CVE-2026-11721-3.patch: Test RRSIG record parsing in",
                            "      tests/dns/rdata_test.c.",
                            "    - CVE-2026-11721",
                            "  * SECURITY UPDATE:Record ordering based unexpected exit with CNAME or DNAME",
                            "    - debian/patches/CVE-2026-12617-1.patch: Do not assert in some CNAME/DNAME",
                            "      queries in lib/dns/resolver.c.",
                            "    - debian/patches/CVE-2026-12617-2.patch: Reproducer for #5946 (assertion in",
                            "      some CNAME/DNAME queries) in",
                            "      bin/tests/system/cname_dname_negcache/ans2/ans.py,",
                            "      bin/tests/system/cname_dname_negcache/ns1/bar.test.db,",
                            "      bin/tests/system/cname_dname_negcache/ns1/named.conf.j2,",
                            "      bin/tests/system/cname_dname_negcache/ns1/root.db,",
                            "      bin/tests/system/cname_dname_negcache/ns1/test.db,",
                            "      bin/tests/system/cname_dname_negcache/ns3/named.conf.j2,",
                            "      bin/tests/system/cname_dname_negcache/tests_cname_dname_negcache.py.",
                            "    - CVE-2026-12617",
                            "  * SECURITY UPDATE: Unexpected exit in certain situations with NSEC and NSEC3",
                            "    both present",
                            "    - debian/patches/CVE-2026-13204-1.patch: dns_rdataset_addnoqname() could",
                            "      find unsigned NSEC/NSEC3 in lib/dns/qpcache.c, lib/dns/rbtdb.c,",
                            "      lib/dns/rdatalist.c, lib/dns/resolver.c, lib/ns/query.c.",
                            "    - debian/patches/CVE-2026-13204-2.patch: Reproducer for #5985 addnoqname",
                            "      mismatch in",
                            "      bin/tests/system/repro_5985_findnoqname_runtime_check/ans1/ans.py,",
                            "      bin/tests/system/repro_5985_findnoqname_runtime_check/ns2/named.conf.j2,",
                            "      bin/tests/system/repro_5985_findnoqname_runtime_check/server.py, bin/tests",
                            "      /system/repro_5985_findnoqname_runtime_check/tests_repro_5985_findnoqname_",
                            "      runtime_check.py.",
                            "    - debian/patches/CVE-2026-13204-3.patch: Update reproducer #5985 in",
                            "      bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py,",
                            "      bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2, bin/tests/",
                            "      system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py.",
                            "    - CVE-2026-13204",
                            "  * SECURITY UPDATE: Record ordering based unexpected exit with CNAME or DNAME",
                            "    - debian/patches/CVE-2026-13321-1.patch: Add system test for out-of-zone",
                            "      nsec dnssec bypass in bin/tests/system/dnssec_bypass/ns1/named.conf.j2,",
                            "      bin/tests/system/dnssec_bypass/ns1/root.db,",
                            "      bin/tests/system/dnssec_bypass/ns1/test.db,",
                            "      bin/tests/system/dnssec_bypass/ns2/named.conf.j2,",
                            "      bin/tests/system/dnssec_bypass/ns2/victim.db,",
                            "      bin/tests/system/dnssec_bypass/ns3/evil.db,",
                            "      bin/tests/system/dnssec_bypass/ns3/named.conf.j2,",
                            "      bin/tests/system/dnssec_bypass/ns4/named.conf.j2,",
                            "      bin/tests/system/dnssec_bypass/tests_bypass.py.",
                            "    - debian/patches/CVE-2026-13321-2.patch: Reject out-of-zone NSEC next owner",
                            "      names in lib/dns/dnssec.c, lib/dns/include/dns/dnssec.h.",
                            "    - debian/patches/CVE-2026-13321-3.patch: change",
                            "      dns_nsec_requiredtypespresent to dns_nsec_is_legal in",
                            "      lib/dns/include/dns/nsec.h, lib/dns/nsec.c, lib/dns/resolver.c,",
                            "      lib/ns/query.c.",
                            "    - CVE-2026-13321",
                            ""
                        ],
                        "package": "bind9",
                        "version": "1:9.20.24-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Mon, 31 Aug 2026 12:10:28 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "bind9",
                        "version": "1:9.20.24-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 10:28:57 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2157486). Remaining changes:",
                            "    - Don't build dnstap as it depends on universe packages:",
                            "      + d/control: drop build-depends on libfstrm-dev, libprotobuf-c-dev and",
                            "        protobuf-c-compiler",
                            "      + d/dnsutils.install: don't install dnstap",
                            "      + d/rules: don't build dnstap nor install dnstap.proto",
                            "    - Add back apport:",
                            "      + d/bind9.apport: add back old bind9 apport hook, but without calling",
                            "        attach_conffiles() since that is already done by apport itself, with",
                            "        confirmation from the user.",
                            "      + d/control, d/rules: build-depends on dh-apport and use it",
                            "    - d/NEWS: mention relevant packaging changes",
                            "    - d/e/apparmor.d/usr.sbin.named: Allow read access to",
                            "      /proc/version_signature for named (LP #2119320)",
                            ""
                        ],
                        "package": "bind9",
                        "version": "1:9.20.24-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2157486
                        ],
                        "author": "Lena Voytek <lena.voytek@canonical.com>",
                        "date": "Thu, 18 Jun 2026 12:22:05 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 9.20.24",
                            ""
                        ],
                        "package": "bind9",
                        "version": "1:9.20.24-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Ondřej Surý <ondrej@debian.org>",
                        "date": "Wed, 17 Jun 2026 14:43:58 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "bind9-host",
                "from_version": {
                    "source_package_name": "bind9",
                    "source_package_version": "1:9.20.23-1ubuntu1",
                    "version": "1:9.20.23-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "bind9",
                    "source_package_version": "1:9.20.24-1ubuntu3",
                    "version": "1:9.20.24-1ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-10723",
                        "url": "https://ubuntu.com/security/CVE-2026-10723",
                        "cve_description": "BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-10822",
                        "url": "https://ubuntu.com/security/CVE-2026-10822",
                        "cve_description": "If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit.  BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11331",
                        "url": "https://ubuntu.com/security/CVE-2026-11331",
                        "cve_description": "An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11605",
                        "url": "https://ubuntu.com/security/CVE-2026-11605",
                        "cve_description": "The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11622",
                        "url": "https://ubuntu.com/security/CVE-2026-11622",
                        "cve_description": "A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11721",
                        "url": "https://ubuntu.com/security/CVE-2026-11721",
                        "cve_description": "It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-12617",
                        "url": "https://ubuntu.com/security/CVE-2026-12617",
                        "cve_description": "The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. Or, if a client queries for a CNAME and A record for the same name to the resolver, and the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME, the same failure may occur. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-13204",
                        "url": "https://ubuntu.com/security/CVE-2026-13204",
                        "cve_description": "If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-13321",
                        "url": "https://ubuntu.com/security/CVE-2026-13321",
                        "cve_description": "The BIND resolver accepts validly-signed NSEC records where the \"Next Domain Name\" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2157486
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-10723",
                                "url": "https://ubuntu.com/security/CVE-2026-10723",
                                "cve_description": "BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-10822",
                                "url": "https://ubuntu.com/security/CVE-2026-10822",
                                "cve_description": "If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit.  BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11331",
                                "url": "https://ubuntu.com/security/CVE-2026-11331",
                                "cve_description": "An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11605",
                                "url": "https://ubuntu.com/security/CVE-2026-11605",
                                "cve_description": "The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11622",
                                "url": "https://ubuntu.com/security/CVE-2026-11622",
                                "cve_description": "A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11721",
                                "url": "https://ubuntu.com/security/CVE-2026-11721",
                                "cve_description": "It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-12617",
                                "url": "https://ubuntu.com/security/CVE-2026-12617",
                                "cve_description": "The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. Or, if a client queries for a CNAME and A record for the same name to the resolver, and the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME, the same failure may occur. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-13204",
                                "url": "https://ubuntu.com/security/CVE-2026-13204",
                                "cve_description": "If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-13321",
                                "url": "https://ubuntu.com/security/CVE-2026-13321",
                                "cve_description": "The BIND resolver accepts validly-signed NSEC records where the \"Next Domain Name\" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Incorrect acceptance of NSEC3 records",
                            "    - debian/patches/CVE-2026-10723-1.patch: Check NSEC3 signer matches the",
                            "      owning zone in lib/dns/dnssec.c, lib/isc/result.c.",
                            "    - debian/patches/CVE-2026-10723-2.patch: Reproducer for #5874 NSEC3",
                            "      impersonation in bin/tests/system/repro_5874_nsec3_parent/ans1/ans.py,",
                            "      bin/tests/system/repro_5874_nsec3_parent/ns2/named.conf.j2,",
                            "      bin/tests/system/repro_5874_nsec3_parent/server.py,",
                            "      bin/tests/system/repro_5874_nsec3_parent/tests_repro_5874_nsec3_parent.py.",
                            "    - debian/patches/CVE-2026-10723-3.patch: Update reproducer #5874 in",
                            "      bin/tests/system/nsec3_impersonation/ans1/ans.py,",
                            "      bin/tests/system/nsec3_impersonation/ns2/named.conf.j2,",
                            "      bin/tests/system/nsec3_impersonation/tests_nsec3_impersonation.py.",
                            "    - CVE-2026-10723",
                            "  * SECURITY UPDATE: Key Record using PRIVATEDNS algorithm may lead to",
                            "    unexpected exit",
                            "    - debian/patches/CVE-2026-10822-1.patch: Check that dns_name_fromwire",
                            "      honours the active region in tests/dns/name_test.c.",
                            "    - debian/patches/CVE-2026-10822-2.patch: Fix the yaml query zone name code",
                            "      in dnstap-read in bin/tools/dnstap-read.c.",
                            "    - debian/patches/CVE-2026-10822-3.patch: Fix dns_name_fromwire to honour the",
                            "      active region in lib/dns/name.c.",
                            "    - debian/patches/CVE-2026-10822-4.patch: Make it clearer that decompression",
                            "      is not allowed here in lib/dns/rdata.c.",
                            "    - debian/patches/CVE-2026-10822-5.patch: Check that a short PRIVATEDNS",
                            "      record is rejected in tests/dns/rdata_test.c.",
                            "    - CVE-2026-10822",
                            "  * SECURITY UPDATE: Potential wildcard CNAME RPZ policy bypass",
                            "    - debian/patches/CVE-2026-11331-1.patch: Fix TTL extraction from A/AAAA",
                            "      record in bin/tests/system/rpz/tests.sh.",
                            "    - debian/patches/CVE-2026-11331-2.patch: Check rpz name too long wildcard",
                            "      CNAME expansion handling in bin/tests/system/rpz/ns2/tld2.db,",
                            "      bin/tests/system/rpz/ns4/tld4.db, bin/tests/system/rpz/tests.sh.",
                            "    - debian/patches/CVE-2026-11331-3.patch: Properly handle rpz name to long",
                            "      wildcard expansion in lib/ns/query.c.",
                            "    - CVE-2026-11331",
                            "  * SECURITY UPDATE: Unnecessary validation of DNSSEC signed records",
                            "    - debian/patches/CVE-2026-11605-1.patch: Limit DNSSEC denial proof",
                            "      validation per fetch in lib/dns/validator.c.",
                            "    - CVE-2026-11605",
                            "  * SECURITY UPDATE: Potential memory usage beyond configured limits",
                            "    - debian/patches/CVE-2026-11622.patch: Make the dns_slabheaders in the cache",
                            "      reference counted in bin/tests/system/reclimit/tests.sh,",
                            "      lib/dns/include/dns/rdataslab.h, lib/dns/qpcache.c, lib/dns/qpzone.c,",
                            "      lib/dns/rbt-cachedb.c, lib/dns/rbtdb.c, lib/dns/rbtdb_p.h,",
                            "      lib/dns/rdataslab.c.",
                            "    - CVE-2026-11622",
                            "  * SECURITY UPDATE: Cache poisoning possible with label count discrepancy,",
                            "    RRSIG, and wildcards",
                            "    - debian/patches/CVE-2026-11721-1.patch: Don't sign out of zone records in",
                            "      dnssec-signzone in bin/dnssec/dnssec-signzone.c.",
                            "    - debian/patches/CVE-2026-11721-2.patch: Invalid signed wildcard records",
                            "      were being accepted in lib/dns/dnssec.c, lib/dns/rdata/generic/rrsig_46.c.",
                            "    - debian/patches/CVE-2026-11721-3.patch: Test RRSIG record parsing in",
                            "      tests/dns/rdata_test.c.",
                            "    - CVE-2026-11721",
                            "  * SECURITY UPDATE:Record ordering based unexpected exit with CNAME or DNAME",
                            "    - debian/patches/CVE-2026-12617-1.patch: Do not assert in some CNAME/DNAME",
                            "      queries in lib/dns/resolver.c.",
                            "    - debian/patches/CVE-2026-12617-2.patch: Reproducer for #5946 (assertion in",
                            "      some CNAME/DNAME queries) in",
                            "      bin/tests/system/cname_dname_negcache/ans2/ans.py,",
                            "      bin/tests/system/cname_dname_negcache/ns1/bar.test.db,",
                            "      bin/tests/system/cname_dname_negcache/ns1/named.conf.j2,",
                            "      bin/tests/system/cname_dname_negcache/ns1/root.db,",
                            "      bin/tests/system/cname_dname_negcache/ns1/test.db,",
                            "      bin/tests/system/cname_dname_negcache/ns3/named.conf.j2,",
                            "      bin/tests/system/cname_dname_negcache/tests_cname_dname_negcache.py.",
                            "    - CVE-2026-12617",
                            "  * SECURITY UPDATE: Unexpected exit in certain situations with NSEC and NSEC3",
                            "    both present",
                            "    - debian/patches/CVE-2026-13204-1.patch: dns_rdataset_addnoqname() could",
                            "      find unsigned NSEC/NSEC3 in lib/dns/qpcache.c, lib/dns/rbtdb.c,",
                            "      lib/dns/rdatalist.c, lib/dns/resolver.c, lib/ns/query.c.",
                            "    - debian/patches/CVE-2026-13204-2.patch: Reproducer for #5985 addnoqname",
                            "      mismatch in",
                            "      bin/tests/system/repro_5985_findnoqname_runtime_check/ans1/ans.py,",
                            "      bin/tests/system/repro_5985_findnoqname_runtime_check/ns2/named.conf.j2,",
                            "      bin/tests/system/repro_5985_findnoqname_runtime_check/server.py, bin/tests",
                            "      /system/repro_5985_findnoqname_runtime_check/tests_repro_5985_findnoqname_",
                            "      runtime_check.py.",
                            "    - debian/patches/CVE-2026-13204-3.patch: Update reproducer #5985 in",
                            "      bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py,",
                            "      bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2, bin/tests/",
                            "      system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py.",
                            "    - CVE-2026-13204",
                            "  * SECURITY UPDATE: Record ordering based unexpected exit with CNAME or DNAME",
                            "    - debian/patches/CVE-2026-13321-1.patch: Add system test for out-of-zone",
                            "      nsec dnssec bypass in bin/tests/system/dnssec_bypass/ns1/named.conf.j2,",
                            "      bin/tests/system/dnssec_bypass/ns1/root.db,",
                            "      bin/tests/system/dnssec_bypass/ns1/test.db,",
                            "      bin/tests/system/dnssec_bypass/ns2/named.conf.j2,",
                            "      bin/tests/system/dnssec_bypass/ns2/victim.db,",
                            "      bin/tests/system/dnssec_bypass/ns3/evil.db,",
                            "      bin/tests/system/dnssec_bypass/ns3/named.conf.j2,",
                            "      bin/tests/system/dnssec_bypass/ns4/named.conf.j2,",
                            "      bin/tests/system/dnssec_bypass/tests_bypass.py.",
                            "    - debian/patches/CVE-2026-13321-2.patch: Reject out-of-zone NSEC next owner",
                            "      names in lib/dns/dnssec.c, lib/dns/include/dns/dnssec.h.",
                            "    - debian/patches/CVE-2026-13321-3.patch: change",
                            "      dns_nsec_requiredtypespresent to dns_nsec_is_legal in",
                            "      lib/dns/include/dns/nsec.h, lib/dns/nsec.c, lib/dns/resolver.c,",
                            "      lib/ns/query.c.",
                            "    - CVE-2026-13321",
                            ""
                        ],
                        "package": "bind9",
                        "version": "1:9.20.24-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Mon, 31 Aug 2026 12:10:28 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "bind9",
                        "version": "1:9.20.24-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 10:28:57 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2157486). Remaining changes:",
                            "    - Don't build dnstap as it depends on universe packages:",
                            "      + d/control: drop build-depends on libfstrm-dev, libprotobuf-c-dev and",
                            "        protobuf-c-compiler",
                            "      + d/dnsutils.install: don't install dnstap",
                            "      + d/rules: don't build dnstap nor install dnstap.proto",
                            "    - Add back apport:",
                            "      + d/bind9.apport: add back old bind9 apport hook, but without calling",
                            "        attach_conffiles() since that is already done by apport itself, with",
                            "        confirmation from the user.",
                            "      + d/control, d/rules: build-depends on dh-apport and use it",
                            "    - d/NEWS: mention relevant packaging changes",
                            "    - d/e/apparmor.d/usr.sbin.named: Allow read access to",
                            "      /proc/version_signature for named (LP #2119320)",
                            ""
                        ],
                        "package": "bind9",
                        "version": "1:9.20.24-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2157486
                        ],
                        "author": "Lena Voytek <lena.voytek@canonical.com>",
                        "date": "Thu, 18 Jun 2026 12:22:05 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 9.20.24",
                            ""
                        ],
                        "package": "bind9",
                        "version": "1:9.20.24-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Ondřej Surý <ondrej@debian.org>",
                        "date": "Wed, 17 Jun 2026 14:43:58 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "bind9-libs:ppc64el",
                "from_version": {
                    "source_package_name": "bind9",
                    "source_package_version": "1:9.20.23-1ubuntu1",
                    "version": "1:9.20.23-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "bind9",
                    "source_package_version": "1:9.20.24-1ubuntu3",
                    "version": "1:9.20.24-1ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-10723",
                        "url": "https://ubuntu.com/security/CVE-2026-10723",
                        "cve_description": "BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-10822",
                        "url": "https://ubuntu.com/security/CVE-2026-10822",
                        "cve_description": "If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit.  BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11331",
                        "url": "https://ubuntu.com/security/CVE-2026-11331",
                        "cve_description": "An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11605",
                        "url": "https://ubuntu.com/security/CVE-2026-11605",
                        "cve_description": "The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11622",
                        "url": "https://ubuntu.com/security/CVE-2026-11622",
                        "cve_description": "A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11721",
                        "url": "https://ubuntu.com/security/CVE-2026-11721",
                        "cve_description": "It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-12617",
                        "url": "https://ubuntu.com/security/CVE-2026-12617",
                        "cve_description": "The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. Or, if a client queries for a CNAME and A record for the same name to the resolver, and the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME, the same failure may occur. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-13204",
                        "url": "https://ubuntu.com/security/CVE-2026-13204",
                        "cve_description": "If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-13321",
                        "url": "https://ubuntu.com/security/CVE-2026-13321",
                        "cve_description": "The BIND resolver accepts validly-signed NSEC records where the \"Next Domain Name\" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-22 15:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2157486
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-10723",
                                "url": "https://ubuntu.com/security/CVE-2026-10723",
                                "cve_description": "BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-10822",
                                "url": "https://ubuntu.com/security/CVE-2026-10822",
                                "cve_description": "If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit.  BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11331",
                                "url": "https://ubuntu.com/security/CVE-2026-11331",
                                "cve_description": "An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11605",
                                "url": "https://ubuntu.com/security/CVE-2026-11605",
                                "cve_description": "The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11622",
                                "url": "https://ubuntu.com/security/CVE-2026-11622",
                                "cve_description": "A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11721",
                                "url": "https://ubuntu.com/security/CVE-2026-11721",
                                "cve_description": "It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-12617",
                                "url": "https://ubuntu.com/security/CVE-2026-12617",
                                "cve_description": "The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. Or, if a client queries for a CNAME and A record for the same name to the resolver, and the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME, the same failure may occur. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-13204",
                                "url": "https://ubuntu.com/security/CVE-2026-13204",
                                "cve_description": "If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-13321",
                                "url": "https://ubuntu.com/security/CVE-2026-13321",
                                "cve_description": "The BIND resolver accepts validly-signed NSEC records where the \"Next Domain Name\" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-22 15:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Incorrect acceptance of NSEC3 records",
                            "    - debian/patches/CVE-2026-10723-1.patch: Check NSEC3 signer matches the",
                            "      owning zone in lib/dns/dnssec.c, lib/isc/result.c.",
                            "    - debian/patches/CVE-2026-10723-2.patch: Reproducer for #5874 NSEC3",
                            "      impersonation in bin/tests/system/repro_5874_nsec3_parent/ans1/ans.py,",
                            "      bin/tests/system/repro_5874_nsec3_parent/ns2/named.conf.j2,",
                            "      bin/tests/system/repro_5874_nsec3_parent/server.py,",
                            "      bin/tests/system/repro_5874_nsec3_parent/tests_repro_5874_nsec3_parent.py.",
                            "    - debian/patches/CVE-2026-10723-3.patch: Update reproducer #5874 in",
                            "      bin/tests/system/nsec3_impersonation/ans1/ans.py,",
                            "      bin/tests/system/nsec3_impersonation/ns2/named.conf.j2,",
                            "      bin/tests/system/nsec3_impersonation/tests_nsec3_impersonation.py.",
                            "    - CVE-2026-10723",
                            "  * SECURITY UPDATE: Key Record using PRIVATEDNS algorithm may lead to",
                            "    unexpected exit",
                            "    - debian/patches/CVE-2026-10822-1.patch: Check that dns_name_fromwire",
                            "      honours the active region in tests/dns/name_test.c.",
                            "    - debian/patches/CVE-2026-10822-2.patch: Fix the yaml query zone name code",
                            "      in dnstap-read in bin/tools/dnstap-read.c.",
                            "    - debian/patches/CVE-2026-10822-3.patch: Fix dns_name_fromwire to honour the",
                            "      active region in lib/dns/name.c.",
                            "    - debian/patches/CVE-2026-10822-4.patch: Make it clearer that decompression",
                            "      is not allowed here in lib/dns/rdata.c.",
                            "    - debian/patches/CVE-2026-10822-5.patch: Check that a short PRIVATEDNS",
                            "      record is rejected in tests/dns/rdata_test.c.",
                            "    - CVE-2026-10822",
                            "  * SECURITY UPDATE: Potential wildcard CNAME RPZ policy bypass",
                            "    - debian/patches/CVE-2026-11331-1.patch: Fix TTL extraction from A/AAAA",
                            "      record in bin/tests/system/rpz/tests.sh.",
                            "    - debian/patches/CVE-2026-11331-2.patch: Check rpz name too long wildcard",
                            "      CNAME expansion handling in bin/tests/system/rpz/ns2/tld2.db,",
                            "      bin/tests/system/rpz/ns4/tld4.db, bin/tests/system/rpz/tests.sh.",
                            "    - debian/patches/CVE-2026-11331-3.patch: Properly handle rpz name to long",
                            "      wildcard expansion in lib/ns/query.c.",
                            "    - CVE-2026-11331",
                            "  * SECURITY UPDATE: Unnecessary validation of DNSSEC signed records",
                            "    - debian/patches/CVE-2026-11605-1.patch: Limit DNSSEC denial proof",
                            "      validation per fetch in lib/dns/validator.c.",
                            "    - CVE-2026-11605",
                            "  * SECURITY UPDATE: Potential memory usage beyond configured limits",
                            "    - debian/patches/CVE-2026-11622.patch: Make the dns_slabheaders in the cache",
                            "      reference counted in bin/tests/system/reclimit/tests.sh,",
                            "      lib/dns/include/dns/rdataslab.h, lib/dns/qpcache.c, lib/dns/qpzone.c,",
                            "      lib/dns/rbt-cachedb.c, lib/dns/rbtdb.c, lib/dns/rbtdb_p.h,",
                            "      lib/dns/rdataslab.c.",
                            "    - CVE-2026-11622",
                            "  * SECURITY UPDATE: Cache poisoning possible with label count discrepancy,",
                            "    RRSIG, and wildcards",
                            "    - debian/patches/CVE-2026-11721-1.patch: Don't sign out of zone records in",
                            "      dnssec-signzone in bin/dnssec/dnssec-signzone.c.",
                            "    - debian/patches/CVE-2026-11721-2.patch: Invalid signed wildcard records",
                            "      were being accepted in lib/dns/dnssec.c, lib/dns/rdata/generic/rrsig_46.c.",
                            "    - debian/patches/CVE-2026-11721-3.patch: Test RRSIG record parsing in",
                            "      tests/dns/rdata_test.c.",
                            "    - CVE-2026-11721",
                            "  * SECURITY UPDATE:Record ordering based unexpected exit with CNAME or DNAME",
                            "    - debian/patches/CVE-2026-12617-1.patch: Do not assert in some CNAME/DNAME",
                            "      queries in lib/dns/resolver.c.",
                            "    - debian/patches/CVE-2026-12617-2.patch: Reproducer for #5946 (assertion in",
                            "      some CNAME/DNAME queries) in",
                            "      bin/tests/system/cname_dname_negcache/ans2/ans.py,",
                            "      bin/tests/system/cname_dname_negcache/ns1/bar.test.db,",
                            "      bin/tests/system/cname_dname_negcache/ns1/named.conf.j2,",
                            "      bin/tests/system/cname_dname_negcache/ns1/root.db,",
                            "      bin/tests/system/cname_dname_negcache/ns1/test.db,",
                            "      bin/tests/system/cname_dname_negcache/ns3/named.conf.j2,",
                            "      bin/tests/system/cname_dname_negcache/tests_cname_dname_negcache.py.",
                            "    - CVE-2026-12617",
                            "  * SECURITY UPDATE: Unexpected exit in certain situations with NSEC and NSEC3",
                            "    both present",
                            "    - debian/patches/CVE-2026-13204-1.patch: dns_rdataset_addnoqname() could",
                            "      find unsigned NSEC/NSEC3 in lib/dns/qpcache.c, lib/dns/rbtdb.c,",
                            "      lib/dns/rdatalist.c, lib/dns/resolver.c, lib/ns/query.c.",
                            "    - debian/patches/CVE-2026-13204-2.patch: Reproducer for #5985 addnoqname",
                            "      mismatch in",
                            "      bin/tests/system/repro_5985_findnoqname_runtime_check/ans1/ans.py,",
                            "      bin/tests/system/repro_5985_findnoqname_runtime_check/ns2/named.conf.j2,",
                            "      bin/tests/system/repro_5985_findnoqname_runtime_check/server.py, bin/tests",
                            "      /system/repro_5985_findnoqname_runtime_check/tests_repro_5985_findnoqname_",
                            "      runtime_check.py.",
                            "    - debian/patches/CVE-2026-13204-3.patch: Update reproducer #5985 in",
                            "      bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py,",
                            "      bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2, bin/tests/",
                            "      system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py.",
                            "    - CVE-2026-13204",
                            "  * SECURITY UPDATE: Record ordering based unexpected exit with CNAME or DNAME",
                            "    - debian/patches/CVE-2026-13321-1.patch: Add system test for out-of-zone",
                            "      nsec dnssec bypass in bin/tests/system/dnssec_bypass/ns1/named.conf.j2,",
                            "      bin/tests/system/dnssec_bypass/ns1/root.db,",
                            "      bin/tests/system/dnssec_bypass/ns1/test.db,",
                            "      bin/tests/system/dnssec_bypass/ns2/named.conf.j2,",
                            "      bin/tests/system/dnssec_bypass/ns2/victim.db,",
                            "      bin/tests/system/dnssec_bypass/ns3/evil.db,",
                            "      bin/tests/system/dnssec_bypass/ns3/named.conf.j2,",
                            "      bin/tests/system/dnssec_bypass/ns4/named.conf.j2,",
                            "      bin/tests/system/dnssec_bypass/tests_bypass.py.",
                            "    - debian/patches/CVE-2026-13321-2.patch: Reject out-of-zone NSEC next owner",
                            "      names in lib/dns/dnssec.c, lib/dns/include/dns/dnssec.h.",
                            "    - debian/patches/CVE-2026-13321-3.patch: change",
                            "      dns_nsec_requiredtypespresent to dns_nsec_is_legal in",
                            "      lib/dns/include/dns/nsec.h, lib/dns/nsec.c, lib/dns/resolver.c,",
                            "      lib/ns/query.c.",
                            "    - CVE-2026-13321",
                            ""
                        ],
                        "package": "bind9",
                        "version": "1:9.20.24-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Mon, 31 Aug 2026 12:10:28 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "bind9",
                        "version": "1:9.20.24-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 10:28:57 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2157486). Remaining changes:",
                            "    - Don't build dnstap as it depends on universe packages:",
                            "      + d/control: drop build-depends on libfstrm-dev, libprotobuf-c-dev and",
                            "        protobuf-c-compiler",
                            "      + d/dnsutils.install: don't install dnstap",
                            "      + d/rules: don't build dnstap nor install dnstap.proto",
                            "    - Add back apport:",
                            "      + d/bind9.apport: add back old bind9 apport hook, but without calling",
                            "        attach_conffiles() since that is already done by apport itself, with",
                            "        confirmation from the user.",
                            "      + d/control, d/rules: build-depends on dh-apport and use it",
                            "    - d/NEWS: mention relevant packaging changes",
                            "    - d/e/apparmor.d/usr.sbin.named: Allow read access to",
                            "      /proc/version_signature for named (LP #2119320)",
                            ""
                        ],
                        "package": "bind9",
                        "version": "1:9.20.24-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2157486
                        ],
                        "author": "Lena Voytek <lena.voytek@canonical.com>",
                        "date": "Thu, 18 Jun 2026 12:22:05 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 9.20.24",
                            ""
                        ],
                        "package": "bind9",
                        "version": "1:9.20.24-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Ondřej Surý <ondrej@debian.org>",
                        "date": "Wed, 17 Jun 2026 14:43:58 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "bpftool",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.7.0+7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.8.0+7.2.0-5.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-47337",
                        "url": "https://ubuntu.com/security/CVE-2026-47337",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47334",
                        "url": "https://ubuntu.com/security/CVE-2026-47334",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47333",
                        "url": "https://ubuntu.com/security/CVE-2026-47333",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47332",
                        "url": "https://ubuntu.com/security/CVE-2026-47332",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47330",
                        "url": "https://ubuntu.com/security/CVE-2026-47330",
                        "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47329",
                        "url": "https://ubuntu.com/security/CVE-2026-47329",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47327",
                        "url": "https://ubuntu.com/security/CVE-2026-47327",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47328",
                        "url": "https://ubuntu.com/security/CVE-2026-47328",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47326",
                        "url": "https://ubuntu.com/security/CVE-2026-47326",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163667,
                    2163401,
                    2147533,
                    1990064,
                    2144679,
                    2142956,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2160302,
                    2161304,
                    2160497,
                    1786013,
                    2159617,
                    1786013,
                    2156849,
                    2155837,
                    2146517,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2148809,
                    2151747,
                    2151747,
                    2151747,
                    1990064,
                    2144679,
                    2142956,
                    2139664,
                    2142956,
                    2141298,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2154256,
                    1786013,
                    2154174,
                    2152714,
                    2148866,
                    2149808,
                    2148718
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.2.0-5.5 -proposed tracker (LP: #2163667)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163667
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 16:59:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-4.4 -proposed tracker (LP: #2163401)",
                            "",
                            "  * AA: disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED (LP: #2147533)",
                            "    - [Config] disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.1.0 [60/61]: apparmor: skb: add the ability to use",
                            "      interface in network mediation.",
                            "    - SAUCE: apparmor5.1.0 [61/61]: apparmor: skb: switch to using sk_ctx crit",
                            "      section",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.1.0 [59/61]: apparmor: skb: fix",
                            "      apparmor_secmark_check() when !inet and secmark defined.",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.1.0 [1/61]: apparmor-next: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.1.0 [2/61]: apparmor-next: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.1.0 [3/61]: apparmor-next: apparmor: Initial support",
                            "      for compressed policies",
                            "    - SAUCE: apparmor5.1.0 [4/61]: apparmor-next: apparmor: fix alternate",
                            "      loaders ability to load compressed policy",
                            "    - SAUCE: apparmor5.1.0 [5/61]: apparmor-next: apparmor: replace",
                            "      decompress_zstd() prototype with its entity",
                            "    - SAUCE: apparmor5.1.0 [6/61]: apparmor-next: apparmor: leverage",
                            "      audit_log_n_untrustedstring() when possible",
                            "    - SAUCE: apparmor5.1.0 [7/61]: apparmor-next: apparmor: switch website",
                            "      link to https",
                            "    - SAUCE: apparmor5.1.0 [8/61]: apparmor-next: apparmor: compressed_data",
                            "      not described in aa_get_data_from_compressed",
                            "    - SAUCE: apparmor5.1.0 [9/61]: apparmor-next: apparmor: Fix build failure",
                            "      when ZSTD_DECOMPRESS is not enabled",
                            "    - SAUCE: apparmor5.1.0 [10/61]: apparmor-next: apparmor: fix implicit",
                            "      declaration of function 'decompress_zstd'",
                            "    - SAUCE: apparmor5.1.0 [11/61]: apparmor-next: apparmor: Fix warning:",
                            "      'decompress_zstd' defined but not used",
                            "    - SAUCE: apparmor5.1.0 [12/61]: apparmor-next: apparmor: use",
                            "      SEND_SIG_NOINFO instead of NULL in aa_audit()",
                            "    - SAUCE: apparmor5.1.0 [13/61]: apparmor-next: apparmor: fix cred UAF",
                            "      caused by begin_current_label_crit_section()",
                            "    - SAUCE: apparmor5.1.0 [14/61]: apparmor-next: apparmor: optimize",
                            "      current_label_crit_section() with needput",
                            "    - SAUCE: apparmor5.1.0 [15/61]: apparmor-next: apparmor: fix integer",
                            "      overflow in verify_tags() bounds check",
                            "    - SAUCE: apparmor5.1.0 [16/61]: apparmor-next: apparmor: fix out-of-bounds",
                            "      write when null terminating a label vec",
                            "    - SAUCE: apparmor5.1.0 [17/61]: apparmor-next: apparmor: fix error",
                            "      handling for copy_from_user in policy_update",
                            "    - SAUCE: apparmor5.1.0 [18/61]: apparmor-next: apparmor: make",
                            "      MEDIATES_AF_UNIX its own fn",
                            "    - SAUCE: apparmor5.1.0 [19/61]: apparmor-next: apparmor: refactor network",
                            "      sock mediation in preparation for inet mediation",
                            "    - SAUCE: apparmor5.1.0 [20/61]: apparmor-next: apparmor: push inet",
                            "      mediation into profile callbacks, and improve auditing",
                            "    - SAUCE: apparmor5.1.0 [21/61]: apparmor-next: apparmor: refactor network",
                            "      socket mediation to support compatibility",
                            "    - SAUCE: apparmor5.1.0 [22/61]: apparmor-next: apparmor: move netfilter",
                            "      functions next to the LSM network operations",
                            "    - SAUCE: apparmor5.1.0 [23/61]: apparmor-next: apparmor: move",
                            "      sock_rcv_skb() next to inet_conn_request",
                            "    - SAUCE: apparmor5.1.0 [24/61]: apparmor-next: apparmor: reserve mediation",
                            "      class for packet mediation",
                            "    - SAUCE: apparmor5.1.0 [25/61]: apparmor-next: apparmor: fix unconfined",
                            "      user namespace restriction forced stack",
                            "    - SAUCE: apparmor5.1.0 [26/61]: apparmor-next: apparmor: refactor xattr",
                            "      attachment, to take the file path",
                            "    - SAUCE: apparmor5.1.0 [27/61]: apparmor-next: apparmor: fix race",
                            "      condition in label replacement",
                            "    - SAUCE: apparmor5.1.0 [28/61]: apparmor-next: apparmor: make table entry",
                            "      count last enum for static tables",
                            "    - SAUCE: apparmor5.1.0 [29/61]: apparmor-next: apparmor: fix error debug",
                            "      output in fn_label_build",
                            "    - SAUCE: apparmor5.1.0 [30/61]: apparmor-next: apparmor: mark static",
                            "      tables and structs as read only",
                            "    - SAUCE: apparmor5.1.0 [31/61]: apparmor-next: apparmor: add audit mode to",
                            "      provide a mechanism to silence complain messages",
                            "    - SAUCE: apparmor5.1.0 [32/61]: apparmor-next: apparmor: fix auditing of",
                            "      mount binary data",
                            "    - SAUCE: apparmor5.1.0 [33/61]: apparmor-next: apparmor: refactory mount",
                            "      to use check_perms",
                            "    - SAUCE: apparmor5.1.0 [34/61]: apparmor-next: apparmor: drop use of",
                            "      _confined variant for iteration",
                            "    - SAUCE: apparmor5.1.0 [35/61]: apparmor-next: apparmor: constify aa_perms",
                            "      parameters that are read-only",
                            "    - SAUCE: apparmor5.1.0 [36/61]: apparmor-next: apparmor: constify",
                            "      aa_profile parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [37/61]: apparmor-next: apparmor: constify aa_dfa",
                            "      parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [38/61]: apparmor-next: apparmor: constify aa_label",
                            "      parameters on read-only query helpers",
                            "    - SAUCE: apparmor5.1.0 [39/61]: apparmor-next-next: apparmor: setup slab",
                            "      cache for audit data",
                            "    - SAUCE: apparmor5.1.0 [40/61]: apparmor-next-next: apparmor: add the",
                            "      ability for profiles to have a learning cache",
                            "    - SAUCE: apparmor5.1.0 [41/61]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.1.0 [42/61]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.1.0 [43/61]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.1.0 [44/61]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.1.0 [45/61]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.1.0 [46/61]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [47/61]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [48/61]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.1.0 [50/61]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.1.0 [51/61]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.1.0 [52/61]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.1.0 [53/61]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.1.0 [54/61]: apparmor: mqueue: prevent",
                            "      profile->disconnected double free in aa_free_profile",
                            "    - SAUCE: apparmor5.1.0 [55/61]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.1.0 [58/61]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.1.0 [56/61]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.1.0 [57/61]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.1.0 [49/61]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Drop DEP-8 tests from kernel packages (LP: #2160302)",
                            "    - [Packaging] Drop DEP-8 tests from kernel source",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] updateconfigs after rebase to v7.2-rc6",
                            "    - [Config] Enable SECURITY_APPARMOR_COMPRESSED_POLICY",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163401,
                            2147533,
                            1990064,
                            2144679,
                            2142956,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602,
                            2160302
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:46:26 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-2.2 -proposed tracker (LP: #2161304)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Changes.md: dropping reboot=pci quirks for sandy bridge hw",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161304
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:29:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-1.1 -proposed tracker (LP: #2160497)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160497,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:07:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-0.0 -proposed tracker (LP: #2159617)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] update annotations scripts",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.2-rc1 rebase",
                            "    - [Config] updateconfigs after v7.2-rc1 rebase",
                            "    - SAUCE: thunderbolt: fixup move of pci_device out of tb_nhi",
                            "    - [Packaging] integrate SBOM generation into the build",
                            "    - SAUCE: fixup s/strncpy/strscpy/ in compat_uts_machine= kernel command",
                            "      line override",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: media: venus: core: guard SC8280XP/SM8350 resources behind !IRIS",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159617,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47337",
                                "url": "https://ubuntu.com/security/CVE-2026-47337",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47334",
                                "url": "https://ubuntu.com/security/CVE-2026-47334",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47333",
                                "url": "https://ubuntu.com/security/CVE-2026-47333",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47332",
                                "url": "https://ubuntu.com/security/CVE-2026-47332",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47330",
                                "url": "https://ubuntu.com/security/CVE-2026-47330",
                                "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47329",
                                "url": "https://ubuntu.com/security/CVE-2026-47329",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47327",
                                "url": "https://ubuntu.com/security/CVE-2026-47327",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47328",
                                "url": "https://ubuntu.com/security/CVE-2026-47328",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47326",
                                "url": "https://ubuntu.com/security/CVE-2026-47326",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-5.5 -proposed tracker (LP: #2156849)",
                            "",
                            "  * MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260",
                            "    renders upside-down (LP: #2155837)",
                            "    - SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14",
                            "      Premium PA14260",
                            "",
                            "  * ov08x40 module mounted upside down on a certain DELL platforms",
                            "    (LP: #2146517)",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for new Dell XPS laptops with",
                            "      upside down sensors",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for Dell 14 laptops with upside",
                            "      down sensors",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747)",
                            "    - SAUCE: apparmor: pass big_resp to handler",
                            "    - SAUCE: apparmor: remove redundant kref_init for listener->count",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47337",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47334",
                            "    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47333",
                            "    - SAUCE: apparmor: fix dfa unpacking size of the notification filter",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47332",
                            "    - SAUCE: apparmor: fix size check against type instead of pointer",
                            "",
                            "  * apparmor: LLVM/clang build failure due to uninitialized variable in",
                            "    notify.c (LP: #2148809) // CVE-2026-47330",
                            "    - SAUCE: apparmor: initialize variable used in uninitialized context",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47329",
                            "    - SAUCE: apparmor: fix name validation bypass on notification",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47327 //",
                            "    CVE-2026-47328",
                            "    - SAUCE: apparmor: fix glob memory leak after kstrdup",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47326",
                            "    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.0.0 [57/57]: apparmor: add the ability to use interface",
                            "      in network mediation.",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [29/57]: apparmor: fix fine grained inet mediation",
                            "      sock_file_perm",
                            "    - SAUCE: apparmor5.0.0 [32/57]: apparmor-next 7.1: apparmor: enable",
                            "      differential encoding",
                            "    - SAUCE: apparmor5.0.0 [33/57]: apparmor-next 7.1: apparmor: propagate",
                            "      -ENOMEM correctly in unpack_table",
                            "    - SAUCE: apparmor5.0.0 [36/57]: apparmor-next 7.1: apparmor: use",
                            "      __label_make_stale in __aa_proxy_redirect",
                            "    - SAUCE: apparmor5.0.0 [37/57]: apparmor-next 7.1: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.0.0 [39/57]: apparmor-next 7.1: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1: apparmor: fix",
                            "      rawdata_f_data implicit flex array",
                            "    - SAUCE: apparmor5.0.0 [42/57]: apparmor-next 7.1: apparmor: free rawdata",
                            "      as soon as possible",
                            "    - SAUCE: apparmor5.0.0 [43/57]: apparmor-next 7.1: apparmor: Initial",
                            "      support for compressed policies",
                            "    - SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1: apparmor: fix potential",
                            "      UAF in aa_replace_profiles",
                            "    - SAUCE: apparmor5.0.0 [45/57]: apparmor-next 7.1: apparmor: hide unused",
                            "      get_loaddata_common_ref() function",
                            "    - SAUCE: apparmor5.0.0 [47/57]: apparmor: fix packed tag on v5 header",
                            "      struct",
                            "    - SAUCE: apparmor5.0.0 [48/57]: apparmor: add temporal caching to audit",
                            "      responses.",
                            "    - SAUCE: apparmor5.0.0 [49/57]: apparmor: change fn_label_build() call to",
                            "      not return NULL",
                            "    - SAUCE: apparmor5.0.0 [50/57]: apparmor: make fn_label_build() capable of",
                            "      handling not supported",
                            "    - SAUCE: apparmor5.0.0 [51/57]: apparmor: move netfilter functions next to",
                            "      the LSM network operations",
                            "    - SAUCE: apparmor5.0.0 [52/57]: apparmor: move sock_rvc_skb() next to",
                            "      inet_conn_request",
                            "    - SAUCE: apparmor5.0.0 [53/57]: apparmor: fix af_unix local addr mediation",
                            "      binding",
                            "    - SAUCE: apparmor5.0.0 [54/57]: cleanups of apparmor af_unix mediation",
                            "    - SAUCE: apparmor5.0.0 [55/57]: apparmor: fix apparmor_secmark_check()",
                            "      when !inet and secmark defined.",
                            "    - SAUCE: apparmor5.0.0 [56/57]: apparmor: fix auditing of non-mediation",
                            "      falures",
                            "",
                            "  * snap service cannot change apparmor hat (LP: #2139664) // Jellyfin Desktop",
                            "    Flatpak doesn't work with the current AppArmor profile (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1: apparmor: grab ns lock",
                            "      and refresh when looking up changehat child profiles",
                            "",
                            "  * AppArmor blocks write(2) to network sockets with Linux 6.19 (LP: #2141298)",
                            "    - SAUCE: apparmor5.0.0 [28/57]: apparmor: fix aa_label_sk_perm to check",
                            "      for RULE_MEDIATES_NET",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.0.0 [1/57]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.0.0 [2/57]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.0.0 [3/57]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.0.0 [4/57]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.0.0 [5/57]: Revert \"apparmor: gate make fine grained",
                            "      unix mediation behind v9 abi\"",
                            "    - SAUCE: apparmor5.0.0 [6/57]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.0.0 [7/57]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [8/57]: apparmor: lift compatibility check out of",
                            "      profile_af_perm",
                            "    - SAUCE: apparmor5.0.0 [9/57]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [10/57]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.0.0 [12/57]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.0.0 [13/57]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.0.0 [14/57]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.0.0 [15/57]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.0.0 [16/57]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.0.0 [19/57]: apparmor: prompt: setup slab cache for",
                            "      audit data",
                            "    - SAUCE: apparmor5.0.0 [20/57]: apparmor: prompt: add the ability for",
                            "      profiles to have a learning cache",
                            "    - SAUCE: apparmor5.0.0 [21/57]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "    - SAUCE: apparmor5.0.0 [22/57]: apparmor: prompt: pass prompt boolean",
                            "      through into path_name as well",
                            "    - SAUCE: apparmor5.0.0 [23/57]: apparmor: check for supported version in",
                            "      notification messages.",
                            "    - SAUCE: apparmor5.0.0 [24/57]: apparmor: refactor building notice so it",
                            "      is easier to extend",
                            "    - SAUCE: apparmor5.0.0 [25/57]: apparmor: switch from ENOTSUPP to",
                            "      EPROTONOSUPPORT",
                            "    - SAUCE: apparmor5.0.0 [26/57]: apparmor: add support for meta data tags",
                            "    - SAUCE: apparmor5.0.0 [27/57]: apparmor: prevent profile->disconnected",
                            "      double free in aa_free_profile",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.0.0 [17/57]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.0.0 [18/57]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.0.0 [11/57]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] enable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "    - [Packaging] Fix cross-builds",
                            "    - [Config] updateconfigs after v7.1 rebase",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2156849,
                            2155837,
                            2146517,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2148809,
                            2151747,
                            2151747,
                            2151747,
                            1990064,
                            2144679,
                            2142956,
                            2139664,
                            2142956,
                            2141298,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:38:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-1.1 -proposed tracker (LP: #2154256)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "",
                            "  * resolute ubuntu_kernel_selftests:seccomp_build test compilation issue",
                            "    (LP: #2154174)",
                            "    - SAUCE: selftests/seccomp fix compilation issue for amd64",
                            "",
                            "  * Kernel 6.19-rc8 does not include GPIB driver (LP: #2152714)",
                            "    - [Config] Enable CONFIG_GPIB for amd64",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.1-rc4 rebase",
                            "    - [packaging] Install gdb scripts again",
                            "    - [Config] updateconfigs after v7.1-rc5 rebase",
                            "    - [Packaging] templates: Use a for-loop for run-parts",
                            "    - [Packaging] Remove dead debian.master/rules.d/x32.mk",
                            "    - [Packaging] Remove orphaned debian/v4l2loopback-modules.ignore",
                            "    - [Packaging] Remove orphaned debian/zfs-modules.ignore",
                            "    - [Packaging] Remove deprecated linux-doc transitional stub",
                            "    - [Packaging] Remove dead comment referencing gcc-4.7 in control.stub.in",
                            "    - [Packaging] Remove dead comment in ppc64el.mk",
                            "    - [Packaging] Remove stale legacy code",
                            "    - [Packaging] rules: Drop an obsolete check for do_zstd_ko",
                            "    - [Config] toolchain version update",
                            "    - [Packaging] update Ubuntu.md",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154256,
                            1786013,
                            2154174,
                            2152714
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:08:55 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 09:59:13 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * resolute/linux: 7.0.0-15.15 -proposed tracker (LP: #2148866)",
                            "",
                            "  * Qualcomm X1E: Speaker overdrive causes hardware protection shutdown",
                            "    (LP: #2149808)",
                            "    - SAUCE: ASoC: qcom: x1e80100: limit speaker volumes",
                            "",
                            "  * intel-ipu7 / intel-ipu7-isys modules are shipped unsigned in latest",
                            "    Resolute kernels, breaking Secure Boot systems  (LP: #2148718)",
                            "    - [packaging] add intel-ipu7 to signature inclusion list",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2148866,
                            2149808,
                            2148718
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:02:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "btrfs-progs",
                "from_version": {
                    "source_package_name": "btrfs-progs",
                    "source_package_version": "7.0-1",
                    "version": "7.0-1"
                },
                "to_version": {
                    "source_package_name": "btrfs-progs",
                    "source_package_version": "7.1-1",
                    "version": "7.1-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Drop the override for dh_auto_build because diffoscope shows that the",
                            "    undocumented \"V=1\" argument does nothing at all.",
                            "  * Use usrmerged paths in btrfs.hook.",
                            ""
                        ],
                        "package": "btrfs-progs",
                        "version": "7.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Nicholas D Steeves <sten@debian.org>",
                        "date": "Sat, 08 Aug 2026 21:30:41 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "busybox-static",
                "from_version": {
                    "source_package_name": "busybox",
                    "source_package_version": "1:1.37.0-10.1ubuntu2",
                    "version": "1:1.37.0-10.1ubuntu2"
                },
                "to_version": {
                    "source_package_name": "busybox",
                    "source_package_version": "1:1.38.0-3ubuntu1",
                    "version": "1:1.38.0-3ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-38754",
                        "url": "https://ubuntu.com/security/CVE-2026-38754",
                        "cve_description": "A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-38755",
                        "url": "https://ubuntu.com/security/CVE-2026-38755",
                        "cve_description": "A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-38752",
                        "url": "https://ubuntu.com/security/CVE-2026-38752",
                        "cve_description": "A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-38753",
                        "url": "https://ubuntu.com/security/CVE-2026-38753",
                        "cve_description": "A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 21:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2157328
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable. Remaining changes:",
                            "    - Prefer busybox cmds over klibc cmds where there is duplication.",
                            "    - d/tree/busybox/usr/share/initramfs-tools/hooks/zz-busybox:",
                            "      Copy certs and openssl config for the casper+busybox-initramfs case.",
                            "    - d/config/pkg/{deb,static}: Enable chpasswd (needed by LXC).",
                            "    - d/p/fix-start-stop-daemon-rust-coreutils.patch:",
                            "      rust-coreutils disallows running an executable by a different",
                            "      name. This leads to \"start-stop-daemon with both -x and -a\"",
                            "      to fail as it attempts to run /bin/false under a different",
                            "      name, qwerty. Patch test to use the same executable as the",
                            "      test does not check argv[0] difference",
                            ""
                        ],
                        "package": "busybox",
                        "version": "1:1.38.0-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Mon, 17 Aug 2026 14:13:52 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-38754",
                                "url": "https://ubuntu.com/security/CVE-2026-38754",
                                "cve_description": "A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-38755",
                                "url": "https://ubuntu.com/security/CVE-2026-38755",
                                "cve_description": "A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-38752",
                                "url": "https://ubuntu.com/security/CVE-2026-38752",
                                "cve_description": "A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-38753",
                                "url": "https://ubuntu.com/security/CVE-2026-38753",
                                "cve_description": "A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 21:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * fix 4 (minor) security issues (Closes: #1142472):",
                            "    - ash-fix-out-of-bounds-read-in-ifsbreakup-CVE-2026-38754.patch",
                            "    - ash-fix-stack-overflow-in-evalfun-CVE-2026-38755.patch",
                            "    - awk-fix-stack-overflow-in-evaluate-CVE-2026-38752.patch",
                            "    - awk-fix-use-after-free-in-awk_sub-CVE-2026-38753.patch",
                            ""
                        ],
                        "package": "busybox",
                        "version": "1:1.38.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Tokarev <mjt@tls.msk.ru>",
                        "date": "Sun, 26 Jul 2026 08:53:18 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/copyright: convert to DEP-5 format (initial)",
                            "  * d/busybox-syslogd.init: use full /usr/bin path to interpreter",
                            "  * d/busybox-syslogd.lintian-overrides, d/udhcpd.lintian-overrides:",
                            "    fix overrides about #! interpreters in init scripts",
                            "  * swaponoff-FreeBSD-support.patch, u-mount-FreeBSD-support.patch:",
                            "    remove (unused for long time, kfreebsd is gone meanwhile)",
                            "  * coreutils-cut.c-typo-fix-delimeter.patch: fix typo",
                            "  * d/control: Standards-Version: 4.7.4 (no changes)",
                            "  * d/control: remove now-redundrand R3: no & Priority: options",
                            "  * remove debian-installer-env-hack patch: and the revert of upstream commit.",
                            "    The only actual difference for the d-i was the set builtin, which usage",
                            "    is now fixed in preseed package.  Restore status quo for regular builds.",
                            "    See https://lists.debian.org/debian-boot/2026/07/msg00057.html",
                            "  * ash-omit-variables-with-invalid-names-in-showvars.patch: fix the `set'",
                            "    builtin to omit showing environment variables with invalid names entirely",
                            ""
                        ],
                        "package": "busybox",
                        "version": "1:1.38.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Tokarev <mjt@tls.msk.ru>",
                        "date": "Sat, 25 Jul 2026 14:43:36 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * new upstream release (1.38.0)",
                            "  * remove patches which are now included",
                            "  * install-readlink-in-bin.patch: remove,",
                            "    usr/bin => bin move is irrelevant these days",
                            "  * update configs (sha384sum lsblk uuidgen vmstat; yescrypt)",
                            "    deb, static:",
                            "     enable --version",
                            "     enable new applets: sha384sum, lsblk, uuidgen, vmstat, test tls server",
                            "     enable internal yescrypt",
                            "       (we can probably switch to libcrypt for deb entirely)",
                            "    udeb:",
                            "     enable sha384sum",
                            "  * two patches to fix upstream testsuite (echo, printf => $ECHO):",
                            "    cpio-tests-echo.diff, ls-tests-printf.diff",
                            ""
                        ],
                        "package": "busybox",
                        "version": "1:1.38.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Tokarev <mjt@tls.msk.ru>",
                        "date": "Thu, 11 Jun 2026 15:15:56 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/tree/usr/share/initramfs-tools/hooks/zz-busybox:",
                            "    Add missing bracket. This is a follow-up from an incorrectly fixed merge.",
                            "  * Remove the busybox-initramfs package. It is smaller than the busybox",
                            "    package, but the size of busybox + glibc is a tiny fraction of Ubuntu's",
                            "    initrd. Carrying this busybox delta in Ubuntu is not worth the effort.",
                            "    (LP: #2157328)",
                            "  * Remove static-sh alias name for ash. Several components in the initrd rely",
                            "    on a working glibc. Users could use busybox-static or the stand-alone",
                            "    shell (sash) for recovery.",
                            "  * Drop test-bin.patch: Move test and friends to /bin is not needed any more",
                            "    because the systems are usr-merged.",
                            ""
                        ],
                        "package": "busybox",
                        "version": "1:1.37.0-10.1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2157328
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Fri, 17 Jul 2026 11:55:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ca-certificates",
                "from_version": {
                    "source_package_name": "ca-certificates",
                    "source_package_version": "20260601",
                    "version": "20260601"
                },
                "to_version": {
                    "source_package_name": "ca-certificates",
                    "source_package_version": "20260816",
                    "version": "20260816"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update Mozilla certificate authority bundle to version 2.90",
                            "    The following certificate authorities were added (+):",
                            "    + \"SECOM TLS ECC Root CA 2024\"",
                            "    + \"SECOM TLS RSA Root CA 2024\"",
                            "    + \"Telia EC TLS Root CA v3\"",
                            "    + \"Telia RSA TLS Root CA v3\"",
                            "    The following certificate authorities were removed (-):",
                            "    - \"Atos TrustedRoot 2011\"",
                            "    - \"Entrust Root Certification Authority\"",
                            "    - \"SecureSign Root CA12\"",
                            "    - \"ePKI Root Certification Authority\"",
                            ""
                        ],
                        "package": "ca-certificates",
                        "version": "20260816",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Julien Cristau <jcristau@debian.org>",
                        "date": "Sun, 16 Aug 2026 23:04:36 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "chrony",
                "from_version": {
                    "source_package_name": "chrony",
                    "source_package_version": "4.8-2ubuntu2",
                    "version": "4.8-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "chrony",
                    "source_package_version": "4.8-4ubuntu2",
                    "version": "4.8-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2161782,
                    2154097
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix NTP sources being left offline after a link flap on systemd-networkd",
                            "    hosts: (LP: #2161782)",
                            "    - d/p/examples-add-improved-networkd-dispatcher-script.patch: cherry-pick",
                            "      upstream's dedicated networkd-dispatcher script.",
                            "    - d/chrony.examples: install chrony.networkd-dispatcher.",
                            "    - d/chrony.links: create symlinks for the new networkd-dispatcher script.",
                            ""
                        ],
                        "package": "chrony",
                        "version": "4.8-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161782
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Wed, 26 Aug 2026 11:28:57 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2154097). Remaining changes:",
                            "    - Set -x as default if unable to set time (e.g. in containers) (LP #1589780)",
                            "      Chrony is a single service which acts as both NTP client (i.e. syncing the",
                            "      local clock) and NTP server (i.e. providing NTP services to the network),",
                            "      and that is both desired and expected in the vast majority of cases.",
                            "      But in containers syncing the local clock is usually impossible, but this",
                            "      shall not break the providing of NTP services to the network.",
                            "      To some extent this makes chrony's default config more similar to 'ntpd',",
                            "      which complained in syslog but still provided NTP server service in those",
                            "      cases.",
                            "      + debian/chrony.service: allow the service to run without CAP_SYS_TIME",
                            "      + d/control: add new dependency libcap2-bin for capsh (usually",
                            "        installed anyway, but make them explicit to be sure).",
                            "      + d/chrony.default: new option SYNC_IN_CONTAINER to not fall",
                            "        back (Default off)",
                            "      + d/chronyd-starter.sh: wrapper to handle special cases in",
                            "        containers and if CAP_SYS_TIME is missing. Effectively allows",
                            "        running the NTP server in containers on a default installation",
                            "        and avoid failing to sync time (or if allowed to sync, avoid",
                            "        multiple containers fighting over it by accident).",
                            "      + d/chrony.install: Make chrony-starter.sh available on install.",
                            "      + d/docs, d/README.container: Provide documentation about the",
                            "        handling of this case.",
                            "    - d/rules, d/chrony.examples: Ship restricted service as an example",
                            "      not installed to the system for use.  (See LP #2051028)",
                            "    - d/chrony.conf: remove Debian NTP pool and Document non-NTS sources from",
                            "      DHCP (LP #2115565)",
                            "    - Install Ubuntu NTP sources in",
                            "      /etc/chrony/sources.d/ubuntu-ntp-pools.sources, gated on a low priority",
                            "      (default yes) debconf question (LP #2048876):",
                            "      + d/templates: Add debconf question to customize installation of",
                            "        /etc/chrony/sources.d/ubuntu-ntp-pools.sources",
                            "      + d/chrony.install, d/ubuntu-ntp-pools.sources: Install",
                            "        ubuntu-ntp-pools.sources in /usr/share/chrony",
                            "      + d/control: add dependency on debconf",
                            "      + d/postinst: handle Ubuntu pools via debconf and ucf",
                            "      + d/postrm: handle Ubuntu pools via debconf and ucf",
                            "      + d/NEWS: Add information about default time sources moving out from",
                            "        chrony.conf to /etc/chrony/sources.d/ubuntu-ntp-pools.sources.",
                            "      + d/chrony.config: debconf script to handle Ubuntu pools",
                            "      + d/t/control, d/t/default-ubuntu-sources-behavior: new test to check the",
                            "        debconf behavior",
                            "    - Use Ubuntu NTS servers by default (LP #2084585):",
                            "      + d/conf.d/ubuntu-nts.conf: refer to the CA used to sign the NTS bootstrap",
                            "        server",
                            "      + d/nts-bootstrap-{,staging}-ubuntu.crt: CA certificate for the NTS",
                            "        bootstrap servers",
                            "      + d/chrony.install: install the NTS bootstrap CAs",
                            "      + d/ubuntu-ntp-pools.sources: use NTS by default",
                            "      + d/t/default-ubuntu-sources-behavior: update tests for NTS support",
                            "      + d/NEWS: add news entry about the NTS change",
                            "    - d/chrony.service: Allow real chronyd to send READY=1 via sd_notify in",
                            "      place of the chronyd-starter.sh wrapper.",
                            "    - d/control: Recommends: networkd-dispatcher (LP #2132159)",
                            "    - configure: switch sed separator from % to # to cope with dpkg",
                            "    - d/t/upstream-simulation-test-suite: revert update of clknetsim done in",
                            "      4.8-1 which redefines __open64_2 and breaks armhf build",
                            "  * Dropped:",
                            "    - d/t/helper-functions: show some logs in case of failure",
                            "      [In 4.8-3]",
                            "    - d/usr.sbin.chronyd: adjust apparmor rule so that chronyd is also allowed",
                            "      to access subdirectories of /run/chrony",
                            "      [In 4.8-3]",
                            ""
                        ],
                        "package": "chrony",
                        "version": "4.8-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154097
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:11:13 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/:",
                            "    - Bump dh compat to 14.",
                            "",
                            "  * debian/chrony.{if*,ppp*}:",
                            "    - Don't exit immediately if `chronyc onoffline` fails (Closes: #1011533)",
                            "    - Check for chronyd.sock instead of chronyd.pid. The existence of the PID",
                            "    file does not guarantee that the command socket is available.",
                            "",
                            "  * debian/control:",
                            "    - Bump Standards-Version to 4.7.4 (no changes required.)",
                            "",
                            "  * debian/copyright:",
                            "    - Update copyright year for debian/*.",
                            ""
                        ],
                        "package": "chrony",
                        "version": "4.8-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Vincent Blut <vincent.debian@free.fr>",
                        "date": "Mon, 22 Jun 2026 16:52:45 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Vincent Blut ]",
                            "  * debian/:",
                            "    - Format packaging files with `debputy reformat`.",
                            "",
                            "  * debian/control:",
                            "    - Use debputy's X-Style: black.",
                            "    - Bump Standards-Version to 4.7.3 (no changes required).",
                            "    - Fix lintian error 'invalid-arch-string-in-source-relation'.",
                            "",
                            "  * debian/patches/:",
                            "    - Drop skip-flaky-007-cmdmon-system-test.patch.",
                            "    - Cherry-pick test_-make-007-cmdmon-test-even-more-reliable.patch from",
                            "    upstream.",
                            "",
                            "  * debian/tests/:",
                            "    - Drop time-sources-from-dhcp-servers autopkgtest as it depends on",
                            "    the no longer available in testing isc-dhcp-{client,server} packages.",
                            "",
                            "  * debian/tests/upstream-simulation-test-suite:",
                            "    - No need to build clknetsim with extra CFLAGS on armel and armhf.",
                            "",
                            "  [ Andreas Hasenack ]",
                            "  * debian/tests/helper-functions:",
                            "    - Show some logs in case of failure.",
                            "",
                            "  * debian/usr.sbin.chronyd:",
                            "    - Adjust apparmor rule so that chronyd is also allowed to access",
                            "    subdirectories of /run/chrony.",
                            ""
                        ],
                        "package": "chrony",
                        "version": "4.8-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Vincent Blut <vincent.debian@free.fr>",
                        "date": "Thu, 26 Feb 2026 15:03:53 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "coreutils",
                "from_version": {
                    "source_package_name": "coreutils-from",
                    "source_package_version": "0.0.0~ubuntu28",
                    "version": "9.5-1ubuntu2+0.0.0~ubuntu28"
                },
                "to_version": {
                    "source_package_name": "coreutils-from",
                    "source_package_version": "0.0.0~ubuntu29",
                    "version": "9.5-1ubuntu2+0.0.0~ubuntu29"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2163383
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * uutils: Reinstate cp and df from rust-coreutils (LP: #2163383)",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "0.0.0~ubuntu29",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163383
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Thu, 13 Aug 2026 10:18:40 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "coreutils-from-uutils",
                "from_version": {
                    "source_package_name": "coreutils-from",
                    "source_package_version": "0.0.0~ubuntu28",
                    "version": "0.0.0~ubuntu28"
                },
                "to_version": {
                    "source_package_name": "coreutils-from",
                    "source_package_version": "0.0.0~ubuntu29",
                    "version": "0.0.0~ubuntu29"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2163383
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * uutils: Reinstate cp and df from rust-coreutils (LP: #2163383)",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "0.0.0~ubuntu29",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163383
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Thu, 13 Aug 2026 10:18:40 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "cpio",
                "from_version": {
                    "source_package_name": "cpio",
                    "source_package_version": "2.15+dfsg-2.1",
                    "version": "2.15+dfsg-2.1"
                },
                "to_version": {
                    "source_package_name": "cpio",
                    "source_package_version": "2.15+dfsg-2.1ubuntu1",
                    "version": "2.15+dfsg-2.1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-66485",
                        "url": "https://ubuntu.com/security/CVE-2026-66485",
                        "cve_description": "GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname during extraction. A malicious cpio archive containing a sufficiently long nested pathname causes an unbounded stack allocation, resulting in a stack overflow and crash of the cpio process. An attacker who can supply a crafted cpio archive to a victim who extracts it can cause a denial of service.  This issue has been fixed in commit 3cd514031371d8aeeaf2048aa10103e02831aaa9",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-10 11:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-66484",
                        "url": "https://ubuntu.com/security/CVE-2026-66484",
                        "cve_description": "GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name function without equivalent sanitization before calling link function. A tar archive provided by an attacker, containing a hard-link entry whose linkname is set to an absolute path outside the extraction directory, can cause cpio to create a hard link to an existing file outside the intended extraction directory, breaking the expected guarantee of --no-absolute-filenames and allowing archive-controlled linkage to external files.  This issue has been fixed in commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-10 11:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-66486",
                        "url": "https://ubuntu.com/security/CVE-2026-66486",
                        "cve_description": "GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed.     This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-10 11:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2019-14866",
                        "url": "https://ubuntu.com/security/CVE-2019-14866",
                        "cve_description": "In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.",
                        "cve_priority": "medium",
                        "cve_public_date": "2020-01-07 17:15:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-66485",
                                "url": "https://ubuntu.com/security/CVE-2026-66485",
                                "cve_description": "GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname during extraction. A malicious cpio archive containing a sufficiently long nested pathname causes an unbounded stack allocation, resulting in a stack overflow and crash of the cpio process. An attacker who can supply a crafted cpio archive to a victim who extracts it can cause a denial of service.  This issue has been fixed in commit 3cd514031371d8aeeaf2048aa10103e02831aaa9",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-10 11:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-66484",
                                "url": "https://ubuntu.com/security/CVE-2026-66484",
                                "cve_description": "GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name function without equivalent sanitization before calling link function. A tar archive provided by an attacker, containing a hard-link entry whose linkname is set to an absolute path outside the extraction directory, can cause cpio to create a hard link to an existing file outside the intended extraction directory, breaking the expected guarantee of --no-absolute-filenames and allowing archive-controlled linkage to external files.  This issue has been fixed in commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-10 11:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-66486",
                                "url": "https://ubuntu.com/security/CVE-2026-66486",
                                "cve_description": "GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed.     This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-10 11:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2019-14866",
                                "url": "https://ubuntu.com/security/CVE-2019-14866",
                                "cve_description": "In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.",
                                "cve_priority": "medium",
                                "cve_public_date": "2020-01-07 17:15:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Unbounded stack allocation",
                            "    - debian/patches/CVE-2026-66485.patch: Minor fixes in src/makepath.c,",
                            "      src/userspec.c.",
                            "    - CVE-2026-66485",
                            "  * SECURITY UPDATE: Hard link to file outside intended directory",
                            "    - debian/patches/CVE-2026-66484.patch: The --no-absolute-filenames option",
                            "      affects hard link targets too. in src/tar.c.",
                            "    - CVE-2026-66484",
                            "  * SECURITY UPDATE: Unescaped output",
                            "    - debian/patches/CVE-2026-66486.patch: Quote file names in error messages",
                            "      and in listings. in src/copyin.c, src/copyout.c, src/copypass.c,",
                            "      src/main.c, tests/CVE-2019-14866.at, tests/testsuite.",
                            "    - CVE-2026-66486",
                            ""
                        ],
                        "package": "cpio",
                        "version": "2.15+dfsg-2.1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Isabel Garcia Contreras <isabel.garcia@canonical.com>",
                        "date": "Tue, 18 Aug 2026 11:42:50 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "cryptsetup",
                "from_version": {
                    "source_package_name": "cryptsetup",
                    "source_package_version": "2:2.8.4-1ubuntu4",
                    "version": "2:2.8.4-1ubuntu4"
                },
                "to_version": {
                    "source_package_name": "cryptsetup",
                    "source_package_version": "2:2.8.7-1ubuntu1",
                    "version": "2:2.8.7-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-33948",
                        "url": "https://ubuntu.com/security/CVE-2026-33948",
                        "cve_description": "jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte count from fgets(), causing it to truncate input at the first NUL byte and parse only the preceding prefix. This enables an attacker to craft input with a benign JSON prefix before a NUL byte followed by malicious trailing data, where jq validates only the prefix as valid JSON while silently discarding the suffix. Workflows relying on jq to validate untrusted JSON before forwarding it to downstream consumers are susceptible to parser differential attacks, as those consumers may process the full input including the malicious trailing bytes. This issue has been patched by commit 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-14 00:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163661,
                    2157328
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2163661). Remaining changes:",
                            "    - d/tests/utils/mkinitramfs: Support zstd compressed modules for self test",
                            "    - d/rules: Compile-in support for a FIPS mode. LP #2032659",
                            "    - d/control: Recommend plymouth",
                            "    - d/control: Move cryptsetup-initramfs back to cryptsetup Recommends,",
                            "      preferring dracut",
                            "    - d/{control,rules}: Disable building cryptsetup-suspend on i386",
                            "    - d/initramfs/cryptroot-unlock: Fix busybox/narrow compat LP #1968636",
                            "    - d/tests: Fix autopkgtests",
                            "      + d/tests/utils/mkinitramfs: Prevent linking attempt if file exists",
                            "      + d/tests/utils/cryptroot-common: Handle Ubuntu kernel package split",
                            "        (linux-image + linux-modules) when extracting the kernel",
                            "    - d/{functions,initramfs/hooks/cryptroot}: Fix ZFS root warning/error",
                            "      + d/functions: Return an empty devno for ZFS devices as they don't have",
                            "        major:minor device numbers.",
                            "      + d/initramfs/hooks/cryptroot: Ignore and don't print an error message",
                            "        when devices don't have a devno.",
                            "    - d/p/{no-dd-direct-flags-tmpfs,series}: Disable O_DIRECT on tmpfs",
                            "    - d/p/test-use-gnudd-as-workaround-in-luks2-reencryption-mangle.patch:",
                            "      use gnudd as workaround in luks2-reencryption-mangle-test failing",
                            "      with rust-coreutils dd (see",
                            "      https://bugs.launchpad.net/ubuntu/+source/rust-coreutils/+bug/2143933)",
                            "  * Dropped changes, included in Debian:",
                            "    - askpass: Fix FTBFS with glibc 2.43 (in 2:2.8.6-1)",
                            "    - d/tests/control: Add cpio autopkgtest dependency (in 2:2.8.6-2)",
                            "    - d/p/tests-Fix-tests-to-not-use-aes-generic-kernel-cipher-name.patch:",
                            "      applied upstream (in 2:2.8.7-1)",
                            "    - d/p/Add-specific-error-for-failed-posix_fallocate-call.patch:",
                            "      applied upstream (in 2:2.8.7-1)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/control: Depend on busybox-initramfs instead of busybox |",
                            "      busybox-static (reverted in 2:2.8.4-1ubuntu5, matching Debian)",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163661
                        ],
                        "author": "Anshul Singh <anshul.singh@canonical.com>",
                        "date": "Mon, 17 Aug 2026 21:59:32 +0900"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream bugfix release.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Wed, 22 Jul 2026 01:53:08 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release candidate. (Closes: #1141257)",
                            "  * d/rules: Adjust blhc's ignore-line-regexp.",
                            "  * cryptsetup-suspend-wrapper: Replace `find … -execdir {}` call with a shell",
                            "    loop. (Closes: #1141157)",
                            "  * Refresh d/patches.",
                            "  * d/t/cryptroot-*: Install mount in the guests.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7~rc2-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Mon, 13 Jul 2026 16:47:12 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release candidate.",
                            "  * Drop d/patches/* applied upstream.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7~rc1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Tue, 30 Jun 2026 12:24:18 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-33948",
                                "url": "https://ubuntu.com/security/CVE-2026-33948",
                                "cve_description": "jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte count from fgets(), causing it to truncate input at the first NUL byte and parse only the preceding prefix. This enables an attacker to craft input with a benign JSON prefix before a NUL byte followed by malicious trailing data, where jq validates only the prefix as valid JSON while silently discarding the suffix. Workflows relying on jq to validate untrusted JSON before forwarding it to downstream consumers are susceptible to parser differential attacks, as those consumers may process the full input including the malicious trailing bytes. This issue has been patched by commit 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-14 00:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport upstream changes to fix FTBFS with recent jq(1). The jq upstream",
                            "    fix for CVE-2026-33948 breaks cryptsetup's test suite. (Closes: #1135390)",
                            "  * Update Standards-Version to 4.7.4 (no changes necessary).",
                            "  * d/t/cryptroot-*: Add \"Depends: cpio\".",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.6-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Sun, 03 May 2026 15:26:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream bugfix release.",
                            "  * askpass: Fix FTBFS with glibc 2.43. (Closes: #1128538)",
                            "  * d/control: Replace B-D: libselinux1-dev with libselinux-dev.",
                            "  * d/t/cryptroot-*: Account for the linux-image package split.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Thu, 02 Apr 2026 20:39:12 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.4-1ubuntu6",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:08 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Depend on busybox | busybox-static instead of busybox-initramfs",
                            "    (LP: #2157328)",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.4-1ubuntu5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2157328
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Fri, 17 Jul 2026 12:23:57 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "cryptsetup-bin",
                "from_version": {
                    "source_package_name": "cryptsetup",
                    "source_package_version": "2:2.8.4-1ubuntu4",
                    "version": "2:2.8.4-1ubuntu4"
                },
                "to_version": {
                    "source_package_name": "cryptsetup",
                    "source_package_version": "2:2.8.7-1ubuntu1",
                    "version": "2:2.8.7-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-33948",
                        "url": "https://ubuntu.com/security/CVE-2026-33948",
                        "cve_description": "jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte count from fgets(), causing it to truncate input at the first NUL byte and parse only the preceding prefix. This enables an attacker to craft input with a benign JSON prefix before a NUL byte followed by malicious trailing data, where jq validates only the prefix as valid JSON while silently discarding the suffix. Workflows relying on jq to validate untrusted JSON before forwarding it to downstream consumers are susceptible to parser differential attacks, as those consumers may process the full input including the malicious trailing bytes. This issue has been patched by commit 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-14 00:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163661,
                    2157328
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2163661). Remaining changes:",
                            "    - d/tests/utils/mkinitramfs: Support zstd compressed modules for self test",
                            "    - d/rules: Compile-in support for a FIPS mode. LP #2032659",
                            "    - d/control: Recommend plymouth",
                            "    - d/control: Move cryptsetup-initramfs back to cryptsetup Recommends,",
                            "      preferring dracut",
                            "    - d/{control,rules}: Disable building cryptsetup-suspend on i386",
                            "    - d/initramfs/cryptroot-unlock: Fix busybox/narrow compat LP #1968636",
                            "    - d/tests: Fix autopkgtests",
                            "      + d/tests/utils/mkinitramfs: Prevent linking attempt if file exists",
                            "      + d/tests/utils/cryptroot-common: Handle Ubuntu kernel package split",
                            "        (linux-image + linux-modules) when extracting the kernel",
                            "    - d/{functions,initramfs/hooks/cryptroot}: Fix ZFS root warning/error",
                            "      + d/functions: Return an empty devno for ZFS devices as they don't have",
                            "        major:minor device numbers.",
                            "      + d/initramfs/hooks/cryptroot: Ignore and don't print an error message",
                            "        when devices don't have a devno.",
                            "    - d/p/{no-dd-direct-flags-tmpfs,series}: Disable O_DIRECT on tmpfs",
                            "    - d/p/test-use-gnudd-as-workaround-in-luks2-reencryption-mangle.patch:",
                            "      use gnudd as workaround in luks2-reencryption-mangle-test failing",
                            "      with rust-coreutils dd (see",
                            "      https://bugs.launchpad.net/ubuntu/+source/rust-coreutils/+bug/2143933)",
                            "  * Dropped changes, included in Debian:",
                            "    - askpass: Fix FTBFS with glibc 2.43 (in 2:2.8.6-1)",
                            "    - d/tests/control: Add cpio autopkgtest dependency (in 2:2.8.6-2)",
                            "    - d/p/tests-Fix-tests-to-not-use-aes-generic-kernel-cipher-name.patch:",
                            "      applied upstream (in 2:2.8.7-1)",
                            "    - d/p/Add-specific-error-for-failed-posix_fallocate-call.patch:",
                            "      applied upstream (in 2:2.8.7-1)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/control: Depend on busybox-initramfs instead of busybox |",
                            "      busybox-static (reverted in 2:2.8.4-1ubuntu5, matching Debian)",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163661
                        ],
                        "author": "Anshul Singh <anshul.singh@canonical.com>",
                        "date": "Mon, 17 Aug 2026 21:59:32 +0900"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream bugfix release.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Wed, 22 Jul 2026 01:53:08 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release candidate. (Closes: #1141257)",
                            "  * d/rules: Adjust blhc's ignore-line-regexp.",
                            "  * cryptsetup-suspend-wrapper: Replace `find … -execdir {}` call with a shell",
                            "    loop. (Closes: #1141157)",
                            "  * Refresh d/patches.",
                            "  * d/t/cryptroot-*: Install mount in the guests.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7~rc2-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Mon, 13 Jul 2026 16:47:12 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release candidate.",
                            "  * Drop d/patches/* applied upstream.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7~rc1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Tue, 30 Jun 2026 12:24:18 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-33948",
                                "url": "https://ubuntu.com/security/CVE-2026-33948",
                                "cve_description": "jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte count from fgets(), causing it to truncate input at the first NUL byte and parse only the preceding prefix. This enables an attacker to craft input with a benign JSON prefix before a NUL byte followed by malicious trailing data, where jq validates only the prefix as valid JSON while silently discarding the suffix. Workflows relying on jq to validate untrusted JSON before forwarding it to downstream consumers are susceptible to parser differential attacks, as those consumers may process the full input including the malicious trailing bytes. This issue has been patched by commit 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-14 00:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport upstream changes to fix FTBFS with recent jq(1). The jq upstream",
                            "    fix for CVE-2026-33948 breaks cryptsetup's test suite. (Closes: #1135390)",
                            "  * Update Standards-Version to 4.7.4 (no changes necessary).",
                            "  * d/t/cryptroot-*: Add \"Depends: cpio\".",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.6-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Sun, 03 May 2026 15:26:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream bugfix release.",
                            "  * askpass: Fix FTBFS with glibc 2.43. (Closes: #1128538)",
                            "  * d/control: Replace B-D: libselinux1-dev with libselinux-dev.",
                            "  * d/t/cryptroot-*: Account for the linux-image package split.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Thu, 02 Apr 2026 20:39:12 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.4-1ubuntu6",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:08 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Depend on busybox | busybox-static instead of busybox-initramfs",
                            "    (LP: #2157328)",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.4-1ubuntu5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2157328
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Fri, 17 Jul 2026 12:23:57 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "debianutils",
                "from_version": {
                    "source_package_name": "debianutils",
                    "source_package_version": "5.23.2build1",
                    "version": "5.23.2build1"
                },
                "to_version": {
                    "source_package_name": "debianutils",
                    "source_package_version": "5.24",
                    "version": "5.24"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/control: Bump standards version from 4.7.2 to 4.7.4, bump",
                            "    debhelper-compat version from 13 to 14, and remove redundant",
                            "    field, Rules-Requires-Root: no.",
                            "  * acinclude.m4: Update DEBIANUTILS_VERSION to 5.24.",
                            "  * run-parts.c: Recognise short option for --debug (Closes: #1131363).",
                            "  * run-parts: Add options -A, --after and -B, --before for greater",
                            "    flexibility (Closes: #1131375).",
                            "  * d/tests/run-parts.test: Extend testing of run-parts for new options.",
                            ""
                        ],
                        "package": "debianutils",
                        "version": "5.24",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Ileana Dumitrescu <ileanadumitrescu95@gmail.com>",
                        "date": "Thu, 27 Aug 2026 17:54:35 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dhcpcd-base",
                "from_version": {
                    "source_package_name": "dhcpcd",
                    "source_package_version": "1:10.3.2-4",
                    "version": "1:10.3.2-4"
                },
                "to_version": {
                    "source_package_name": "dhcpcd",
                    "source_package_version": "1:10.3.2-6",
                    "version": "1:10.3.2-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * [autopkgtest]",
                            "    + Make the timesyncd test request an NTP server FQDN via DHCPv6 option 56.",
                            "    = Still request NTP server IPs via DHCPv4 option 42 and DHCPv6 option 31.",
                            ""
                        ],
                        "package": "dhcpcd",
                        "version": "1:10.3.2-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Martin-Éric Racine <martin-eric.racine@iki.fi>",
                        "date": "Mon, 27 Jul 2026 16:05:35 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * [autopkgtest]",
                            "    + Make the timesyncd test produce more usefull output.",
                            "  * [lintian-brush.conf]",
                            "    + Add override to maintain Bookworm compatibility.",
                            ""
                        ],
                        "package": "dhcpcd",
                        "version": "1:10.3.2-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Martin-Éric Racine <martin-eric.racine@iki.fi>",
                        "date": "Mon, 27 Jul 2026 12:01:25 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dirmngr",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu1",
                    "version": "2.4.9-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Change gpgv priority to optional (see LP#2163769)",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:21:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "distro-info-data",
                "from_version": {
                    "source_package_name": "distro-info-data",
                    "source_package_version": "2026.07.30-1",
                    "version": "2026.07.30-1"
                },
                "to_version": {
                    "source_package_name": "distro-info-data",
                    "source_package_version": "2026.08.20-1",
                    "version": "2026.08.20-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release:",
                            "    - Devuan experimental really is called experimental.",
                            ""
                        ],
                        "package": "distro-info-data",
                        "version": "2026.08.20-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Thu, 20 Aug 2026 10:36:09 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dracut",
                "from_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-1",
                    "version": "112-1"
                },
                "to_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-5",
                    "version": "112-5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2150657,
                    2166082
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - Support busybox applets",
                            "      + fix(i18n): support find applet from busybox in module-setup.sh",
                            "      + fix(convertfs): support find applet from busybox",
                            "      + fix(lsinitrd): use \"find -exec ls\" instead of \"find -ls\"",
                            "      + fix(dracut-functions): support head applet from busybox",
                            "      + fix(shutdown): make \"timeout\" call busybox-compatible",
                            "      + fix(znet): support mktemp applet from busybox in module-setup.sh",
                            "      + test: support mktemp applet from busybox",
                            "      + fix(systemd-cryptsetup): support grep applet from busybox",
                            "        in module-setup.sh",
                            "      + fix(url-lib): support grep applet from busybox in module-setup.sh",
                            "      + fix(dmsquash-live-autooverlay): support grep applet from busybox",
                            "      + test(FULL-SYSTEMD): avoid copying /usr twice",
                            "      + fix(base): support readlink applet from busybox",
                            "      + fix(dmsquash-live): support umount applet from busybox",
                            "      + fix(lvmmerge): support umount applet from busybox",
                            "      + fix(selinux): support umount applet from busybox",
                            "    - Use busybox instead of coreutils/rust-coreutils in initrd (LP: #2150657)",
                            "      + fix(busybox): use full path provided by busybox --list-full",
                            "      + fix(busybox): do not rely on CONFIG_FEATURE_INSTALLER=y",
                            "      + test: provide default test_setup hook",
                            "      + feat(busybox): run before 80base so applets replace host binaries",
                            "      + fix(busybox): do not install blkid if udev rules need -o",
                            "      + fix(busybox): do not install mount applet",
                            "      + test(BUSYBOX): use initramfs.testing as initrd name",
                            "      + test(BUSYBOX): also test booting",
                            "      + fix(busybox): do not install mke2fs applet",
                            "      + fix(busybox): do not install nbd-client applet",
                            "      + fix(busybox): do not install losetup applet",
                            "      + fix(busybox): do not install sulogin applet",
                            "      + fix(busybox): do not install blkid unconditionally",
                            "      + feat(dracut): add --prefer option",
                            "      + feat(debian.conf): prefer busybox",
                            "  * Support busybox built with CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix(nbd): use /usr/sbin/nbd-client for CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix(dracut-systemd): use /sbin/sulogin for CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix: use /sbin/losetup for CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix: use /bin/mount for CONFIG_FEATURE_PREFER_APPLETS",
                            "  * Renumber Dracut module 81busybox to 10busybox",
                            "  * Recommend busybox | busybox-static",
                            "  * Add 15-busybox autopkgtest (once for busybox and once for busybox-static)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2150657
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Mon, 07 Sep 2026 00:25:28 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - fix(dracut): correct order of \"Creating image\" log line",
                            "    - perf(lsinitrd): call extractor only once in extract_squash_img",
                            "    - fix(drm): add leds-qcom-lpg to aarch64 specific modules needed by drm",
                            "  * Ensure split dracut packages are upgraded together (Closes: #1146782)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Sun, 06 Sep 2026 13:35:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Document that the systemd-pcrextend module needs systemd-tpm",
                            "  * fix(chrony): support _chrony username",
                            "  * Fix failing 60-nfs autopkgtest on Ubuntu (LP: #2166082):",
                            "    - test(NFS): fix ETIMEDOUT error in rpc.nfsd call",
                            "    - test(NFS): always load the nfsv3 kernel module",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2166082
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Thu, 03 Sep 2026 01:44:40 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - Security related fixes:",
                            "      + fix(net-lib): normalize iSCSI target names on the iqn./eui./naa. path",
                            "      + fix(iscsi): do not source the boot-time net-lib.sh into module-setup.sh",
                            "      + fix(iscsi): normalize the target name in the generated netroot=",
                            "      + fix(dracut): --remove globbing does not work",
                            "      + fix(dracut): --remove allows removing files from the host filesystem",
                            "      + refactor(net-lib): use strip_non_digits() to validate iSCSI LUN",
                            "        parameters",
                            "      + fix(net-lib): validate iSCSI port parameters",
                            "      + fix(base): sanitize message written by die() to the emergency hook",
                            "      + fix(iscsi): sanitize netroot= value passed to initqueue scripts",
                            "    - fix(dracut-systemd): actually make rd.break=pre-trigger stop before",
                            "      pre-trigger",
                            "    - Support Qualcomm X2 laptop models:",
                            "      + refactor(devicetree-firmware): make looping over fw_dir top-level loop",
                            "      + fix(devicetree-firmware): include soc specific firmwares in",
                            "        install_generic()",
                            "      + fix(devicetree-firmware): include Qualcomm X2 laptop model specific",
                            "        firmwares",
                            "    - fix(dracut): disable hostonly-cmdline by default in container",
                            "    - fix(lsinitrd): do no sort cpio output if not needed",
                            "    - feat(dracut-initramfs-restore): support 3cpio",
                            "    - Put compressed kernel modules and firmware in an uncompressed cpio:",
                            "      + feat(Makefile): switch from gnu99 to gnu11 by default",
                            "      + feat: add extractinitrd",
                            "      + feat(lsinitrd): use extractinitrd",
                            "      + feat(dracut-initramfs-restore): use extractinitrd",
                            "      + chore: remove skipcpio",
                            "      + feat: put compressed kernel modules and firmware in an uncompressed",
                            "        cpio",
                            "  * Remove 81-skipcpio and add 83-extractinitrd autopkgtest",
                            "  * Reduce dependencies for 80-getarg autopkgtests",
                            "  * Increase verbosity of build time tests",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Wed, 26 Aug 2026 02:04:15 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dracut-core",
                "from_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-1",
                    "version": "112-1"
                },
                "to_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-5",
                    "version": "112-5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2150657,
                    2166082
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - Support busybox applets",
                            "      + fix(i18n): support find applet from busybox in module-setup.sh",
                            "      + fix(convertfs): support find applet from busybox",
                            "      + fix(lsinitrd): use \"find -exec ls\" instead of \"find -ls\"",
                            "      + fix(dracut-functions): support head applet from busybox",
                            "      + fix(shutdown): make \"timeout\" call busybox-compatible",
                            "      + fix(znet): support mktemp applet from busybox in module-setup.sh",
                            "      + test: support mktemp applet from busybox",
                            "      + fix(systemd-cryptsetup): support grep applet from busybox",
                            "        in module-setup.sh",
                            "      + fix(url-lib): support grep applet from busybox in module-setup.sh",
                            "      + fix(dmsquash-live-autooverlay): support grep applet from busybox",
                            "      + test(FULL-SYSTEMD): avoid copying /usr twice",
                            "      + fix(base): support readlink applet from busybox",
                            "      + fix(dmsquash-live): support umount applet from busybox",
                            "      + fix(lvmmerge): support umount applet from busybox",
                            "      + fix(selinux): support umount applet from busybox",
                            "    - Use busybox instead of coreutils/rust-coreutils in initrd (LP: #2150657)",
                            "      + fix(busybox): use full path provided by busybox --list-full",
                            "      + fix(busybox): do not rely on CONFIG_FEATURE_INSTALLER=y",
                            "      + test: provide default test_setup hook",
                            "      + feat(busybox): run before 80base so applets replace host binaries",
                            "      + fix(busybox): do not install blkid if udev rules need -o",
                            "      + fix(busybox): do not install mount applet",
                            "      + test(BUSYBOX): use initramfs.testing as initrd name",
                            "      + test(BUSYBOX): also test booting",
                            "      + fix(busybox): do not install mke2fs applet",
                            "      + fix(busybox): do not install nbd-client applet",
                            "      + fix(busybox): do not install losetup applet",
                            "      + fix(busybox): do not install sulogin applet",
                            "      + fix(busybox): do not install blkid unconditionally",
                            "      + feat(dracut): add --prefer option",
                            "      + feat(debian.conf): prefer busybox",
                            "  * Support busybox built with CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix(nbd): use /usr/sbin/nbd-client for CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix(dracut-systemd): use /sbin/sulogin for CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix: use /sbin/losetup for CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix: use /bin/mount for CONFIG_FEATURE_PREFER_APPLETS",
                            "  * Renumber Dracut module 81busybox to 10busybox",
                            "  * Recommend busybox | busybox-static",
                            "  * Add 15-busybox autopkgtest (once for busybox and once for busybox-static)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2150657
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Mon, 07 Sep 2026 00:25:28 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - fix(dracut): correct order of \"Creating image\" log line",
                            "    - perf(lsinitrd): call extractor only once in extract_squash_img",
                            "    - fix(drm): add leds-qcom-lpg to aarch64 specific modules needed by drm",
                            "  * Ensure split dracut packages are upgraded together (Closes: #1146782)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Sun, 06 Sep 2026 13:35:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Document that the systemd-pcrextend module needs systemd-tpm",
                            "  * fix(chrony): support _chrony username",
                            "  * Fix failing 60-nfs autopkgtest on Ubuntu (LP: #2166082):",
                            "    - test(NFS): fix ETIMEDOUT error in rpc.nfsd call",
                            "    - test(NFS): always load the nfsv3 kernel module",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2166082
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Thu, 03 Sep 2026 01:44:40 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - Security related fixes:",
                            "      + fix(net-lib): normalize iSCSI target names on the iqn./eui./naa. path",
                            "      + fix(iscsi): do not source the boot-time net-lib.sh into module-setup.sh",
                            "      + fix(iscsi): normalize the target name in the generated netroot=",
                            "      + fix(dracut): --remove globbing does not work",
                            "      + fix(dracut): --remove allows removing files from the host filesystem",
                            "      + refactor(net-lib): use strip_non_digits() to validate iSCSI LUN",
                            "        parameters",
                            "      + fix(net-lib): validate iSCSI port parameters",
                            "      + fix(base): sanitize message written by die() to the emergency hook",
                            "      + fix(iscsi): sanitize netroot= value passed to initqueue scripts",
                            "    - fix(dracut-systemd): actually make rd.break=pre-trigger stop before",
                            "      pre-trigger",
                            "    - Support Qualcomm X2 laptop models:",
                            "      + refactor(devicetree-firmware): make looping over fw_dir top-level loop",
                            "      + fix(devicetree-firmware): include soc specific firmwares in",
                            "        install_generic()",
                            "      + fix(devicetree-firmware): include Qualcomm X2 laptop model specific",
                            "        firmwares",
                            "    - fix(dracut): disable hostonly-cmdline by default in container",
                            "    - fix(lsinitrd): do no sort cpio output if not needed",
                            "    - feat(dracut-initramfs-restore): support 3cpio",
                            "    - Put compressed kernel modules and firmware in an uncompressed cpio:",
                            "      + feat(Makefile): switch from gnu99 to gnu11 by default",
                            "      + feat: add extractinitrd",
                            "      + feat(lsinitrd): use extractinitrd",
                            "      + feat(dracut-initramfs-restore): use extractinitrd",
                            "      + chore: remove skipcpio",
                            "      + feat: put compressed kernel modules and firmware in an uncompressed",
                            "        cpio",
                            "  * Remove 81-skipcpio and add 83-extractinitrd autopkgtest",
                            "  * Reduce dependencies for 80-getarg autopkgtests",
                            "  * Increase verbosity of build time tests",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Wed, 26 Aug 2026 02:04:15 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dracut-install",
                "from_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-1",
                    "version": "112-1"
                },
                "to_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-5",
                    "version": "112-5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2150657,
                    2166082
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - Support busybox applets",
                            "      + fix(i18n): support find applet from busybox in module-setup.sh",
                            "      + fix(convertfs): support find applet from busybox",
                            "      + fix(lsinitrd): use \"find -exec ls\" instead of \"find -ls\"",
                            "      + fix(dracut-functions): support head applet from busybox",
                            "      + fix(shutdown): make \"timeout\" call busybox-compatible",
                            "      + fix(znet): support mktemp applet from busybox in module-setup.sh",
                            "      + test: support mktemp applet from busybox",
                            "      + fix(systemd-cryptsetup): support grep applet from busybox",
                            "        in module-setup.sh",
                            "      + fix(url-lib): support grep applet from busybox in module-setup.sh",
                            "      + fix(dmsquash-live-autooverlay): support grep applet from busybox",
                            "      + test(FULL-SYSTEMD): avoid copying /usr twice",
                            "      + fix(base): support readlink applet from busybox",
                            "      + fix(dmsquash-live): support umount applet from busybox",
                            "      + fix(lvmmerge): support umount applet from busybox",
                            "      + fix(selinux): support umount applet from busybox",
                            "    - Use busybox instead of coreutils/rust-coreutils in initrd (LP: #2150657)",
                            "      + fix(busybox): use full path provided by busybox --list-full",
                            "      + fix(busybox): do not rely on CONFIG_FEATURE_INSTALLER=y",
                            "      + test: provide default test_setup hook",
                            "      + feat(busybox): run before 80base so applets replace host binaries",
                            "      + fix(busybox): do not install blkid if udev rules need -o",
                            "      + fix(busybox): do not install mount applet",
                            "      + test(BUSYBOX): use initramfs.testing as initrd name",
                            "      + test(BUSYBOX): also test booting",
                            "      + fix(busybox): do not install mke2fs applet",
                            "      + fix(busybox): do not install nbd-client applet",
                            "      + fix(busybox): do not install losetup applet",
                            "      + fix(busybox): do not install sulogin applet",
                            "      + fix(busybox): do not install blkid unconditionally",
                            "      + feat(dracut): add --prefer option",
                            "      + feat(debian.conf): prefer busybox",
                            "  * Support busybox built with CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix(nbd): use /usr/sbin/nbd-client for CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix(dracut-systemd): use /sbin/sulogin for CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix: use /sbin/losetup for CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix: use /bin/mount for CONFIG_FEATURE_PREFER_APPLETS",
                            "  * Renumber Dracut module 81busybox to 10busybox",
                            "  * Recommend busybox | busybox-static",
                            "  * Add 15-busybox autopkgtest (once for busybox and once for busybox-static)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2150657
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Mon, 07 Sep 2026 00:25:28 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - fix(dracut): correct order of \"Creating image\" log line",
                            "    - perf(lsinitrd): call extractor only once in extract_squash_img",
                            "    - fix(drm): add leds-qcom-lpg to aarch64 specific modules needed by drm",
                            "  * Ensure split dracut packages are upgraded together (Closes: #1146782)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Sun, 06 Sep 2026 13:35:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Document that the systemd-pcrextend module needs systemd-tpm",
                            "  * fix(chrony): support _chrony username",
                            "  * Fix failing 60-nfs autopkgtest on Ubuntu (LP: #2166082):",
                            "    - test(NFS): fix ETIMEDOUT error in rpc.nfsd call",
                            "    - test(NFS): always load the nfsv3 kernel module",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2166082
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Thu, 03 Sep 2026 01:44:40 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - Security related fixes:",
                            "      + fix(net-lib): normalize iSCSI target names on the iqn./eui./naa. path",
                            "      + fix(iscsi): do not source the boot-time net-lib.sh into module-setup.sh",
                            "      + fix(iscsi): normalize the target name in the generated netroot=",
                            "      + fix(dracut): --remove globbing does not work",
                            "      + fix(dracut): --remove allows removing files from the host filesystem",
                            "      + refactor(net-lib): use strip_non_digits() to validate iSCSI LUN",
                            "        parameters",
                            "      + fix(net-lib): validate iSCSI port parameters",
                            "      + fix(base): sanitize message written by die() to the emergency hook",
                            "      + fix(iscsi): sanitize netroot= value passed to initqueue scripts",
                            "    - fix(dracut-systemd): actually make rd.break=pre-trigger stop before",
                            "      pre-trigger",
                            "    - Support Qualcomm X2 laptop models:",
                            "      + refactor(devicetree-firmware): make looping over fw_dir top-level loop",
                            "      + fix(devicetree-firmware): include soc specific firmwares in",
                            "        install_generic()",
                            "      + fix(devicetree-firmware): include Qualcomm X2 laptop model specific",
                            "        firmwares",
                            "    - fix(dracut): disable hostonly-cmdline by default in container",
                            "    - fix(lsinitrd): do no sort cpio output if not needed",
                            "    - feat(dracut-initramfs-restore): support 3cpio",
                            "    - Put compressed kernel modules and firmware in an uncompressed cpio:",
                            "      + feat(Makefile): switch from gnu99 to gnu11 by default",
                            "      + feat: add extractinitrd",
                            "      + feat(lsinitrd): use extractinitrd",
                            "      + feat(dracut-initramfs-restore): use extractinitrd",
                            "      + chore: remove skipcpio",
                            "      + feat: put compressed kernel modules and firmware in an uncompressed",
                            "        cpio",
                            "  * Remove 81-skipcpio and add 83-extractinitrd autopkgtest",
                            "  * Reduce dependencies for 80-getarg autopkgtests",
                            "  * Increase verbosity of build time tests",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Wed, 26 Aug 2026 02:04:15 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dracut-network",
                "from_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-1",
                    "version": "112-1"
                },
                "to_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-5",
                    "version": "112-5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2150657,
                    2166082
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - Support busybox applets",
                            "      + fix(i18n): support find applet from busybox in module-setup.sh",
                            "      + fix(convertfs): support find applet from busybox",
                            "      + fix(lsinitrd): use \"find -exec ls\" instead of \"find -ls\"",
                            "      + fix(dracut-functions): support head applet from busybox",
                            "      + fix(shutdown): make \"timeout\" call busybox-compatible",
                            "      + fix(znet): support mktemp applet from busybox in module-setup.sh",
                            "      + test: support mktemp applet from busybox",
                            "      + fix(systemd-cryptsetup): support grep applet from busybox",
                            "        in module-setup.sh",
                            "      + fix(url-lib): support grep applet from busybox in module-setup.sh",
                            "      + fix(dmsquash-live-autooverlay): support grep applet from busybox",
                            "      + test(FULL-SYSTEMD): avoid copying /usr twice",
                            "      + fix(base): support readlink applet from busybox",
                            "      + fix(dmsquash-live): support umount applet from busybox",
                            "      + fix(lvmmerge): support umount applet from busybox",
                            "      + fix(selinux): support umount applet from busybox",
                            "    - Use busybox instead of coreutils/rust-coreutils in initrd (LP: #2150657)",
                            "      + fix(busybox): use full path provided by busybox --list-full",
                            "      + fix(busybox): do not rely on CONFIG_FEATURE_INSTALLER=y",
                            "      + test: provide default test_setup hook",
                            "      + feat(busybox): run before 80base so applets replace host binaries",
                            "      + fix(busybox): do not install blkid if udev rules need -o",
                            "      + fix(busybox): do not install mount applet",
                            "      + test(BUSYBOX): use initramfs.testing as initrd name",
                            "      + test(BUSYBOX): also test booting",
                            "      + fix(busybox): do not install mke2fs applet",
                            "      + fix(busybox): do not install nbd-client applet",
                            "      + fix(busybox): do not install losetup applet",
                            "      + fix(busybox): do not install sulogin applet",
                            "      + fix(busybox): do not install blkid unconditionally",
                            "      + feat(dracut): add --prefer option",
                            "      + feat(debian.conf): prefer busybox",
                            "  * Support busybox built with CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix(nbd): use /usr/sbin/nbd-client for CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix(dracut-systemd): use /sbin/sulogin for CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix: use /sbin/losetup for CONFIG_FEATURE_PREFER_APPLETS",
                            "    - fix: use /bin/mount for CONFIG_FEATURE_PREFER_APPLETS",
                            "  * Renumber Dracut module 81busybox to 10busybox",
                            "  * Recommend busybox | busybox-static",
                            "  * Add 15-busybox autopkgtest (once for busybox and once for busybox-static)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2150657
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Mon, 07 Sep 2026 00:25:28 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - fix(dracut): correct order of \"Creating image\" log line",
                            "    - perf(lsinitrd): call extractor only once in extract_squash_img",
                            "    - fix(drm): add leds-qcom-lpg to aarch64 specific modules needed by drm",
                            "  * Ensure split dracut packages are upgraded together (Closes: #1146782)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Sun, 06 Sep 2026 13:35:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Document that the systemd-pcrextend module needs systemd-tpm",
                            "  * fix(chrony): support _chrony username",
                            "  * Fix failing 60-nfs autopkgtest on Ubuntu (LP: #2166082):",
                            "    - test(NFS): fix ETIMEDOUT error in rpc.nfsd call",
                            "    - test(NFS): always load the nfsv3 kernel module",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2166082
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Thu, 03 Sep 2026 01:44:40 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - Security related fixes:",
                            "      + fix(net-lib): normalize iSCSI target names on the iqn./eui./naa. path",
                            "      + fix(iscsi): do not source the boot-time net-lib.sh into module-setup.sh",
                            "      + fix(iscsi): normalize the target name in the generated netroot=",
                            "      + fix(dracut): --remove globbing does not work",
                            "      + fix(dracut): --remove allows removing files from the host filesystem",
                            "      + refactor(net-lib): use strip_non_digits() to validate iSCSI LUN",
                            "        parameters",
                            "      + fix(net-lib): validate iSCSI port parameters",
                            "      + fix(base): sanitize message written by die() to the emergency hook",
                            "      + fix(iscsi): sanitize netroot= value passed to initqueue scripts",
                            "    - fix(dracut-systemd): actually make rd.break=pre-trigger stop before",
                            "      pre-trigger",
                            "    - Support Qualcomm X2 laptop models:",
                            "      + refactor(devicetree-firmware): make looping over fw_dir top-level loop",
                            "      + fix(devicetree-firmware): include soc specific firmwares in",
                            "        install_generic()",
                            "      + fix(devicetree-firmware): include Qualcomm X2 laptop model specific",
                            "        firmwares",
                            "    - fix(dracut): disable hostonly-cmdline by default in container",
                            "    - fix(lsinitrd): do no sort cpio output if not needed",
                            "    - feat(dracut-initramfs-restore): support 3cpio",
                            "    - Put compressed kernel modules and firmware in an uncompressed cpio:",
                            "      + feat(Makefile): switch from gnu99 to gnu11 by default",
                            "      + feat: add extractinitrd",
                            "      + feat(lsinitrd): use extractinitrd",
                            "      + feat(dracut-initramfs-restore): use extractinitrd",
                            "      + chore: remove skipcpio",
                            "      + feat: put compressed kernel modules and firmware in an uncompressed",
                            "        cpio",
                            "  * Remove 81-skipcpio and add 83-extractinitrd autopkgtest",
                            "  * Reduce dependencies for 80-getarg autopkgtests",
                            "  * Increase verbosity of build time tests",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Wed, 26 Aug 2026 02:04:15 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ethtool",
                "from_version": {
                    "source_package_name": "ethtool",
                    "source_package_version": "1:7.0-1",
                    "version": "1:7.0-1"
                },
                "to_version": {
                    "source_package_name": "ethtool",
                    "source_package_version": "1:7.1-1",
                    "version": "1:7.1-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release: 7.1",
                            ""
                        ],
                        "package": "ethtool",
                        "version": "1:7.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Salvatore Bonaccorso <carnil@debian.org>",
                        "date": "Wed, 15 Jul 2026 09:46:17 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "exfatprogs",
                "from_version": {
                    "source_package_name": "exfatprogs",
                    "source_package_version": "1.4.2-2",
                    "version": "1.4.2-2"
                },
                "to_version": {
                    "source_package_name": "exfatprogs",
                    "source_package_version": "1.4.3-1",
                    "version": "1.4.3-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "    - Honor the user's full locale for diagnostic messages and date formatting.",
                            "    - Fix GUIDs generation with correct version and variant fields.",
                            ""
                        ],
                        "package": "exfatprogs",
                        "version": "1.4.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Hoexter <hoexter@debian.org>",
                        "date": "Tue, 18 Aug 2026 19:44:24 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ftp",
                "from_version": {
                    "source_package_name": "tnftp",
                    "source_package_version": "20260211-2",
                    "version": "20260211-2"
                },
                "to_version": {
                    "source_package_name": "tnftp",
                    "source_package_version": "20260211-2build1",
                    "version": "20260211-2build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "tnftp",
                        "version": "20260211-2build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 16:32:26 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gcc-16-base:ppc64el",
                "from_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.1.0-2ubuntu1",
                    "version": "16.1.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-1ubuntu1",
                    "version": "16.2.0-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158577
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 09 Aug 2026 06:21:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * GCC 16.2.0 release.",
                            "    - Fix PR target/126581 (x86), PR tree-optimization/126504,",
                            "      PR tree-optimization/126503, PR middle-end/126497,",
                            "      PR tree-optimization/126490, PR tree-optimization/126464,",
                            "      PR tree-optimization/126476, PR tree-optimization/126464,",
                            "      PR middle-end/126084, PR tree-optimization/126471, PR target/126446,",
                            "      PR middle-end/126410, PR tree-optimization/126457,",
                            "      PR tree-optimization/126404, PR tree-optimization/126404,",
                            "      PR target/126438 (PPC), PR target/126450 (x86), PR middle-end/126447,",
                            "      PR middle-end/126405, PR rtl-optimization/126184,",
                            "      PR rtl-optimization/126184, PR target/126429 (x86),",
                            "      PR tree-optimization/125396, PR tree-optimization/125290,",
                            "      PR target/126320 (x86), PR middle-end/126341, PR target/123625 (AArch64),",
                            "      PR target/121957 (AArch64), PR rtl-optimization/125209,",
                            "      PR middle-end/124637, PR tree-optimization/126171,",
                            "      PR tree-optimization/126225, PR tree-optimization/124663, PR ipa/125207,",
                            "      PR target/119210 (AArch64), PR target/105116, PR driver/1240,",
                            "      PR ada/126553, PR ada/126379, PR ada/126482, PR algol68/126330,",
                            "      PR c++/126309, PR c++/126508, PR c++/126420, PR c++/126423,",
                            "      PR c++/126343, PR c++/126406, PR c++/119343, PR c++/126209,",
                            "      PR c++/126310, PR c++/126280, PR c++/126215, PR driver/124058,",
                            "      PR fortran/125866, PR fortran/126386, PR fortran/126303,",
                            "      PR fortran/97592, PR fortran/125998, PR sanitizer/126307,",
                            "      PR libstdc++/122197, PR libstdc++/124854, PR libstdc++/116110,",
                            "      PR libstdc++/124853, PR libstdc++/116110, PR libstdc++/124852,",
                            "      PR libstdc++/124852, PR libstdc++/124851, PR libstdc++/123165.",
                            "  * Update to git 20260809 from the gcc-16 branch.",
                            "    - Fix PR target/126484 (MIPS), PR tree-optimization/126576,",
                            "      PR tree-optimization/126547, PR tree-optimization/126549,",
                            "      PR tree-optimization/126564, PR tree-optimization/126601,",
                            "      PR target/124948, PR tree-optimization/126464, PR preprocessor/125048,",
                            "      PR libstdc++/125200, PR c++/125591, PR c++/125601, PR c++/125680,",
                            "      PR c++/125541, PR fortran/126205, PR target/126667 (S390),",
                            "      PR fortran/125263.",
                            "",
                            "  [ Matthias Klose ]",
                            "  * Update libgcc-s, libcc1, libasan and libgcobol symbols files.",
                            "  * d/rules2: Use rva23u64 with zifencei extension for Ubuntu (Vladimir Petko).",
                            "    LP: #2158577.",
                            "  * d/rules: Reformat riscv64 extensions for Debian.",
                            "  * Configure with --enable-checking=release on every architecture.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * d/rules2: Use rva20u64 with zifencei extension for Debian.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2158577
                        ],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 09 Aug 2026 06:10:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 19 Jul 2026 14:16:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260719 from the gcc-16 branch.",
                            "    - Fix PR tree-optimization/126262, PR tree-optimization/126257,",
                            "      PR middle-end/126084, PR tree-optimization/120201,",
                            "      PR tree-optimization/126194, PR tree-optimization/126150,",
                            "      PR tree-optimization/125953, PR middle-end/125875,",
                            "      PR tree-optimization/125786, PR tree-optimization/125668,",
                            "      PR tree-optimization/125296, PR tree-optimization/126008,",
                            "      PR tree-optimization/125730, PR tree-optimization/125040,",
                            "      PR ipa/125121, PR ipa/124128, PR target/126054 (S390),",
                            "      PR target/126148 (x86), PR tree-optimization/125597,",
                            "      PR tree-optimization/125597, PR tree-optimization/125597,",
                            "      PR target/126081 (or1k), PR target/126049 (RISCV),",
                            "      PR target/126098 (x86), PR target/67459 (SH), PR target/122948 (SH),",
                            "      PR target/125972 (S390), PR rtl-optimization/125173,",
                            "      PR target/124908 (AArch64), PR target/125838 (AArch64),",
                            "      PR target/125883 (x86), PR target/125818 (AArch64),",
                            "      PR target/125469 (x86), PR target/125469 (x86), PR target/125949 (x86),",
                            "      PR target/125992 (S390), PR middle-end/125977, PR target/125628 (MIPS),",
                            "      PR target/125478 (RISCV), PR target/106895 (PPC), PR target/122665 (PPC),",
                            "      PR target/125670 (RISCV), PR middle-end/125621,",
                            "      PR target/125148 (AArch64), PR tree-optimization/125431,",
                            "      PR target/125795 (AArch64), PR tree-optimization/125501,",
                            "      PR tree-optimization/125776, PR tree-optimization/125774,",
                            "      PR target/120144 (MIPS), PR ipa/125699, PR tree-optimization/125419,",
                            "      PR tree-optimization/125652, PR tree-optimization/125686,",
                            "      PR tree-optimization/125646, PR tree-optimization/125553,",
                            "      PR tree-optimization/125545, PR tree-optimization/125502,",
                            "      PR tree-optimization/125477, PR target/124948, PR c/125072, PR c/125935,",
                            "      PR c/125604, PR c/123569, PR c/125252, PR c/124303, PR c/124985,",
                            "      PR c++/126057, PR c++/126036, PR c++/126007, PR c++/125674, PR c++/91155,",
                            "      PR c++/126066, PR c++/125901, PR c++/126031, PR c++/121552, PR c++/124584,",
                            "      PR c++/121094, PR c++/117259, PR c++/123536, PR c++/125900, PR c++/125334,",
                            "      PR c++/125768, PR c++/125939, PR c++/125745, PR c++/125408, PR c++/124978,",
                            "      PR c++/115314, PR c++/125889, PR c++/125764, PR c++/125759, PR c++/65271,",
                            "      PR c++/125770, PR fortran/126234, PR fortran/125172, PR fortran/126210,",
                            "      PR fortran/126170, PR fortran/126127, PR fortran/103367,",
                            "      PR fortran/126018, PR fortran/125051, PR fortran/125902,",
                            "      PR fortran/125902, PR fortran/60576, PR fortran/125430,",
                            "      PR fortran/125527, PR fortran/125535, PR fortran/125650,",
                            "      PR fortran/125481, PR fortran/125527, PR fortran/125528,",
                            "      PR fortran/125529, PR fortran/125530, PR fortran/125531,",
                            "      PR fortran/125534, PR fortran/125535, PR lto/125257, PR libgcc/123976,",
                            "      PR target/125752 (AVR), PR libfortran/126116, PR libstdc++/126111,",
                            "      PR libstdc++/125956, PR libstdc++/118158, PR libstdc++/125228,",
                            "      PR libstdc++/125890.",
                            "  * Let the ada build fail on an alihash mismatch, if fail_on_alihash_mismatch",
                            "    is enabled.",
                            "  * Enable Modula-2 on powerpc and ppc64. Closes: #1141560, #1141596.",
                            "  * Enable LRA by default on m68k for snapshot builds (Adrian Glaubitz).",
                            "    Addresses: #1142039.",
                            "  * Disable running tests on Debian/riscv64 for meaningful build times.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 19 Jul 2026 13:28:39 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gettext-base",
                "from_version": {
                    "source_package_name": "gettext",
                    "source_package_version": "0.23.2-1",
                    "version": "0.23.2-1"
                },
                "to_version": {
                    "source_package_name": "gettext",
                    "source_package_version": "1.0-3",
                    "version": "1.0-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Change python3 build-dependency to be python3:any for cross-builds.",
                            "    Thanks to Helmut Grohne. Closes: #1141301.",
                            ""
                        ],
                        "package": "gettext",
                        "version": "1.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Santiago Vila <sanvila@debian.org>",
                        "date": "Thu, 02 Jul 2026 20:55:00 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip test-getaddrinfo. Closes: #1141154.",
                            "  * Do not pass XFAIL_TESTS to dh_auto_test anymore.",
                            "  * Drop unused lintian override.",
                            ""
                        ],
                        "package": "gettext",
                        "version": "1.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Santiago Vila <sanvila@debian.org>",
                        "date": "Tue, 30 Jun 2026 18:20:00 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release. Closes: #1101483.",
                            "  * Drop old patches, not needed anymore.",
                            "  * Enable all tests again.",
                            "  * Add python3 to Recommends, required by new program spit.",
                            "  * Update some lintian overrides.",
                            ""
                        ],
                        "package": "gettext",
                        "version": "1.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Santiago Vila <sanvila@debian.org>",
                        "date": "Tue, 16 Jun 2026 16:40:00 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Apply patch from Bruno Haible to allow building with glibc 2.43.",
                            "  * Skip test-pr_xid_continue and test-pr_xid_start (libunistring 1.4).",
                            "  * Refresh signing key.",
                            "  * Update standards-version.",
                            ""
                        ],
                        "package": "gettext",
                        "version": "0.26-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Santiago Vila <sanvila@debian.org>",
                        "date": "Thu, 21 May 2026 20:45:00 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Temporarily disable tests broken by libunistring 1.4.",
                            "  * Drop references to kfreebsd-any (lintian error).",
                            "  * Update standards-version.",
                            ""
                        ],
                        "package": "gettext",
                        "version": "0.23.2-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Santiago Vila <sanvila@debian.org>",
                        "date": "Sun, 22 Mar 2026 10:55:00 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gir1.2-girepository-3.0:ppc64el",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.2-1",
                    "version": "2.89.2-1"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.3-4",
                    "version": "2.89.3-4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from unstable",
                            "    - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "      d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "      Add patches from upstream (to be released in 2.89.4) to address",
                            "      an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "      and fix a related test failure on minimal systems",
                            "      (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            "  * d/p/workarounds: Mark memory-monitor-psi tests as flaky",
                            "    (Mitigates: #1143197, #1143241)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-4",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 21:28:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon McVittie ]",
                            "  * Merge packaging from unstable",
                            "    - d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "      by ensuring that user-session-migration gets removed rather than",
                            "      making libglib2.0-0t64 be reinstalled",
                            "  * Drop patches added by 2.88.3-2, already part of 2.89.x",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 06 Aug 2026 14:23:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate",
                            "    previous changelog entry",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * debian/libglib2.0-0t64.symbols: Add new symbols",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 15:55:39 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "    d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "    Add patches from upstream (to be released in 2.89.4) to address",
                            "    an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "    and fix a related test failure on minimal systems",
                            "    (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 10:10:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport patches from 2.89.0 to harden D-Bus introspection parsing",
                            "    - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,",
                            "      d/p/tests-Improve-D-Bus-introspection-test-paths.patch,",
                            "      d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,",
                            "      d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:",
                            "      Avoid a possible integer underflow if parsing malformed D-Bus",
                            "      introspection XML sent by a malicious service",
                            "      (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)",
                            "  * d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "    by ensuring that user-session-migration gets removed rather than",
                            "    making libglib2.0-0t64 be reinstalled",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:22:30 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "    - Fixes resource exhaustion if a malicious client can contact a",
                            "      GDBusServer (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/control, d/gbp.conf: Use debian/forky branch",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:13:54 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gir1.2-glib-2.0:ppc64el",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.2-1",
                    "version": "2.89.2-1"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.3-4",
                    "version": "2.89.3-4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from unstable",
                            "    - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "      d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "      Add patches from upstream (to be released in 2.89.4) to address",
                            "      an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "      and fix a related test failure on minimal systems",
                            "      (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            "  * d/p/workarounds: Mark memory-monitor-psi tests as flaky",
                            "    (Mitigates: #1143197, #1143241)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-4",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 21:28:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon McVittie ]",
                            "  * Merge packaging from unstable",
                            "    - d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "      by ensuring that user-session-migration gets removed rather than",
                            "      making libglib2.0-0t64 be reinstalled",
                            "  * Drop patches added by 2.88.3-2, already part of 2.89.x",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 06 Aug 2026 14:23:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate",
                            "    previous changelog entry",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * debian/libglib2.0-0t64.symbols: Add new symbols",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 15:55:39 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "    d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "    Add patches from upstream (to be released in 2.89.4) to address",
                            "    an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "    and fix a related test failure on minimal systems",
                            "    (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 10:10:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport patches from 2.89.0 to harden D-Bus introspection parsing",
                            "    - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,",
                            "      d/p/tests-Improve-D-Bus-introspection-test-paths.patch,",
                            "      d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,",
                            "      d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:",
                            "      Avoid a possible integer underflow if parsing malformed D-Bus",
                            "      introspection XML sent by a malicious service",
                            "      (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)",
                            "  * d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "    by ensuring that user-session-migration gets removed rather than",
                            "    making libglib2.0-0t64 be reinstalled",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:22:30 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "    - Fixes resource exhaustion if a malicious client can contact a",
                            "      GDBusServer (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/control, d/gbp.conf: Use debian/forky branch",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:13:54 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "git",
                "from_version": {
                    "source_package_name": "git",
                    "source_package_version": "1:2.53.0-1ubuntu1",
                    "version": "1:2.53.0-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "git",
                    "source_package_version": "1:2.55.0-1ubuntu1",
                    "version": "1:2.55.0-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable. Remaining changes:",
                            "    - Build diff-highlight in the contrib dir",
                            "    - Don't build-depend on subversion on i386, it is not reasonable to",
                            "      support on the partial arch.",
                            ""
                        ],
                        "package": "git",
                        "version": "1:2.55.0-1ubuntu1",
                        "urgency": "low",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Gianfranco Costamagna <locutusofborg@debian.org>",
                        "date": "Tue, 04 Aug 2026 12:18:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * new upstream release (see RelNotes/2.54.0.adoc, 2.55.0.adoc).",
                            "  * debian/rules: disable Rust for now.",
                            ""
                        ],
                        "package": "git",
                        "version": "1:2.55.0-1",
                        "urgency": "low",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jonathan Nieder <jrnieder@gmail.com>",
                        "date": "Sun, 02 Aug 2026 16:39:03 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "git-man",
                "from_version": {
                    "source_package_name": "git",
                    "source_package_version": "1:2.53.0-1ubuntu1",
                    "version": "1:2.53.0-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "git",
                    "source_package_version": "1:2.55.0-1ubuntu1",
                    "version": "1:2.55.0-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable. Remaining changes:",
                            "    - Build diff-highlight in the contrib dir",
                            "    - Don't build-depend on subversion on i386, it is not reasonable to",
                            "      support on the partial arch.",
                            ""
                        ],
                        "package": "git",
                        "version": "1:2.55.0-1ubuntu1",
                        "urgency": "low",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Gianfranco Costamagna <locutusofborg@debian.org>",
                        "date": "Tue, 04 Aug 2026 12:18:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * new upstream release (see RelNotes/2.54.0.adoc, 2.55.0.adoc).",
                            "  * debian/rules: disable Rust for now.",
                            ""
                        ],
                        "package": "git",
                        "version": "1:2.55.0-1",
                        "urgency": "low",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jonathan Nieder <jrnieder@gmail.com>",
                        "date": "Sun, 02 Aug 2026 16:39:03 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gnu-coreutils",
                "from_version": {
                    "source_package_name": "coreutils",
                    "source_package_version": "9.10-1ubuntu1",
                    "version": "9.10-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "coreutils",
                    "source_package_version": "9.10-1ubuntu2",
                    "version": "9.10-1ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-56391",
                        "url": "https://ubuntu.com/security/CVE-2026-56391",
                        "cve_description": "GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.  When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.   This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-24 09:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-56391",
                                "url": "https://ubuntu.com/security/CVE-2026-56391",
                                "cve_description": "GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.  When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.   This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-24 09:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: out‑of‑bounds read in uniq",
                            "    - debian/patches/CVE-2026-56391.patch: uniq: fix read overrun with -w in",
                            "      src/uniq.c, tests/uniq/uniq.pl.",
                            "    - CVE-2026-56391",
                            ""
                        ],
                        "package": "coreutils",
                        "version": "9.10-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 11:06:22 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gnupg",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu1",
                    "version": "2.4.9-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Change gpgv priority to optional (see LP#2163769)",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:21:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gnupg-l10n",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu1",
                    "version": "2.4.9-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Change gpgv priority to optional (see LP#2163769)",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:21:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gnupg-utils",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu1",
                    "version": "2.4.9-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Change gpgv priority to optional (see LP#2163769)",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:21:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gpg",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu1",
                    "version": "2.4.9-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Change gpgv priority to optional (see LP#2163769)",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:21:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gpg-agent",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu1",
                    "version": "2.4.9-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Change gpgv priority to optional (see LP#2163769)",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:21:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gpg-wks-client",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu1",
                    "version": "2.4.9-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Change gpgv priority to optional (see LP#2163769)",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:21:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gpgconf",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu1",
                    "version": "2.4.9-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Change gpgv priority to optional (see LP#2163769)",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:21:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gpgsm",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu1",
                    "version": "2.4.9-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Change gpgv priority to optional (see LP#2163769)",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:21:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gpgv",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu1",
                    "version": "2.4.9-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Change gpgv priority to optional (see LP#2163769)",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:21:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "htop",
                "from_version": {
                    "source_package_name": "htop",
                    "source_package_version": "3.5.2-1",
                    "version": "3.5.2-1"
                },
                "to_version": {
                    "source_package_name": "htop",
                    "source_package_version": "3.5.3-1",
                    "version": "3.5.3-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "htop",
                        "version": "3.5.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Daniel Lange <DLange@debian.org>",
                        "date": "Sun, 16 Aug 2026 18:12:00 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "initramfs-tools-bin",
                "from_version": {
                    "source_package_name": "initramfs-tools",
                    "source_package_version": "0.151ubuntu1",
                    "version": "0.151ubuntu1"
                },
                "to_version": {
                    "source_package_name": "initramfs-tools",
                    "source_package_version": "0.151ubuntu2",
                    "version": "0.151ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2157328,
                    2154301
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop depending on busybox-initramfs and recommend busybox or busybox-static.",
                            "    The busybox-initramfs package is smaller than the busybox package, but the",
                            "    size of busybox + glibc is a tiny fraction of Ubuntu's initrd. Carrying this",
                            "    busybox delta in Ubuntu is not worth the effort. (LP: #2157328)",
                            "  * Drop setting hard-coded IPV6NETMASK='128' (LP: #2154301)",
                            ""
                        ],
                        "package": "initramfs-tools",
                        "version": "0.151ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2157328,
                            2154301
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Mon, 20 Jul 2026 10:27:32 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "initramfs-tools-core",
                "from_version": {
                    "source_package_name": "initramfs-tools",
                    "source_package_version": "0.151ubuntu1",
                    "version": "0.151ubuntu1"
                },
                "to_version": {
                    "source_package_name": "initramfs-tools",
                    "source_package_version": "0.151ubuntu2",
                    "version": "0.151ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2157328,
                    2154301
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop depending on busybox-initramfs and recommend busybox or busybox-static.",
                            "    The busybox-initramfs package is smaller than the busybox package, but the",
                            "    size of busybox + glibc is a tiny fraction of Ubuntu's initrd. Carrying this",
                            "    busybox delta in Ubuntu is not worth the effort. (LP: #2157328)",
                            "  * Drop setting hard-coded IPV6NETMASK='128' (LP: #2154301)",
                            ""
                        ],
                        "package": "initramfs-tools",
                        "version": "0.151ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2157328,
                            2154301
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Mon, 20 Jul 2026 10:27:32 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "jq",
                "from_version": {
                    "source_package_name": "jq",
                    "source_package_version": "1.8.1-4ubuntu1",
                    "version": "1.8.1-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "jq",
                    "source_package_version": "1.8.2-1ubuntu1",
                    "version": "1.8.2-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-49839",
                        "url": "https://ubuntu.com/security/CVE-2026-49839",
                        "cve_description": "jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-25 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47770",
                        "url": "https://ubuntu.com/security/CVE-2026-47770",
                        "cve_description": "jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-25 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40612",
                        "url": "https://ubuntu.com/security/CVE-2026-40612",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-41256",
                        "url": "https://ubuntu.com/security/CVE-2026-41256",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-41257",
                        "url": "https://ubuntu.com/security/CVE-2026-41257",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-43894",
                        "url": "https://ubuntu.com/security/CVE-2026-43894",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-43895",
                        "url": "https://ubuntu.com/security/CVE-2026-43895",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-43896",
                        "url": "https://ubuntu.com/security/CVE-2026-43896",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-44777",
                        "url": "https://ubuntu.com/security/CVE-2026-44777",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-32316",
                        "url": "https://ubuntu.com/security/CVE-2026-32316",
                        "cve_description": "jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, resulting in a drastically undersized heap buffer. Subsequent memory copy operations then write the full string data into this undersized buffer, causing a heap buffer overflow classified as CWE-190 (Integer Overflow) leading to CWE-122 (Heap-based Buffer Overflow). Any system evaluating untrusted jq queries is affected, as an attacker can crash the process or potentially achieve further exploitation through heap corruption by crafting queries that produce extremely large strings. The root cause is the absence of string size bounds checking, unlike arrays and objects which already have size limits. The issue has been addressed in commit e47e56d226519635768e6aab2f38f0ab037c09e5.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-13 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-33947",
                        "url": "https://ubuntu.com/security/CVE-2026-33947",
                        "cve_description": "jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-13 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-33948",
                        "url": "https://ubuntu.com/security/CVE-2026-33948",
                        "cve_description": "jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte count from fgets(), causing it to truncate input at the first NUL byte and parse only the preceding prefix. This enables an attacker to craft input with a benign JSON prefix before a NUL byte followed by malicious trailing data, where jq validates only the prefix as valid JSON while silently discarding the suffix. Workflows relying on jq to validate untrusted JSON before forwarding it to downstream consumers are susceptible to parser differential attacks, as those consumers may process the full input including the malicious trailing bytes. This issue has been patched by commit 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-14 00:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-39956",
                        "url": "https://ubuntu.com/security/CVE-2026-39956",
                        "cve_description": "jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks that are stripped in release builds compiled with -DNDEBUG. This allows an attacker to crash jq trivially with input like _strindices(0), and by crafting a numeric value whose IEEE-754 bit pattern maps to a chosen pointer, achieve a controlled pointer dereference and limited memory read/probe primitive. Any deployment that evaluates untrusted jq filters against a release build is vulnerable. This issue has been patched in commit fdf8ef0f0810e3d365cdd5160de43db46f57ed03.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-13 23:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-39979",
                        "url": "https://ubuntu.com/security/CVE-2026-39979",
                        "cve_description": "jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-13 23:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40164",
                        "url": "https://ubuntu.com/security/CVE-2026-40164",
                        "cve_description": "jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to precompute key collisions offline. By supplying a crafted JSON object (~100 KB) where all keys hashed to the same bucket, hash table lookups degraded from O(1) to O(n), turning any jq expression into an O(n²) operation and causing significant CPU exhaustion. This affected common jq use cases such as CI/CD pipelines, web services, and data processing scripts, and was far more practical to exploit than existing heap overflow issues since it required only a small payload. This issue has been patched in commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-14 00:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153197
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153197). Remaining changes:",
                            "    - d/control: don't build-depend on python3-jsonschema on i386, since that",
                            "      package is uninstallable on Ubuntu i386. This works for now because",
                            "      python3-jsonschema is only used in a script during tests if the manual.yml",
                            "      file is patched by the packaging. (LP #2104170)",
                            ""
                        ],
                        "package": "jq",
                        "version": "1.8.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153197
                        ],
                        "author": "Jonas Jelten <jj@ubuntu.com>",
                        "date": "Sat, 01 Aug 2026 05:30:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 1.8.2.",
                            "  * d/patches: Remove unnecessary upstream patches.",
                            "  * d/gbp.conf: Update debian-branch.",
                            ""
                        ],
                        "package": "jq",
                        "version": "1.8.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "ChangZhuo Chen (陳昌倬) <czchen@debian.org>",
                        "date": "Tue, 23 Jun 2026 21:04:10 +0800"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-49839",
                                "url": "https://ubuntu.com/security/CVE-2026-49839",
                                "cve_description": "jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-25 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Cherry-pick upstream fix for the following:",
                            "    * GHSA-ggc9-rpv2-xgpm",
                            "    * GHSA-gvwx-xj9r-3frq",
                            "    * CVE-2026-49839",
                            ""
                        ],
                        "package": "jq",
                        "version": "1.8.1-8",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "ChangZhuo Chen (陳昌倬) <czchen@debian.org>",
                        "date": "Tue, 09 Jun 2026 09:48:23 +0800"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47770",
                                "url": "https://ubuntu.com/security/CVE-2026-47770",
                                "cve_description": "jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-25 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Cherry-pick upstream fix for CVE-2026-47770.",
                            "  * d/patches: Add no-forwarded for all upstream fixes.",
                            ""
                        ],
                        "package": "jq",
                        "version": "1.8.1-7",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "ChangZhuo Chen (陳昌倬) <czchen@debian.org>",
                        "date": "Wed, 27 May 2026 21:19:20 +0800"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-40612",
                                "url": "https://ubuntu.com/security/CVE-2026-40612",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-41256",
                                "url": "https://ubuntu.com/security/CVE-2026-41256",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-41257",
                                "url": "https://ubuntu.com/security/CVE-2026-41257",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-43894",
                                "url": "https://ubuntu.com/security/CVE-2026-43894",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-43895",
                                "url": "https://ubuntu.com/security/CVE-2026-43895",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-43896",
                                "url": "https://ubuntu.com/security/CVE-2026-43896",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-44777",
                                "url": "https://ubuntu.com/security/CVE-2026-44777",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Cherry-pick upstream fix for the following CVE (Closes: #1136445):",
                            "    * CVE-2026-40612",
                            "    * CVE-2026-41256",
                            "    * CVE-2026-41257",
                            "    * CVE-2026-43894",
                            "    * CVE-2026-43895",
                            "    * CVE-2026-43896",
                            "    * CVE-2026-44777",
                            ""
                        ],
                        "package": "jq",
                        "version": "1.8.1-6",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "ChangZhuo Chen (陳昌倬) <czchen@debian.org>",
                        "date": "Sun, 17 May 2026 01:00:50 +0800"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-32316",
                                "url": "https://ubuntu.com/security/CVE-2026-32316",
                                "cve_description": "jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, resulting in a drastically undersized heap buffer. Subsequent memory copy operations then write the full string data into this undersized buffer, causing a heap buffer overflow classified as CWE-190 (Integer Overflow) leading to CWE-122 (Heap-based Buffer Overflow). Any system evaluating untrusted jq queries is affected, as an attacker can crash the process or potentially achieve further exploitation through heap corruption by crafting queries that produce extremely large strings. The root cause is the absence of string size bounds checking, unlike arrays and objects which already have size limits. The issue has been addressed in commit e47e56d226519635768e6aab2f38f0ab037c09e5.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-13 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-33947",
                                "url": "https://ubuntu.com/security/CVE-2026-33947",
                                "cve_description": "jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-13 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-33948",
                                "url": "https://ubuntu.com/security/CVE-2026-33948",
                                "cve_description": "jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte count from fgets(), causing it to truncate input at the first NUL byte and parse only the preceding prefix. This enables an attacker to craft input with a benign JSON prefix before a NUL byte followed by malicious trailing data, where jq validates only the prefix as valid JSON while silently discarding the suffix. Workflows relying on jq to validate untrusted JSON before forwarding it to downstream consumers are susceptible to parser differential attacks, as those consumers may process the full input including the malicious trailing bytes. This issue has been patched by commit 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-14 00:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-39956",
                                "url": "https://ubuntu.com/security/CVE-2026-39956",
                                "cve_description": "jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks that are stripped in release builds compiled with -DNDEBUG. This allows an attacker to crash jq trivially with input like _strindices(0), and by crafting a numeric value whose IEEE-754 bit pattern maps to a chosen pointer, achieve a controlled pointer dereference and limited memory read/probe primitive. Any deployment that evaluates untrusted jq filters against a release build is vulnerable. This issue has been patched in commit fdf8ef0f0810e3d365cdd5160de43db46f57ed03.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-13 23:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-39979",
                                "url": "https://ubuntu.com/security/CVE-2026-39979",
                                "cve_description": "jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-13 23:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-40164",
                                "url": "https://ubuntu.com/security/CVE-2026-40164",
                                "cve_description": "jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to precompute key collisions offline. By supplying a crafted JSON object (~100 KB) where all keys hashed to the same bucket, hash table lookups degraded from O(1) to O(n), turning any jq expression into an O(n²) operation and causing significant CPU exhaustion. This affected common jq use cases such as CI/CD pipelines, web services, and data processing scripts, and was far more practical to exploit than existing heap overflow issues since it required only a small payload. This issue has been patched in commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-14 00:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/control: Bump Standards-Version to 4.7.4:",
                            "    * Remove unnecessary Priority, Rules-Required-Root.",
                            "  * Cherry-pick upstream fix for the following CVE (Closes: #1133921):",
                            "    * CVE-2026-32316",
                            "    * CVE-2026-33947",
                            "    * CVE-2026-33948",
                            "    * CVE-2026-39956",
                            "    * CVE-2026-39979",
                            "    * CVE-2026-40164",
                            ""
                        ],
                        "package": "jq",
                        "version": "1.8.1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "ChangZhuo Chen (陳昌倬) <czchen@debian.org>",
                        "date": "Fri, 17 Apr 2026 09:31:25 +0800"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "kmod",
                "from_version": {
                    "source_package_name": "kmod",
                    "source_package_version": "34.2-2ubuntu2",
                    "version": "34.2-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "kmod",
                    "source_package_version": "34.2-2ubuntu3",
                    "version": "34.2-2ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "kmod",
                        "version": "34.2-2ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 14:28:11 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "kpartx",
                "from_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-2ubuntu1",
                    "version": "0.14.3-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu1",
                    "version": "0.14.3-3ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153215
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153215). Remaining changes:",
                            "    - d/rules: don't build the multipath-tools binary package on i386; only kpartx.",
                            "    - d/p/enable-find-multipaths.patch: re-enable find_multipaths by",
                            "      default -- see the removed 'add_find-multipaths.patch' (LP 1463046)",
                            "    - d/NEWS: add removal of kpartx-boot package",
                            "    - d/rules: remove -Bsymbolic-functions from LDFLAGS",
                            "    - d/rules: install friendly names multipath.conf by default",
                            "    - d/initramfs/scripts/init-top: ensure the bindings file exists before",
                            "      calling multipathd -B in the initramfs. This prevents multipathd -B from",
                            "      failing and exiting immediately (LP #2120444).",
                            "    - d/p/testsuite-no-lto: disable lto to workaround testsuite symbol wrapping (LP #2135118)",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153215
                        ],
                        "author": "Jonas Jelten <jj@ubuntu.com>",
                        "date": "Sat, 01 Aug 2026 06:13:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * [55c6f80] multipath-tools-boot: add Depends: procps for pidof",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 07 May 2026 11:35:01 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "krb5-locales",
                "from_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-2ubuntu4",
                    "version": "1.22.1-2ubuntu4"
                },
                "to_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-3ubuntu2",
                    "version": "1.22.1-3ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-11850",
                        "url": "https://ubuntu.com/security/CVE-2026-11850",
                        "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-11 10:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40355",
                        "url": "https://ubuntu.com/security/CVE-2026-40355",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40356",
                        "url": "https://ubuntu.com/security/CVE-2026-40356",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153198,
                    2155018
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:57:38 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153198, LP: #2155018). Remaining changes:",
                            "    - d/t/util: add test cleanup and log function",
                            "    - d/t/util: Prepend includedir /etc/krb5.conf.d/ for the configuration file",
                            "      created in create_realm.",
                            "    - d/t/includedir-ordering: Add new test.",
                            "    - Fix FTBFS test t_otp.py (LP #2142451):",
                            "      + d/p/set-fork-start-method-t-otpy.patch: Python 3.14 changes the default",
                            "        start method of multiprocessing to 'forkserver'. This introduces issues",
                            "        in the test t_otp.py that does not use a main block. Set the start",
                            "        method to force 'fork' instead.",
                            "    - d/p/default-enctype-list.patch: do not default to weak encryption",
                            "      algorithms (LP #2144909)",
                            "    - d/NEWS: explain weak algorithms are no longer default options",
                            "  * Dropped:",
                            "    - d/p/fix-strchr-conformance-to-c23.patch: Fix FTBFS with glibc2.43",
                            "      (LP #2142893)",
                            "      [In 1.22.1-3]",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153198,
                            2155018
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Mon, 29 Jun 2026 15:44:10 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11850",
                                "url": "https://ubuntu.com/security/CVE-2026-11850",
                                "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-11 10:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Emmanuel Arias ]",
                            "  * CVE-2026-11850: Prevent read overrun in libkdb_ldap (Closes: #1139821).",
                            "",
                            "  [ Sam Hartman ]",
                            "  * Fix C23 use of strchr, Closes: #1128877",
                            "  * Remove lintian tag that ldap plugin is linked against libc6; no longer needed",
                            "  * Upstream patch for OpenSSL 4.0 compatibility, Closes: #1138466",
                            "  * Upstream commit f5bbfa4 to use openssl facilities to verify certificates; needed to avoid discarding const qualifier from Openssl 4.0 patch",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sam Hartman <hartmans@debian.org>",
                        "date": "Fri, 19 Jun 2026 08:30:16 -0600"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-40355",
                                "url": "https://ubuntu.com/security/CVE-2026-40355",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-40356",
                                "url": "https://ubuntu.com/security/CVE-2026-40356",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Non-maintainer upload.",
                            "  * Fix two NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)",
                            "    (Closes: #1135317)",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-2.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Salvatore Bonaccorso <carnil@debian.org>",
                        "date": "Sun, 10 May 2026 09:08:30 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libapparmor1:ppc64el",
                "from_version": {
                    "source_package_name": "apparmor",
                    "source_package_version": "5.0.2-0ubuntu1",
                    "version": "5.0.2-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "apparmor",
                    "source_package_version": "6.0.0~alpha1-0ubuntu1",
                    "version": "6.0.0~alpha1-0ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * debian/control: add iwyu, pytest, pytest-xdist to Build-Depends",
                            "  * Drop patches that were applied upstream:",
                            "    - d/p/u/0001-parser-add-more-reserved-mediation-classes.patch",
                            "  * Refresh patches for new release:",
                            "    - d/p/u/0007-Set-parser-network.h-ip_conds-ptrs-to-null-in-its-fr.patch",
                            "  * Update patches for new release:",
                            "    - d/p/u/profiles-use-coreutils-tunable.patch",
                            "    - d/p/u/profiles_add_more_consoles_workaround.patch",
                            "    - d/p/u/profiles_disable_free.patch",
                            "  * Add patches to install a confining loupe profile:",
                            "    - d/p/u/0001-profiles-add-a-glycin-tunable.patch",
                            "    - d/p/u/0002-profiles-begin-adding-abstractions-for-the-XDG-Deskt.patch",
                            "    - d/p/u/0003-profiles-rewrite-the-loupe-profile.patch",
                            "  * debian/apparmor.install: add glycin tunables",
                            ""
                        ],
                        "package": "apparmor",
                        "version": "6.0.0~alpha1-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ryan Lee <ryan.lee@canonical.com>",
                        "date": "Thu, 20 Aug 2026 12:05:00 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libappstream5:ppc64el",
                "from_version": {
                    "source_package_name": "appstream",
                    "source_package_version": "1.1.5-1",
                    "version": "1.1.5-1"
                },
                "to_version": {
                    "source_package_name": "appstream",
                    "source_package_version": "1.1.6-1",
                    "version": "1.1.6-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version: 1.1.6",
                            "  * Update symbols file",
                            ""
                        ],
                        "package": "appstream",
                        "version": "1.1.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klumpp <mak@debian.org>",
                        "date": "Wed, 12 Aug 2026 16:32:34 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libapt-pkg7.0:ppc64el",
                "from_version": {
                    "source_package_name": "apt",
                    "source_package_version": "3.2.0",
                    "version": "3.2.0"
                },
                "to_version": {
                    "source_package_name": "apt",
                    "source_package_version": "3.3.3",
                    "version": "3.3.3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158000,
                    2150631
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  This release introduces initial interactive help output for apt(8)",
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * cmdline: add declarative option help printer",
                            "  * mirror: Scale fan-out with the square root of the number of files",
                            "",
                            "  [ Simon Johnsson ]",
                            "  * cmdline: add command-specific help texts",
                            "",
                            "  [ Zara Grigoryan ]",
                            "  * cmdline: render declarative options in command help",
                            "  * cmdline: mark option descriptions for translation",
                            "  * cmdline: refine command-specific help rendering",
                            "",
                            "  [ Andriy Pysyk ]",
                            "  * Fix fuzzy entries in Ukrainian translation for APT 3.3.2 + terminology consistency improvements",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Fri, 14 Aug 2026 17:51:56 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * Document and test combined `build-dep --arch-only --indep-only`",
                            "  * ftparchive: fix heap overflow in ContentsExtract::DoItem",
                            "  * deb: guard against unsigned underflow when trimming control newlines",
                            "  * gpgv: don't advance past the null terminator in PushEntryWithKeyID",
                            "  * ftparchive: replace ContentsExtract's manual buffer with std::vector<char>",
                            "  * test: Limit valgrind to 1024 open files",
                            "  * hashes: Fix lingering OpenSSL error (Closes: #1140227)",
                            "  * test: use `gnurm` where available",
                            "  * Convert command-line option-parsing to declarative format",
                            "  * Fix crash when an aux file request is redirected",
                            "  * Reply to aux requests with the original URI if redirected",
                            "  * debian/apt-daily.service: Add timeouts.",
                            "    30 mins for apt-daily.service, 12 hours for apt-daily-upgrade.service",
                            "    should be sufficient. (LP: #2158000)",
                            "",
                            "  [ наб ]",
                            "  * apt-transport-https(1): document host-specific SSLCert, SSLKey, Verify-Host with host:: instead of ::host",
                            "",
                            "  [ David Kalnischkies ]",
                            "  * aptwebserver: Refuse client immediately on TLS handshake",
                            "",
                            "  [ Américo Monteiro ]",
                            "  * Portuguese manpages translation update (Closes: #1133965)",
                            "",
                            "  [ Frans Spiesschaert ]",
                            "  * Dutch program translation update (Closes: #1135221)",
                            "  * Dutch manpages translation update (Closes: #1135222)",
                            "",
                            "  [ Remus-Gabriel Chelu ]",
                            "  * Romanian program translation update (Closes: #1139336)",
                            "",
                            "  [ Mark Atwood ]",
                            "  * hashes: include <span> for std::span",
                            "  * hashes: don't crash on an unavailable digest",
                            "  * test: exercise hashes with a disabled digest",
                            "",
                            "  [ dongshengyuan ]",
                            "  * Fix installing a deb with colon in path",
                            "",
                            "  [ Simon Johnsson ]",
                            "  * apt-pkg: rename \"OpenPGP signature verification failed\" to \"Signature verification failed\"",
                            "",
                            "  [ Andreas Noteng ]",
                            "  * Norwegian Bokmål (nb) translation update",
                            "",
                            "  [ Temuri Doghonadze ]",
                            "  * po: Add Georgian translation",
                            "",
                            "  [ Andriy Pysyk ]",
                            "  * Update Ukrainian translation for 3.3.1",
                            "",
                            "  [ Mikhail Khachayants ]",
                            "  * srvrec: reject res_query answers bigger than our buffer",
                            "",
                            "  [ Ramesh Adhikari ]",
                            "  * tagfile: fix unbounded backward scan in Fill()'s trailing-newline check",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2158000
                        ],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 22:43:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * solver3: Follow installed Suggests earlier",
                            "  * Fix `noexcept` as pointed out by gcc",
                            "  * Fix wrongful std::make_unique conversion",
                            "  * Fix regression in dirstream (Closes: #1136441)",
                            "",
                            "  [ Varun Varma ]",
                            "  * Warn if auth.conf is unreadable (LP: #2150631)",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2150631
                        ],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Sun, 17 May 2026 21:21:50 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Anders Kaseorg ]",
                            "  * Fix Phased-Update-Percentage probability mistake",
                            "",
                            "  [ Simon Johnsson ]",
                            "  * Scale history-list to screen width",
                            "  * Optimize ShortenCommand",
                            "  * Change GetKindString to not use .data() call",
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * Drop warning about unstable CLI interface.",
                            "    A specific CLI version can now be requested using the --cli-version",
                            "    flag, and old versions can be deprecated on a reasonable cadence.",
                            "    Therefore, a warning is no longer necessary.",
                            "  * hashes: Use std::span instead of std::basic_string_view",
                            "  * sources.list(5): Document Contact/Bugs/Description fields.",
                            "    Thanks to josch for the suggestion",
                            "  * Require sqv for builds on supported archs and !pkg.apt.nosqv",
                            "",
                            "  [ Zheyu Shen ]",
                            "  * fix apt patterns parsing bug for pre-depends",
                            "",
                            "  [ Herman Semenoff ]",
                            "  * apt: funcs called with a string literal consisting of a single character",
                            "  * apt-pkg/acquire: use range based for loop C++17",
                            "  * apt: push to emplace C++11 if possible",
                            "  * apt: modernize to make_unique C++17",
                            "  * apt-pkg: methods: fixed many minor memleaks",
                            "",
                            "  [ наб ]",
                            "  * sources.list(5): th[r]ough typo",
                            "",
                            "  [ Sebastian Krzyszkowiak ]",
                            "  * acquire-item: Fix up the error message on committing aborted transaction",
                            "  * pkgAcqMetaClearSig: Abort transaction when pkgAcquire::Run has been cancelled",
                            "    (Closes: #1078608)",
                            "  * pkgAcqMetaBase: Commit InRelease after other transaction items",
                            "    (Closes: #1078608)",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Fix bug reference",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.0",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Fri, 01 May 2026 18:40:52 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libatomic1:ppc64el",
                "from_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.1.0-2ubuntu1",
                    "version": "16.1.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-1ubuntu1",
                    "version": "16.2.0-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158577
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 09 Aug 2026 06:21:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * GCC 16.2.0 release.",
                            "    - Fix PR target/126581 (x86), PR tree-optimization/126504,",
                            "      PR tree-optimization/126503, PR middle-end/126497,",
                            "      PR tree-optimization/126490, PR tree-optimization/126464,",
                            "      PR tree-optimization/126476, PR tree-optimization/126464,",
                            "      PR middle-end/126084, PR tree-optimization/126471, PR target/126446,",
                            "      PR middle-end/126410, PR tree-optimization/126457,",
                            "      PR tree-optimization/126404, PR tree-optimization/126404,",
                            "      PR target/126438 (PPC), PR target/126450 (x86), PR middle-end/126447,",
                            "      PR middle-end/126405, PR rtl-optimization/126184,",
                            "      PR rtl-optimization/126184, PR target/126429 (x86),",
                            "      PR tree-optimization/125396, PR tree-optimization/125290,",
                            "      PR target/126320 (x86), PR middle-end/126341, PR target/123625 (AArch64),",
                            "      PR target/121957 (AArch64), PR rtl-optimization/125209,",
                            "      PR middle-end/124637, PR tree-optimization/126171,",
                            "      PR tree-optimization/126225, PR tree-optimization/124663, PR ipa/125207,",
                            "      PR target/119210 (AArch64), PR target/105116, PR driver/1240,",
                            "      PR ada/126553, PR ada/126379, PR ada/126482, PR algol68/126330,",
                            "      PR c++/126309, PR c++/126508, PR c++/126420, PR c++/126423,",
                            "      PR c++/126343, PR c++/126406, PR c++/119343, PR c++/126209,",
                            "      PR c++/126310, PR c++/126280, PR c++/126215, PR driver/124058,",
                            "      PR fortran/125866, PR fortran/126386, PR fortran/126303,",
                            "      PR fortran/97592, PR fortran/125998, PR sanitizer/126307,",
                            "      PR libstdc++/122197, PR libstdc++/124854, PR libstdc++/116110,",
                            "      PR libstdc++/124853, PR libstdc++/116110, PR libstdc++/124852,",
                            "      PR libstdc++/124852, PR libstdc++/124851, PR libstdc++/123165.",
                            "  * Update to git 20260809 from the gcc-16 branch.",
                            "    - Fix PR target/126484 (MIPS), PR tree-optimization/126576,",
                            "      PR tree-optimization/126547, PR tree-optimization/126549,",
                            "      PR tree-optimization/126564, PR tree-optimization/126601,",
                            "      PR target/124948, PR tree-optimization/126464, PR preprocessor/125048,",
                            "      PR libstdc++/125200, PR c++/125591, PR c++/125601, PR c++/125680,",
                            "      PR c++/125541, PR fortran/126205, PR target/126667 (S390),",
                            "      PR fortran/125263.",
                            "",
                            "  [ Matthias Klose ]",
                            "  * Update libgcc-s, libcc1, libasan and libgcobol symbols files.",
                            "  * d/rules2: Use rva23u64 with zifencei extension for Ubuntu (Vladimir Petko).",
                            "    LP: #2158577.",
                            "  * d/rules: Reformat riscv64 extensions for Debian.",
                            "  * Configure with --enable-checking=release on every architecture.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * d/rules2: Use rva20u64 with zifencei extension for Debian.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2158577
                        ],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 09 Aug 2026 06:10:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 19 Jul 2026 14:16:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260719 from the gcc-16 branch.",
                            "    - Fix PR tree-optimization/126262, PR tree-optimization/126257,",
                            "      PR middle-end/126084, PR tree-optimization/120201,",
                            "      PR tree-optimization/126194, PR tree-optimization/126150,",
                            "      PR tree-optimization/125953, PR middle-end/125875,",
                            "      PR tree-optimization/125786, PR tree-optimization/125668,",
                            "      PR tree-optimization/125296, PR tree-optimization/126008,",
                            "      PR tree-optimization/125730, PR tree-optimization/125040,",
                            "      PR ipa/125121, PR ipa/124128, PR target/126054 (S390),",
                            "      PR target/126148 (x86), PR tree-optimization/125597,",
                            "      PR tree-optimization/125597, PR tree-optimization/125597,",
                            "      PR target/126081 (or1k), PR target/126049 (RISCV),",
                            "      PR target/126098 (x86), PR target/67459 (SH), PR target/122948 (SH),",
                            "      PR target/125972 (S390), PR rtl-optimization/125173,",
                            "      PR target/124908 (AArch64), PR target/125838 (AArch64),",
                            "      PR target/125883 (x86), PR target/125818 (AArch64),",
                            "      PR target/125469 (x86), PR target/125469 (x86), PR target/125949 (x86),",
                            "      PR target/125992 (S390), PR middle-end/125977, PR target/125628 (MIPS),",
                            "      PR target/125478 (RISCV), PR target/106895 (PPC), PR target/122665 (PPC),",
                            "      PR target/125670 (RISCV), PR middle-end/125621,",
                            "      PR target/125148 (AArch64), PR tree-optimization/125431,",
                            "      PR target/125795 (AArch64), PR tree-optimization/125501,",
                            "      PR tree-optimization/125776, PR tree-optimization/125774,",
                            "      PR target/120144 (MIPS), PR ipa/125699, PR tree-optimization/125419,",
                            "      PR tree-optimization/125652, PR tree-optimization/125686,",
                            "      PR tree-optimization/125646, PR tree-optimization/125553,",
                            "      PR tree-optimization/125545, PR tree-optimization/125502,",
                            "      PR tree-optimization/125477, PR target/124948, PR c/125072, PR c/125935,",
                            "      PR c/125604, PR c/123569, PR c/125252, PR c/124303, PR c/124985,",
                            "      PR c++/126057, PR c++/126036, PR c++/126007, PR c++/125674, PR c++/91155,",
                            "      PR c++/126066, PR c++/125901, PR c++/126031, PR c++/121552, PR c++/124584,",
                            "      PR c++/121094, PR c++/117259, PR c++/123536, PR c++/125900, PR c++/125334,",
                            "      PR c++/125768, PR c++/125939, PR c++/125745, PR c++/125408, PR c++/124978,",
                            "      PR c++/115314, PR c++/125889, PR c++/125764, PR c++/125759, PR c++/65271,",
                            "      PR c++/125770, PR fortran/126234, PR fortran/125172, PR fortran/126210,",
                            "      PR fortran/126170, PR fortran/126127, PR fortran/103367,",
                            "      PR fortran/126018, PR fortran/125051, PR fortran/125902,",
                            "      PR fortran/125902, PR fortran/60576, PR fortran/125430,",
                            "      PR fortran/125527, PR fortran/125535, PR fortran/125650,",
                            "      PR fortran/125481, PR fortran/125527, PR fortran/125528,",
                            "      PR fortran/125529, PR fortran/125530, PR fortran/125531,",
                            "      PR fortran/125534, PR fortran/125535, PR lto/125257, PR libgcc/123976,",
                            "      PR target/125752 (AVR), PR libfortran/126116, PR libstdc++/126111,",
                            "      PR libstdc++/125956, PR libstdc++/118158, PR libstdc++/125228,",
                            "      PR libstdc++/125890.",
                            "  * Let the ada build fail on an alihash mismatch, if fail_on_alihash_mismatch",
                            "    is enabled.",
                            "  * Enable Modula-2 on powerpc and ppc64. Closes: #1141560, #1141596.",
                            "  * Enable LRA by default on m68k for snapshot builds (Adrian Glaubitz).",
                            "    Addresses: #1142039.",
                            "  * Disable running tests on Debian/riscv64 for meaningful build times.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 19 Jul 2026 13:28:39 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libbrotli1:ppc64el",
                "from_version": {
                    "source_package_name": "brotli",
                    "source_package_version": "1.2.0-3build1",
                    "version": "1.2.0-3build1"
                },
                "to_version": {
                    "source_package_name": "brotli",
                    "source_package_version": "1.2.0-4",
                    "version": "1.2.0-4"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Maximiliano Curia ]",
                            "  * Avoid using qemu whenever we try to build against arm64 (Closes: #1144507)",
                            "",
                            "  [ Tomasz Buchert ]",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "brotli",
                        "version": "1.2.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Tomasz Buchert <tomasz@debian.org>",
                        "date": "Sat, 22 Aug 2026 16:27:53 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libbytesize-common",
                "from_version": {
                    "source_package_name": "libbytesize",
                    "source_package_version": "2.12-2",
                    "version": "2.12-2"
                },
                "to_version": {
                    "source_package_name": "libbytesize",
                    "source_package_version": "2.12-3",
                    "version": "2.12-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * python: fix BSUnit ctypes binding.",
                            "    Patch cherry-picked from upstream Git.",
                            "    Thanks to Jeroen Diederen (Closes: #1115070)",
                            ""
                        ],
                        "package": "libbytesize",
                        "version": "2.12-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Fri, 14 Aug 2026 13:27:46 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libbytesize1:ppc64el",
                "from_version": {
                    "source_package_name": "libbytesize",
                    "source_package_version": "2.12-2",
                    "version": "2.12-2"
                },
                "to_version": {
                    "source_package_name": "libbytesize",
                    "source_package_version": "2.12-3",
                    "version": "2.12-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * python: fix BSUnit ctypes binding.",
                            "    Patch cherry-picked from upstream Git.",
                            "    Thanks to Jeroen Diederen (Closes: #1115070)",
                            ""
                        ],
                        "package": "libbytesize",
                        "version": "2.12-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Fri, 14 Aug 2026 13:27:46 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc-bin",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2",
                    "version": "2.43-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2.3",
                    "version": "2.43-2ubuntu2.3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: assertion failure via IBM1390 or IBM1399 charsets",
                            "    - debian/patches/CVE-2026-4046.patch: Use pending character state in",
                            "      IBM1390, IBM1399 character sets in iconvdata/Makefile,",
                            "      iconvdata/ibm1364.c, iconvdata/tst-bug33980.c.",
                            "    - CVE-2026-4046",
                            "  * SECURITY UPDATE: out-of-bounds write in deprecated debugging function",
                            "    - debian/patches/CVE-2026-5435.patch: resolv: More types as unknown in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - CVE-2026-5435",
                            "  * SECURITY UPDATE: one byte heap buffer overflow in scanf %mc",
                            "    - debian/patches/CVE-2026-5450.patch: stdio-common: Fix buffer overflow in",
                            "      scanf %mc [BZ #34008] in stdio-common/Makefile, stdio-common/tst-vfscanf-",
                            "      bz34008.c, stdio-common/vfscanf-internal.c.",
                            "    - CVE-2026-5450",
                            "  * SECURITY UPDATE: crash or info disclosure in ungetwc function",
                            "    - debian/patches/CVE-2026-5928.patch: libio: Fix ungetwc operating on byte",
                            "      stream in libio/Makefile, libio/bug-wgenops-bz33998.c, libio/wgenops.c.",
                            "    - CVE-2026-5928",
                            "  * SECURITY UPDATE: crash in deprecated debugging functions",
                            "    - debian/patches/CVE-2026-6238-pre1.patch: resolv: Declare __p_class_syms,",
                            "      __p_type_syms for internal use in include/resolv.h, resolv/res_debug.c.",
                            "    - debian/patches/CVE-2026-6238-pre2.patch: resolv: Fix ns_sprintrrf",
                            "      formatting of class, type values in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre3.patch: resolv: Improve formatting of",
                            "      unknown records in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre4.patch: resolv: Check for inet_ntop",
                            "      failure in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-1.patch: resolv: Fix buffer overreads in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-2.patch: resolv: Add test case tst-",
                            "      ns_sprintrr in resolv/Makefile, resolv/tst-ns_sprintrr.c.",
                            "    - CVE-2026-6238",
                            "  * Disable failing tests because of rust-coreutils (LP: 2161727)",
                            "    - debian/testsuite-xfail-debian.mk: added tst-spawn-chdir and",
                            "      tst-spawn-chdir-pidfd.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-2ubuntu2.3",
                        "urgency": "medium",
                        "distributions": "resolute-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Wed, 22 Jul 2026 13:24:47 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc-dev-bin",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2",
                    "version": "2.43-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2.3",
                    "version": "2.43-2ubuntu2.3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: assertion failure via IBM1390 or IBM1399 charsets",
                            "    - debian/patches/CVE-2026-4046.patch: Use pending character state in",
                            "      IBM1390, IBM1399 character sets in iconvdata/Makefile,",
                            "      iconvdata/ibm1364.c, iconvdata/tst-bug33980.c.",
                            "    - CVE-2026-4046",
                            "  * SECURITY UPDATE: out-of-bounds write in deprecated debugging function",
                            "    - debian/patches/CVE-2026-5435.patch: resolv: More types as unknown in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - CVE-2026-5435",
                            "  * SECURITY UPDATE: one byte heap buffer overflow in scanf %mc",
                            "    - debian/patches/CVE-2026-5450.patch: stdio-common: Fix buffer overflow in",
                            "      scanf %mc [BZ #34008] in stdio-common/Makefile, stdio-common/tst-vfscanf-",
                            "      bz34008.c, stdio-common/vfscanf-internal.c.",
                            "    - CVE-2026-5450",
                            "  * SECURITY UPDATE: crash or info disclosure in ungetwc function",
                            "    - debian/patches/CVE-2026-5928.patch: libio: Fix ungetwc operating on byte",
                            "      stream in libio/Makefile, libio/bug-wgenops-bz33998.c, libio/wgenops.c.",
                            "    - CVE-2026-5928",
                            "  * SECURITY UPDATE: crash in deprecated debugging functions",
                            "    - debian/patches/CVE-2026-6238-pre1.patch: resolv: Declare __p_class_syms,",
                            "      __p_type_syms for internal use in include/resolv.h, resolv/res_debug.c.",
                            "    - debian/patches/CVE-2026-6238-pre2.patch: resolv: Fix ns_sprintrrf",
                            "      formatting of class, type values in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre3.patch: resolv: Improve formatting of",
                            "      unknown records in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre4.patch: resolv: Check for inet_ntop",
                            "      failure in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-1.patch: resolv: Fix buffer overreads in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-2.patch: resolv: Add test case tst-",
                            "      ns_sprintrr in resolv/Makefile, resolv/tst-ns_sprintrr.c.",
                            "    - CVE-2026-6238",
                            "  * Disable failing tests because of rust-coreutils (LP: 2161727)",
                            "    - debian/testsuite-xfail-debian.mk: added tst-spawn-chdir and",
                            "      tst-spawn-chdir-pidfd.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-2ubuntu2.3",
                        "urgency": "medium",
                        "distributions": "resolute-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Wed, 22 Jul 2026 13:24:47 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc-gconv-modules-extra:ppc64el",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2",
                    "version": "2.43-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2.3",
                    "version": "2.43-2ubuntu2.3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: assertion failure via IBM1390 or IBM1399 charsets",
                            "    - debian/patches/CVE-2026-4046.patch: Use pending character state in",
                            "      IBM1390, IBM1399 character sets in iconvdata/Makefile,",
                            "      iconvdata/ibm1364.c, iconvdata/tst-bug33980.c.",
                            "    - CVE-2026-4046",
                            "  * SECURITY UPDATE: out-of-bounds write in deprecated debugging function",
                            "    - debian/patches/CVE-2026-5435.patch: resolv: More types as unknown in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - CVE-2026-5435",
                            "  * SECURITY UPDATE: one byte heap buffer overflow in scanf %mc",
                            "    - debian/patches/CVE-2026-5450.patch: stdio-common: Fix buffer overflow in",
                            "      scanf %mc [BZ #34008] in stdio-common/Makefile, stdio-common/tst-vfscanf-",
                            "      bz34008.c, stdio-common/vfscanf-internal.c.",
                            "    - CVE-2026-5450",
                            "  * SECURITY UPDATE: crash or info disclosure in ungetwc function",
                            "    - debian/patches/CVE-2026-5928.patch: libio: Fix ungetwc operating on byte",
                            "      stream in libio/Makefile, libio/bug-wgenops-bz33998.c, libio/wgenops.c.",
                            "    - CVE-2026-5928",
                            "  * SECURITY UPDATE: crash in deprecated debugging functions",
                            "    - debian/patches/CVE-2026-6238-pre1.patch: resolv: Declare __p_class_syms,",
                            "      __p_type_syms for internal use in include/resolv.h, resolv/res_debug.c.",
                            "    - debian/patches/CVE-2026-6238-pre2.patch: resolv: Fix ns_sprintrrf",
                            "      formatting of class, type values in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre3.patch: resolv: Improve formatting of",
                            "      unknown records in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre4.patch: resolv: Check for inet_ntop",
                            "      failure in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-1.patch: resolv: Fix buffer overreads in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-2.patch: resolv: Add test case tst-",
                            "      ns_sprintrr in resolv/Makefile, resolv/tst-ns_sprintrr.c.",
                            "    - CVE-2026-6238",
                            "  * Disable failing tests because of rust-coreutils (LP: 2161727)",
                            "    - debian/testsuite-xfail-debian.mk: added tst-spawn-chdir and",
                            "      tst-spawn-chdir-pidfd.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-2ubuntu2.3",
                        "urgency": "medium",
                        "distributions": "resolute-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Wed, 22 Jul 2026 13:24:47 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc6:ppc64el",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2",
                    "version": "2.43-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2.3",
                    "version": "2.43-2ubuntu2.3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: assertion failure via IBM1390 or IBM1399 charsets",
                            "    - debian/patches/CVE-2026-4046.patch: Use pending character state in",
                            "      IBM1390, IBM1399 character sets in iconvdata/Makefile,",
                            "      iconvdata/ibm1364.c, iconvdata/tst-bug33980.c.",
                            "    - CVE-2026-4046",
                            "  * SECURITY UPDATE: out-of-bounds write in deprecated debugging function",
                            "    - debian/patches/CVE-2026-5435.patch: resolv: More types as unknown in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - CVE-2026-5435",
                            "  * SECURITY UPDATE: one byte heap buffer overflow in scanf %mc",
                            "    - debian/patches/CVE-2026-5450.patch: stdio-common: Fix buffer overflow in",
                            "      scanf %mc [BZ #34008] in stdio-common/Makefile, stdio-common/tst-vfscanf-",
                            "      bz34008.c, stdio-common/vfscanf-internal.c.",
                            "    - CVE-2026-5450",
                            "  * SECURITY UPDATE: crash or info disclosure in ungetwc function",
                            "    - debian/patches/CVE-2026-5928.patch: libio: Fix ungetwc operating on byte",
                            "      stream in libio/Makefile, libio/bug-wgenops-bz33998.c, libio/wgenops.c.",
                            "    - CVE-2026-5928",
                            "  * SECURITY UPDATE: crash in deprecated debugging functions",
                            "    - debian/patches/CVE-2026-6238-pre1.patch: resolv: Declare __p_class_syms,",
                            "      __p_type_syms for internal use in include/resolv.h, resolv/res_debug.c.",
                            "    - debian/patches/CVE-2026-6238-pre2.patch: resolv: Fix ns_sprintrrf",
                            "      formatting of class, type values in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre3.patch: resolv: Improve formatting of",
                            "      unknown records in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre4.patch: resolv: Check for inet_ntop",
                            "      failure in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-1.patch: resolv: Fix buffer overreads in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-2.patch: resolv: Add test case tst-",
                            "      ns_sprintrr in resolv/Makefile, resolv/tst-ns_sprintrr.c.",
                            "    - CVE-2026-6238",
                            "  * Disable failing tests because of rust-coreutils (LP: 2161727)",
                            "    - debian/testsuite-xfail-debian.mk: added tst-spawn-chdir and",
                            "      tst-spawn-chdir-pidfd.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-2ubuntu2.3",
                        "urgency": "medium",
                        "distributions": "resolute-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Wed, 22 Jul 2026 13:24:47 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc6-dev:ppc64el",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2",
                    "version": "2.43-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2.3",
                    "version": "2.43-2ubuntu2.3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: assertion failure via IBM1390 or IBM1399 charsets",
                            "    - debian/patches/CVE-2026-4046.patch: Use pending character state in",
                            "      IBM1390, IBM1399 character sets in iconvdata/Makefile,",
                            "      iconvdata/ibm1364.c, iconvdata/tst-bug33980.c.",
                            "    - CVE-2026-4046",
                            "  * SECURITY UPDATE: out-of-bounds write in deprecated debugging function",
                            "    - debian/patches/CVE-2026-5435.patch: resolv: More types as unknown in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - CVE-2026-5435",
                            "  * SECURITY UPDATE: one byte heap buffer overflow in scanf %mc",
                            "    - debian/patches/CVE-2026-5450.patch: stdio-common: Fix buffer overflow in",
                            "      scanf %mc [BZ #34008] in stdio-common/Makefile, stdio-common/tst-vfscanf-",
                            "      bz34008.c, stdio-common/vfscanf-internal.c.",
                            "    - CVE-2026-5450",
                            "  * SECURITY UPDATE: crash or info disclosure in ungetwc function",
                            "    - debian/patches/CVE-2026-5928.patch: libio: Fix ungetwc operating on byte",
                            "      stream in libio/Makefile, libio/bug-wgenops-bz33998.c, libio/wgenops.c.",
                            "    - CVE-2026-5928",
                            "  * SECURITY UPDATE: crash in deprecated debugging functions",
                            "    - debian/patches/CVE-2026-6238-pre1.patch: resolv: Declare __p_class_syms,",
                            "      __p_type_syms for internal use in include/resolv.h, resolv/res_debug.c.",
                            "    - debian/patches/CVE-2026-6238-pre2.patch: resolv: Fix ns_sprintrrf",
                            "      formatting of class, type values in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre3.patch: resolv: Improve formatting of",
                            "      unknown records in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre4.patch: resolv: Check for inet_ntop",
                            "      failure in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-1.patch: resolv: Fix buffer overreads in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-2.patch: resolv: Add test case tst-",
                            "      ns_sprintrr in resolv/Makefile, resolv/tst-ns_sprintrr.c.",
                            "    - CVE-2026-6238",
                            "  * Disable failing tests because of rust-coreutils (LP: 2161727)",
                            "    - debian/testsuite-xfail-debian.mk: added tst-spawn-chdir and",
                            "      tst-spawn-chdir-pidfd.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-2ubuntu2.3",
                        "urgency": "medium",
                        "distributions": "resolute-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Wed, 22 Jul 2026 13:24:47 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libcrypt1:ppc64el",
                "from_version": {
                    "source_package_name": "libxcrypt",
                    "source_package_version": "1:4.5.1-1",
                    "version": "1:4.5.1-1"
                },
                "to_version": {
                    "source_package_name": "libxcrypt",
                    "source_package_version": "1:4.5.2+20251210-1",
                    "version": "1:4.5.2+20251210-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream snapshot.",
                            ""
                        ],
                        "package": "libxcrypt",
                        "version": "1:4.5.2+20251210-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marco d'Itri <md@linux.it>",
                        "date": "Sun, 09 Aug 2026 00:52:53 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libcryptsetup12:ppc64el",
                "from_version": {
                    "source_package_name": "cryptsetup",
                    "source_package_version": "2:2.8.4-1ubuntu4",
                    "version": "2:2.8.4-1ubuntu4"
                },
                "to_version": {
                    "source_package_name": "cryptsetup",
                    "source_package_version": "2:2.8.7-1ubuntu1",
                    "version": "2:2.8.7-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-33948",
                        "url": "https://ubuntu.com/security/CVE-2026-33948",
                        "cve_description": "jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte count from fgets(), causing it to truncate input at the first NUL byte and parse only the preceding prefix. This enables an attacker to craft input with a benign JSON prefix before a NUL byte followed by malicious trailing data, where jq validates only the prefix as valid JSON while silently discarding the suffix. Workflows relying on jq to validate untrusted JSON before forwarding it to downstream consumers are susceptible to parser differential attacks, as those consumers may process the full input including the malicious trailing bytes. This issue has been patched by commit 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-14 00:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163661,
                    2157328
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2163661). Remaining changes:",
                            "    - d/tests/utils/mkinitramfs: Support zstd compressed modules for self test",
                            "    - d/rules: Compile-in support for a FIPS mode. LP #2032659",
                            "    - d/control: Recommend plymouth",
                            "    - d/control: Move cryptsetup-initramfs back to cryptsetup Recommends,",
                            "      preferring dracut",
                            "    - d/{control,rules}: Disable building cryptsetup-suspend on i386",
                            "    - d/initramfs/cryptroot-unlock: Fix busybox/narrow compat LP #1968636",
                            "    - d/tests: Fix autopkgtests",
                            "      + d/tests/utils/mkinitramfs: Prevent linking attempt if file exists",
                            "      + d/tests/utils/cryptroot-common: Handle Ubuntu kernel package split",
                            "        (linux-image + linux-modules) when extracting the kernel",
                            "    - d/{functions,initramfs/hooks/cryptroot}: Fix ZFS root warning/error",
                            "      + d/functions: Return an empty devno for ZFS devices as they don't have",
                            "        major:minor device numbers.",
                            "      + d/initramfs/hooks/cryptroot: Ignore and don't print an error message",
                            "        when devices don't have a devno.",
                            "    - d/p/{no-dd-direct-flags-tmpfs,series}: Disable O_DIRECT on tmpfs",
                            "    - d/p/test-use-gnudd-as-workaround-in-luks2-reencryption-mangle.patch:",
                            "      use gnudd as workaround in luks2-reencryption-mangle-test failing",
                            "      with rust-coreutils dd (see",
                            "      https://bugs.launchpad.net/ubuntu/+source/rust-coreutils/+bug/2143933)",
                            "  * Dropped changes, included in Debian:",
                            "    - askpass: Fix FTBFS with glibc 2.43 (in 2:2.8.6-1)",
                            "    - d/tests/control: Add cpio autopkgtest dependency (in 2:2.8.6-2)",
                            "    - d/p/tests-Fix-tests-to-not-use-aes-generic-kernel-cipher-name.patch:",
                            "      applied upstream (in 2:2.8.7-1)",
                            "    - d/p/Add-specific-error-for-failed-posix_fallocate-call.patch:",
                            "      applied upstream (in 2:2.8.7-1)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/control: Depend on busybox-initramfs instead of busybox |",
                            "      busybox-static (reverted in 2:2.8.4-1ubuntu5, matching Debian)",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163661
                        ],
                        "author": "Anshul Singh <anshul.singh@canonical.com>",
                        "date": "Mon, 17 Aug 2026 21:59:32 +0900"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream bugfix release.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Wed, 22 Jul 2026 01:53:08 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release candidate. (Closes: #1141257)",
                            "  * d/rules: Adjust blhc's ignore-line-regexp.",
                            "  * cryptsetup-suspend-wrapper: Replace `find … -execdir {}` call with a shell",
                            "    loop. (Closes: #1141157)",
                            "  * Refresh d/patches.",
                            "  * d/t/cryptroot-*: Install mount in the guests.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7~rc2-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Mon, 13 Jul 2026 16:47:12 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release candidate.",
                            "  * Drop d/patches/* applied upstream.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7~rc1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Tue, 30 Jun 2026 12:24:18 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-33948",
                                "url": "https://ubuntu.com/security/CVE-2026-33948",
                                "cve_description": "jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte count from fgets(), causing it to truncate input at the first NUL byte and parse only the preceding prefix. This enables an attacker to craft input with a benign JSON prefix before a NUL byte followed by malicious trailing data, where jq validates only the prefix as valid JSON while silently discarding the suffix. Workflows relying on jq to validate untrusted JSON before forwarding it to downstream consumers are susceptible to parser differential attacks, as those consumers may process the full input including the malicious trailing bytes. This issue has been patched by commit 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-14 00:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport upstream changes to fix FTBFS with recent jq(1). The jq upstream",
                            "    fix for CVE-2026-33948 breaks cryptsetup's test suite. (Closes: #1135390)",
                            "  * Update Standards-Version to 4.7.4 (no changes necessary).",
                            "  * d/t/cryptroot-*: Add \"Depends: cpio\".",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.6-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Sun, 03 May 2026 15:26:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream bugfix release.",
                            "  * askpass: Fix FTBFS with glibc 2.43. (Closes: #1128538)",
                            "  * d/control: Replace B-D: libselinux1-dev with libselinux-dev.",
                            "  * d/t/cryptroot-*: Account for the linux-image package split.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guilhem Moulin <guilhem@debian.org>",
                        "date": "Thu, 02 Apr 2026 20:39:12 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.4-1ubuntu6",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:08 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Depend on busybox | busybox-static instead of busybox-initramfs",
                            "    (LP: #2157328)",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.4-1ubuntu5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2157328
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Fri, 17 Jul 2026 12:23:57 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libevent-core-2.1-7t64:ppc64el",
                "from_version": {
                    "source_package_name": "libevent",
                    "source_package_version": "2.1.12-stable-10build2",
                    "version": "2.1.12-stable-10build2"
                },
                "to_version": {
                    "source_package_name": "libevent",
                    "source_package_version": "2.1.13-stable-1build1",
                    "version": "2.1.13-stable-1build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "libevent",
                        "version": "2.1.13-stable-1build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 14:29:46 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New Upstream Release",
                            "  * d/control: Upgrade Standards-Version to 4.7.4",
                            "  * d/control: Remove Priority option",
                            "  * d/control: Remove Rules-Requires-Root option",
                            "  * d/control: Upgrade debhelper-compat version to 14",
                            "  * d/symbols: update with new symbols",
                            "  * d/*.lintian-overrides: disable unnecessary lintian-overrides",
                            ""
                        ],
                        "package": "libevent",
                        "version": "2.1.13-stable-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Nicolas Mora <babelouest@debian.org>",
                        "date": "Wed, 01 Jul 2026 11:45:31 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libexpat1:ppc64el",
                "from_version": {
                    "source_package_name": "expat",
                    "source_package_version": "2.8.2-1",
                    "version": "2.8.2-1"
                },
                "to_version": {
                    "source_package_name": "expat",
                    "source_package_version": "2.8.3-1",
                    "version": "2.8.3-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-72522",
                        "url": "https://ubuntu.com/security/CVE-2026-72522",
                        "cve_description": "libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-10 04:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-72522",
                                "url": "https://ubuntu.com/security/CVE-2026-72522",
                                "cve_description": "libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-10 04:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release:",
                            "    - fixes CVE-2026-72522: out of bounds read and resultant infinite loop",
                            "      (closes: #1144064).",
                            ""
                        ],
                        "package": "expat",
                        "version": "2.8.3-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Tue, 11 Aug 2026 06:52:38 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libffi8:ppc64el",
                "from_version": {
                    "source_package_name": "libffi",
                    "source_package_version": "3.5.2-4",
                    "version": "3.5.2-4"
                },
                "to_version": {
                    "source_package_name": "libffi",
                    "source_package_version": "3.8.0-2",
                    "version": "3.8.0-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Correct symbols file for LIBFFI_CALL_PLAN_8.[45] versioned symbols.",
                            ""
                        ],
                        "package": "libffi",
                        "version": "3.8.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sat, 15 Aug 2026 16:05:11 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Update symbols file.",
                            ""
                        ],
                        "package": "libffi",
                        "version": "3.8.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 13 Aug 2026 01:57:42 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Conditionalize new symbols on architectures.",
                            ""
                        ],
                        "package": "libffi",
                        "version": "3.7.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Mon, 13 Jul 2026 14:13:24 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Update symbols file.",
                            "  * Bump standards version.",
                            ""
                        ],
                        "package": "libffi",
                        "version": "3.7.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:27:02 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libfido2-1:ppc64el",
                "from_version": {
                    "source_package_name": "libfido2",
                    "source_package_version": "1.17.0-1",
                    "version": "1.17.0-1"
                },
                "to_version": {
                    "source_package_name": "libfido2",
                    "source_package_version": "1.17.0-2build1",
                    "version": "1.17.0-2build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "libfido2",
                        "version": "1.17.0-2build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:58:54 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "  * Use watch v5",
                            "  * Drop Priority: optional",
                            "  * Standards-Version: 4.7.4",
                            "  * Use compat 14",
                            "  * Move to pkg-security team maintainer",
                            "  * Expand fido2-tool Description, dropping overrides",
                            "  * Ship examples too",
                            "  * Improve d/copyright",
                            ""
                        ],
                        "package": "libfido2",
                        "version": "1.17.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon Josefsson <simon@josefsson.org>",
                        "date": "Wed, 22 Jul 2026 17:20:14 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libfreetype6:ppc64el",
                "from_version": {
                    "source_package_name": "freetype",
                    "source_package_version": "2.14.3+dfsg-1ubuntu1",
                    "version": "2.14.3+dfsg-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "freetype",
                    "source_package_version": "2.14.3+dfsg-2",
                    "version": "2.14.3+dfsg-2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-50811",
                        "url": "https://ubuntu.com/security/CVE-2026-50811",
                        "cve_description": "An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 23:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-50811",
                                "url": "https://ubuntu.com/security/CVE-2026-50811",
                                "cve_description": "An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 23:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: OOB read in TT_Get_Var_Design implementation",
                            "    - debian/patches/CVE-2026-50811-1.patch: Zero extras in",
                            "      src/truetype/ttgxvar.c.",
                            "    - debian/patches/CVE-2026-50811-2.patch: Updated in src/type1/t1load.c.",
                            "    - CVE-2026-50811",
                            ""
                        ],
                        "package": "freetype",
                        "version": "2.14.3+dfsg-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Thu, 16 Jul 2026 10:51:20 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "libgcc-s1:ppc64el",
                "from_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.1.0-2ubuntu1",
                    "version": "16.1.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-1ubuntu1",
                    "version": "16.2.0-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158577
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 09 Aug 2026 06:21:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * GCC 16.2.0 release.",
                            "    - Fix PR target/126581 (x86), PR tree-optimization/126504,",
                            "      PR tree-optimization/126503, PR middle-end/126497,",
                            "      PR tree-optimization/126490, PR tree-optimization/126464,",
                            "      PR tree-optimization/126476, PR tree-optimization/126464,",
                            "      PR middle-end/126084, PR tree-optimization/126471, PR target/126446,",
                            "      PR middle-end/126410, PR tree-optimization/126457,",
                            "      PR tree-optimization/126404, PR tree-optimization/126404,",
                            "      PR target/126438 (PPC), PR target/126450 (x86), PR middle-end/126447,",
                            "      PR middle-end/126405, PR rtl-optimization/126184,",
                            "      PR rtl-optimization/126184, PR target/126429 (x86),",
                            "      PR tree-optimization/125396, PR tree-optimization/125290,",
                            "      PR target/126320 (x86), PR middle-end/126341, PR target/123625 (AArch64),",
                            "      PR target/121957 (AArch64), PR rtl-optimization/125209,",
                            "      PR middle-end/124637, PR tree-optimization/126171,",
                            "      PR tree-optimization/126225, PR tree-optimization/124663, PR ipa/125207,",
                            "      PR target/119210 (AArch64), PR target/105116, PR driver/1240,",
                            "      PR ada/126553, PR ada/126379, PR ada/126482, PR algol68/126330,",
                            "      PR c++/126309, PR c++/126508, PR c++/126420, PR c++/126423,",
                            "      PR c++/126343, PR c++/126406, PR c++/119343, PR c++/126209,",
                            "      PR c++/126310, PR c++/126280, PR c++/126215, PR driver/124058,",
                            "      PR fortran/125866, PR fortran/126386, PR fortran/126303,",
                            "      PR fortran/97592, PR fortran/125998, PR sanitizer/126307,",
                            "      PR libstdc++/122197, PR libstdc++/124854, PR libstdc++/116110,",
                            "      PR libstdc++/124853, PR libstdc++/116110, PR libstdc++/124852,",
                            "      PR libstdc++/124852, PR libstdc++/124851, PR libstdc++/123165.",
                            "  * Update to git 20260809 from the gcc-16 branch.",
                            "    - Fix PR target/126484 (MIPS), PR tree-optimization/126576,",
                            "      PR tree-optimization/126547, PR tree-optimization/126549,",
                            "      PR tree-optimization/126564, PR tree-optimization/126601,",
                            "      PR target/124948, PR tree-optimization/126464, PR preprocessor/125048,",
                            "      PR libstdc++/125200, PR c++/125591, PR c++/125601, PR c++/125680,",
                            "      PR c++/125541, PR fortran/126205, PR target/126667 (S390),",
                            "      PR fortran/125263.",
                            "",
                            "  [ Matthias Klose ]",
                            "  * Update libgcc-s, libcc1, libasan and libgcobol symbols files.",
                            "  * d/rules2: Use rva23u64 with zifencei extension for Ubuntu (Vladimir Petko).",
                            "    LP: #2158577.",
                            "  * d/rules: Reformat riscv64 extensions for Debian.",
                            "  * Configure with --enable-checking=release on every architecture.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * d/rules2: Use rva20u64 with zifencei extension for Debian.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2158577
                        ],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 09 Aug 2026 06:10:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 19 Jul 2026 14:16:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260719 from the gcc-16 branch.",
                            "    - Fix PR tree-optimization/126262, PR tree-optimization/126257,",
                            "      PR middle-end/126084, PR tree-optimization/120201,",
                            "      PR tree-optimization/126194, PR tree-optimization/126150,",
                            "      PR tree-optimization/125953, PR middle-end/125875,",
                            "      PR tree-optimization/125786, PR tree-optimization/125668,",
                            "      PR tree-optimization/125296, PR tree-optimization/126008,",
                            "      PR tree-optimization/125730, PR tree-optimization/125040,",
                            "      PR ipa/125121, PR ipa/124128, PR target/126054 (S390),",
                            "      PR target/126148 (x86), PR tree-optimization/125597,",
                            "      PR tree-optimization/125597, PR tree-optimization/125597,",
                            "      PR target/126081 (or1k), PR target/126049 (RISCV),",
                            "      PR target/126098 (x86), PR target/67459 (SH), PR target/122948 (SH),",
                            "      PR target/125972 (S390), PR rtl-optimization/125173,",
                            "      PR target/124908 (AArch64), PR target/125838 (AArch64),",
                            "      PR target/125883 (x86), PR target/125818 (AArch64),",
                            "      PR target/125469 (x86), PR target/125469 (x86), PR target/125949 (x86),",
                            "      PR target/125992 (S390), PR middle-end/125977, PR target/125628 (MIPS),",
                            "      PR target/125478 (RISCV), PR target/106895 (PPC), PR target/122665 (PPC),",
                            "      PR target/125670 (RISCV), PR middle-end/125621,",
                            "      PR target/125148 (AArch64), PR tree-optimization/125431,",
                            "      PR target/125795 (AArch64), PR tree-optimization/125501,",
                            "      PR tree-optimization/125776, PR tree-optimization/125774,",
                            "      PR target/120144 (MIPS), PR ipa/125699, PR tree-optimization/125419,",
                            "      PR tree-optimization/125652, PR tree-optimization/125686,",
                            "      PR tree-optimization/125646, PR tree-optimization/125553,",
                            "      PR tree-optimization/125545, PR tree-optimization/125502,",
                            "      PR tree-optimization/125477, PR target/124948, PR c/125072, PR c/125935,",
                            "      PR c/125604, PR c/123569, PR c/125252, PR c/124303, PR c/124985,",
                            "      PR c++/126057, PR c++/126036, PR c++/126007, PR c++/125674, PR c++/91155,",
                            "      PR c++/126066, PR c++/125901, PR c++/126031, PR c++/121552, PR c++/124584,",
                            "      PR c++/121094, PR c++/117259, PR c++/123536, PR c++/125900, PR c++/125334,",
                            "      PR c++/125768, PR c++/125939, PR c++/125745, PR c++/125408, PR c++/124978,",
                            "      PR c++/115314, PR c++/125889, PR c++/125764, PR c++/125759, PR c++/65271,",
                            "      PR c++/125770, PR fortran/126234, PR fortran/125172, PR fortran/126210,",
                            "      PR fortran/126170, PR fortran/126127, PR fortran/103367,",
                            "      PR fortran/126018, PR fortran/125051, PR fortran/125902,",
                            "      PR fortran/125902, PR fortran/60576, PR fortran/125430,",
                            "      PR fortran/125527, PR fortran/125535, PR fortran/125650,",
                            "      PR fortran/125481, PR fortran/125527, PR fortran/125528,",
                            "      PR fortran/125529, PR fortran/125530, PR fortran/125531,",
                            "      PR fortran/125534, PR fortran/125535, PR lto/125257, PR libgcc/123976,",
                            "      PR target/125752 (AVR), PR libfortran/126116, PR libstdc++/126111,",
                            "      PR libstdc++/125956, PR libstdc++/118158, PR libstdc++/125228,",
                            "      PR libstdc++/125890.",
                            "  * Let the ada build fail on an alihash mismatch, if fail_on_alihash_mismatch",
                            "    is enabled.",
                            "  * Enable Modula-2 on powerpc and ppc64. Closes: #1141560, #1141596.",
                            "  * Enable LRA by default on m68k for snapshot builds (Adrian Glaubitz).",
                            "    Addresses: #1142039.",
                            "  * Disable running tests on Debian/riscv64 for meaningful build times.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 19 Jul 2026 13:28:39 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgirepository-2.0-0:ppc64el",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.2-1",
                    "version": "2.89.2-1"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.3-4",
                    "version": "2.89.3-4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from unstable",
                            "    - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "      d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "      Add patches from upstream (to be released in 2.89.4) to address",
                            "      an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "      and fix a related test failure on minimal systems",
                            "      (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            "  * d/p/workarounds: Mark memory-monitor-psi tests as flaky",
                            "    (Mitigates: #1143197, #1143241)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-4",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 21:28:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon McVittie ]",
                            "  * Merge packaging from unstable",
                            "    - d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "      by ensuring that user-session-migration gets removed rather than",
                            "      making libglib2.0-0t64 be reinstalled",
                            "  * Drop patches added by 2.88.3-2, already part of 2.89.x",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 06 Aug 2026 14:23:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate",
                            "    previous changelog entry",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * debian/libglib2.0-0t64.symbols: Add new symbols",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 15:55:39 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "    d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "    Add patches from upstream (to be released in 2.89.4) to address",
                            "    an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "    and fix a related test failure on minimal systems",
                            "    (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 10:10:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport patches from 2.89.0 to harden D-Bus introspection parsing",
                            "    - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,",
                            "      d/p/tests-Improve-D-Bus-introspection-test-paths.patch,",
                            "      d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,",
                            "      d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:",
                            "      Avoid a possible integer underflow if parsing malformed D-Bus",
                            "      introspection XML sent by a malicious service",
                            "      (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)",
                            "  * d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "    by ensuring that user-session-migration gets removed rather than",
                            "    making libglib2.0-0t64 be reinstalled",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:22:30 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "    - Fixes resource exhaustion if a malicious client can contact a",
                            "      GDBusServer (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/control, d/gbp.conf: Use debian/forky branch",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:13:54 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libglib2.0-0t64:ppc64el",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.2-1",
                    "version": "2.89.2-1"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.3-4",
                    "version": "2.89.3-4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from unstable",
                            "    - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "      d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "      Add patches from upstream (to be released in 2.89.4) to address",
                            "      an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "      and fix a related test failure on minimal systems",
                            "      (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            "  * d/p/workarounds: Mark memory-monitor-psi tests as flaky",
                            "    (Mitigates: #1143197, #1143241)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-4",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 21:28:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon McVittie ]",
                            "  * Merge packaging from unstable",
                            "    - d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "      by ensuring that user-session-migration gets removed rather than",
                            "      making libglib2.0-0t64 be reinstalled",
                            "  * Drop patches added by 2.88.3-2, already part of 2.89.x",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 06 Aug 2026 14:23:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate",
                            "    previous changelog entry",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * debian/libglib2.0-0t64.symbols: Add new symbols",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 15:55:39 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "    d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "    Add patches from upstream (to be released in 2.89.4) to address",
                            "    an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "    and fix a related test failure on minimal systems",
                            "    (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 10:10:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport patches from 2.89.0 to harden D-Bus introspection parsing",
                            "    - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,",
                            "      d/p/tests-Improve-D-Bus-introspection-test-paths.patch,",
                            "      d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,",
                            "      d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:",
                            "      Avoid a possible integer underflow if parsing malformed D-Bus",
                            "      introspection XML sent by a malicious service",
                            "      (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)",
                            "  * d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "    by ensuring that user-session-migration gets removed rather than",
                            "    making libglib2.0-0t64 be reinstalled",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:22:30 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "    - Fixes resource exhaustion if a malicious client can contact a",
                            "      GDBusServer (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/control, d/gbp.conf: Use debian/forky branch",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:13:54 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libglib2.0-bin",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.2-1",
                    "version": "2.89.2-1"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.3-4",
                    "version": "2.89.3-4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from unstable",
                            "    - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "      d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "      Add patches from upstream (to be released in 2.89.4) to address",
                            "      an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "      and fix a related test failure on minimal systems",
                            "      (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            "  * d/p/workarounds: Mark memory-monitor-psi tests as flaky",
                            "    (Mitigates: #1143197, #1143241)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-4",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 21:28:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon McVittie ]",
                            "  * Merge packaging from unstable",
                            "    - d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "      by ensuring that user-session-migration gets removed rather than",
                            "      making libglib2.0-0t64 be reinstalled",
                            "  * Drop patches added by 2.88.3-2, already part of 2.89.x",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 06 Aug 2026 14:23:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate",
                            "    previous changelog entry",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * debian/libglib2.0-0t64.symbols: Add new symbols",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 15:55:39 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "    d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "    Add patches from upstream (to be released in 2.89.4) to address",
                            "    an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "    and fix a related test failure on minimal systems",
                            "    (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 10:10:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport patches from 2.89.0 to harden D-Bus introspection parsing",
                            "    - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,",
                            "      d/p/tests-Improve-D-Bus-introspection-test-paths.patch,",
                            "      d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,",
                            "      d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:",
                            "      Avoid a possible integer underflow if parsing malformed D-Bus",
                            "      introspection XML sent by a malicious service",
                            "      (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)",
                            "  * d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "    by ensuring that user-session-migration gets removed rather than",
                            "    making libglib2.0-0t64 be reinstalled",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:22:30 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "    - Fixes resource exhaustion if a malicious client can contact a",
                            "      GDBusServer (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/control, d/gbp.conf: Use debian/forky branch",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:13:54 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libglib2.0-data",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.2-1",
                    "version": "2.89.2-1"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.3-4",
                    "version": "2.89.3-4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from unstable",
                            "    - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "      d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "      Add patches from upstream (to be released in 2.89.4) to address",
                            "      an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "      and fix a related test failure on minimal systems",
                            "      (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            "  * d/p/workarounds: Mark memory-monitor-psi tests as flaky",
                            "    (Mitigates: #1143197, #1143241)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-4",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 21:28:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon McVittie ]",
                            "  * Merge packaging from unstable",
                            "    - d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "      by ensuring that user-session-migration gets removed rather than",
                            "      making libglib2.0-0t64 be reinstalled",
                            "  * Drop patches added by 2.88.3-2, already part of 2.89.x",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 06 Aug 2026 14:23:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate",
                            "    previous changelog entry",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * debian/libglib2.0-0t64.symbols: Add new symbols",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 15:55:39 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "    d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "    Add patches from upstream (to be released in 2.89.4) to address",
                            "    an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "    and fix a related test failure on minimal systems",
                            "    (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 10:10:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport patches from 2.89.0 to harden D-Bus introspection parsing",
                            "    - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,",
                            "      d/p/tests-Improve-D-Bus-introspection-test-paths.patch,",
                            "      d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,",
                            "      d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:",
                            "      Avoid a possible integer underflow if parsing malformed D-Bus",
                            "      introspection XML sent by a malicious service",
                            "      (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)",
                            "  * d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "    by ensuring that user-session-migration gets removed rather than",
                            "    making libglib2.0-0t64 be reinstalled",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:22:30 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "    - Fixes resource exhaustion if a malicious client can contact a",
                            "      GDBusServer (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/control, d/gbp.conf: Use debian/forky branch",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:13:54 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgnutls30t64:ppc64el",
                "from_version": {
                    "source_package_name": "gnutls28",
                    "source_package_version": "3.8.12-2ubuntu1.1",
                    "version": "3.8.12-2ubuntu1.1"
                },
                "to_version": {
                    "source_package_name": "gnutls28",
                    "source_package_version": "3.8.13-1ubuntu1",
                    "version": "3.8.13-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-33846",
                        "url": "https://ubuntu.com/security/CVE-2026-33846",
                        "cve_description": "A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-04 10:15:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42009",
                        "url": "https://ubuntu.com/security/CVE-2026-42009",
                        "cve_description": "A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-18 13:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-33845",
                        "url": "https://ubuntu.com/security/CVE-2026-33845",
                        "cve_description": "A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-3832",
                        "url": "https://ubuntu.com/security/CVE-2026-3832",
                        "cve_description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-3833",
                        "url": "https://ubuntu.com/security/CVE-2026-3833",
                        "cve_description": "A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42011",
                        "url": "https://ubuntu.com/security/CVE-2026-42011",
                        "cve_description": "A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-07 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42010",
                        "url": "https://ubuntu.com/security/CVE-2026-42010",
                        "cve_description": "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-07 12:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5260",
                        "url": "https://ubuntu.com/security/CVE-2026-5260",
                        "cve_description": "A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42012",
                        "url": "https://ubuntu.com/security/CVE-2026-42012",
                        "cve_description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42013",
                        "url": "https://ubuntu.com/security/CVE-2026-42013",
                        "cve_description": "A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42014",
                        "url": "https://ubuntu.com/security/CVE-2026-42014",
                        "cve_description": "A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-16 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42015",
                        "url": "https://ubuntu.com/security/CVE-2026-42015",
                        "cve_description": "A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5419",
                        "url": "https://ubuntu.com/security/CVE-2026-5419",
                        "cve_description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-01 21:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2155651,
                    2150202
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-33846",
                                "url": "https://ubuntu.com/security/CVE-2026-33846",
                                "cve_description": "A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-04 10:15:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42009",
                                "url": "https://ubuntu.com/security/CVE-2026-42009",
                                "cve_description": "A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-18 13:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-33845",
                                "url": "https://ubuntu.com/security/CVE-2026-33845",
                                "cve_description": "A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-3832",
                                "url": "https://ubuntu.com/security/CVE-2026-3832",
                                "cve_description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-3833",
                                "url": "https://ubuntu.com/security/CVE-2026-3833",
                                "cve_description": "A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42011",
                                "url": "https://ubuntu.com/security/CVE-2026-42011",
                                "cve_description": "A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-07 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42010",
                                "url": "https://ubuntu.com/security/CVE-2026-42010",
                                "cve_description": "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-07 12:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5260",
                                "url": "https://ubuntu.com/security/CVE-2026-5260",
                                "cve_description": "A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42012",
                                "url": "https://ubuntu.com/security/CVE-2026-42012",
                                "cve_description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42013",
                                "url": "https://ubuntu.com/security/CVE-2026-42013",
                                "cve_description": "A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42014",
                                "url": "https://ubuntu.com/security/CVE-2026-42014",
                                "cve_description": "A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-16 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42015",
                                "url": "https://ubuntu.com/security/CVE-2026-42015",
                                "cve_description": "A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5419",
                                "url": "https://ubuntu.com/security/CVE-2026-5419",
                                "cve_description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-01 21:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2155651, LP: #2150202). Remaining changes:",
                            "    - d/p/9259100633b7: Enable CET support.",
                            "    - d/c/config: Forcefully disable TLS 1.0 and 1.1.",
                            "    - d/c/config: Forcefully disable DTLS 0.9 and 1.0.",
                            "    - d/rules: Set priority to only allow TLS1.2, DTLS1.2 and TLS1.3.",
                            "  * Drop Changes:",
                            "    - present upstream: d/p/CVE-2026-33846*.patch",
                            "    - present upstream: d/p/CVE-2026-42009-*.patch",
                            "    - present upstream: d/p/CVE-2026-33845*.patch",
                            "    - present upstream: d/p/CVE-2026-3832.patch",
                            "    - present upstream: d/p/CVE-2026-3833.patch",
                            "    - present upstream: d/p/CVE-2026-42011.patch",
                            "    - present upstream: d/p/CVE-2026-42010.patch",
                            "    - present upstream: d/p/CVE-2026-5260-*.patch",
                            "    - present upstream: d/p/CVE-2026-42012*.patch",
                            "    - present upstream: d/p/CVE-2026-42013*.patch",
                            "    - present upstream: d/p/CVE-2026-42014.patch",
                            "    - present upstream: d/p/CVE-2026-42015.patch",
                            "    - present upstream: d/p/CVE-2026-5419*.patch",
                            "    - d/p/crypto-config.patch",
                            "  * New Changes:",
                            "    - d/p/fix_test-getaddrinfo.patch: Avoid failure in CI due to unreachable DNS server.",
                            ""
                        ],
                        "package": "gnutls28",
                        "version": "3.8.13-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2155651,
                            2150202
                        ],
                        "author": "Ghadi Elie Rahme <ghadi.rahme@canonical.com>",
                        "date": "Wed, 17 Jun 2026 19:36:03 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream bugfix/security release.",
                            "  * Unfuzz patches.",
                            "  * Update copyright info.",
                            "  * Update symbol file.",
                            ""
                        ],
                        "package": "gnutls28",
                        "version": "3.8.13-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Fri, 01 May 2026 07:19:11 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop OpenSSL wrapper library again.",
                            ""
                        ],
                        "package": "gnutls28",
                        "version": "3.8.12-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Sat, 21 Feb 2026 13:31:21 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgssapi-krb5-2:ppc64el",
                "from_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-2ubuntu4",
                    "version": "1.22.1-2ubuntu4"
                },
                "to_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-3ubuntu2",
                    "version": "1.22.1-3ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-11850",
                        "url": "https://ubuntu.com/security/CVE-2026-11850",
                        "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-11 10:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40355",
                        "url": "https://ubuntu.com/security/CVE-2026-40355",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40356",
                        "url": "https://ubuntu.com/security/CVE-2026-40356",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153198,
                    2155018
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:57:38 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153198, LP: #2155018). Remaining changes:",
                            "    - d/t/util: add test cleanup and log function",
                            "    - d/t/util: Prepend includedir /etc/krb5.conf.d/ for the configuration file",
                            "      created in create_realm.",
                            "    - d/t/includedir-ordering: Add new test.",
                            "    - Fix FTBFS test t_otp.py (LP #2142451):",
                            "      + d/p/set-fork-start-method-t-otpy.patch: Python 3.14 changes the default",
                            "        start method of multiprocessing to 'forkserver'. This introduces issues",
                            "        in the test t_otp.py that does not use a main block. Set the start",
                            "        method to force 'fork' instead.",
                            "    - d/p/default-enctype-list.patch: do not default to weak encryption",
                            "      algorithms (LP #2144909)",
                            "    - d/NEWS: explain weak algorithms are no longer default options",
                            "  * Dropped:",
                            "    - d/p/fix-strchr-conformance-to-c23.patch: Fix FTBFS with glibc2.43",
                            "      (LP #2142893)",
                            "      [In 1.22.1-3]",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153198,
                            2155018
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Mon, 29 Jun 2026 15:44:10 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11850",
                                "url": "https://ubuntu.com/security/CVE-2026-11850",
                                "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-11 10:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Emmanuel Arias ]",
                            "  * CVE-2026-11850: Prevent read overrun in libkdb_ldap (Closes: #1139821).",
                            "",
                            "  [ Sam Hartman ]",
                            "  * Fix C23 use of strchr, Closes: #1128877",
                            "  * Remove lintian tag that ldap plugin is linked against libc6; no longer needed",
                            "  * Upstream patch for OpenSSL 4.0 compatibility, Closes: #1138466",
                            "  * Upstream commit f5bbfa4 to use openssl facilities to verify certificates; needed to avoid discarding const qualifier from Openssl 4.0 patch",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sam Hartman <hartmans@debian.org>",
                        "date": "Fri, 19 Jun 2026 08:30:16 -0600"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-40355",
                                "url": "https://ubuntu.com/security/CVE-2026-40355",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-40356",
                                "url": "https://ubuntu.com/security/CVE-2026-40356",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Non-maintainer upload.",
                            "  * Fix two NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)",
                            "    (Closes: #1135317)",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-2.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Salvatore Bonaccorso <carnil@debian.org>",
                        "date": "Sun, 10 May 2026 09:08:30 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgstreamer1.0-0:ppc64el",
                "from_version": {
                    "source_package_name": "gstreamer1.0",
                    "source_package_version": "1.28.4-2",
                    "version": "1.28.4-2"
                },
                "to_version": {
                    "source_package_name": "gstreamer1.0",
                    "source_package_version": "1.28.6-1",
                    "version": "1.28.6-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 1.28.6",
                            ""
                        ],
                        "package": "gstreamer1.0",
                        "version": "1.28.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Leeman <marc.leeman@gmail.com>",
                        "date": "Wed, 05 Aug 2026 15:39:54 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 1.28.5",
                            ""
                        ],
                        "package": "gstreamer1.0",
                        "version": "1.28.5-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Leeman <marc.leeman@gmail.com>",
                        "date": "Thu, 16 Jul 2026 14:23:06 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libisns0t64:ppc64el",
                "from_version": {
                    "source_package_name": "open-isns",
                    "source_package_version": "0.101-2.1",
                    "version": "0.101-2.1"
                },
                "to_version": {
                    "source_package_name": "open-isns",
                    "source_package_version": "0.103-2",
                    "version": "0.103-2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-55995",
                        "url": "https://ubuntu.com/security/CVE-2026-55995",
                        "cve_description": "A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.       This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-29 14:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-55995",
                                "url": "https://ubuntu.com/security/CVE-2026-55995",
                                "cve_description": "A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.       This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-29 14:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Pick upstream fix for CVE-2026-55995 (Closes: #1143053)",
                            "  * d/changelog: remove incorrect CVE fix mention in 0.103-1",
                            "  * d/control: remove Testsuite: autopkgtest to fix lintian warning",
                            "    unnecessary-testsuite-autopkgtest-field",
                            "  * Remove Christian Seiler from Uploaders.",
                            "    Thank you for your past contributions.",
                            ""
                        ],
                        "package": "open-isns",
                        "version": "0.103-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Sat, 01 Aug 2026 14:32:19 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream version 0.103",
                            "  * d/control: set X-Style black",
                            "  * Switch build system to meson. Upstream replaced the buildsystem.",
                            "    This also drops building static libraries.",
                            ""
                        ],
                        "package": "open-isns",
                        "version": "0.103-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Fri, 31 Jul 2026 19:09:07 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libjq1:ppc64el",
                "from_version": {
                    "source_package_name": "jq",
                    "source_package_version": "1.8.1-4ubuntu1",
                    "version": "1.8.1-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "jq",
                    "source_package_version": "1.8.2-1ubuntu1",
                    "version": "1.8.2-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-49839",
                        "url": "https://ubuntu.com/security/CVE-2026-49839",
                        "cve_description": "jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-25 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47770",
                        "url": "https://ubuntu.com/security/CVE-2026-47770",
                        "cve_description": "jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-25 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40612",
                        "url": "https://ubuntu.com/security/CVE-2026-40612",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-41256",
                        "url": "https://ubuntu.com/security/CVE-2026-41256",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-41257",
                        "url": "https://ubuntu.com/security/CVE-2026-41257",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-43894",
                        "url": "https://ubuntu.com/security/CVE-2026-43894",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-43895",
                        "url": "https://ubuntu.com/security/CVE-2026-43895",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-43896",
                        "url": "https://ubuntu.com/security/CVE-2026-43896",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-44777",
                        "url": "https://ubuntu.com/security/CVE-2026-44777",
                        "cve_description": "jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-32316",
                        "url": "https://ubuntu.com/security/CVE-2026-32316",
                        "cve_description": "jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, resulting in a drastically undersized heap buffer. Subsequent memory copy operations then write the full string data into this undersized buffer, causing a heap buffer overflow classified as CWE-190 (Integer Overflow) leading to CWE-122 (Heap-based Buffer Overflow). Any system evaluating untrusted jq queries is affected, as an attacker can crash the process or potentially achieve further exploitation through heap corruption by crafting queries that produce extremely large strings. The root cause is the absence of string size bounds checking, unlike arrays and objects which already have size limits. The issue has been addressed in commit e47e56d226519635768e6aab2f38f0ab037c09e5.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-13 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-33947",
                        "url": "https://ubuntu.com/security/CVE-2026-33947",
                        "cve_description": "jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-13 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-33948",
                        "url": "https://ubuntu.com/security/CVE-2026-33948",
                        "cve_description": "jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte count from fgets(), causing it to truncate input at the first NUL byte and parse only the preceding prefix. This enables an attacker to craft input with a benign JSON prefix before a NUL byte followed by malicious trailing data, where jq validates only the prefix as valid JSON while silently discarding the suffix. Workflows relying on jq to validate untrusted JSON before forwarding it to downstream consumers are susceptible to parser differential attacks, as those consumers may process the full input including the malicious trailing bytes. This issue has been patched by commit 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-14 00:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-39956",
                        "url": "https://ubuntu.com/security/CVE-2026-39956",
                        "cve_description": "jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks that are stripped in release builds compiled with -DNDEBUG. This allows an attacker to crash jq trivially with input like _strindices(0), and by crafting a numeric value whose IEEE-754 bit pattern maps to a chosen pointer, achieve a controlled pointer dereference and limited memory read/probe primitive. Any deployment that evaluates untrusted jq filters against a release build is vulnerable. This issue has been patched in commit fdf8ef0f0810e3d365cdd5160de43db46f57ed03.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-13 23:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-39979",
                        "url": "https://ubuntu.com/security/CVE-2026-39979",
                        "cve_description": "jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-13 23:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40164",
                        "url": "https://ubuntu.com/security/CVE-2026-40164",
                        "cve_description": "jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to precompute key collisions offline. By supplying a crafted JSON object (~100 KB) where all keys hashed to the same bucket, hash table lookups degraded from O(1) to O(n), turning any jq expression into an O(n²) operation and causing significant CPU exhaustion. This affected common jq use cases such as CI/CD pipelines, web services, and data processing scripts, and was far more practical to exploit than existing heap overflow issues since it required only a small payload. This issue has been patched in commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-14 00:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153197
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153197). Remaining changes:",
                            "    - d/control: don't build-depend on python3-jsonschema on i386, since that",
                            "      package is uninstallable on Ubuntu i386. This works for now because",
                            "      python3-jsonschema is only used in a script during tests if the manual.yml",
                            "      file is patched by the packaging. (LP #2104170)",
                            ""
                        ],
                        "package": "jq",
                        "version": "1.8.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153197
                        ],
                        "author": "Jonas Jelten <jj@ubuntu.com>",
                        "date": "Sat, 01 Aug 2026 05:30:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 1.8.2.",
                            "  * d/patches: Remove unnecessary upstream patches.",
                            "  * d/gbp.conf: Update debian-branch.",
                            ""
                        ],
                        "package": "jq",
                        "version": "1.8.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "ChangZhuo Chen (陳昌倬) <czchen@debian.org>",
                        "date": "Tue, 23 Jun 2026 21:04:10 +0800"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-49839",
                                "url": "https://ubuntu.com/security/CVE-2026-49839",
                                "cve_description": "jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-25 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Cherry-pick upstream fix for the following:",
                            "    * GHSA-ggc9-rpv2-xgpm",
                            "    * GHSA-gvwx-xj9r-3frq",
                            "    * CVE-2026-49839",
                            ""
                        ],
                        "package": "jq",
                        "version": "1.8.1-8",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "ChangZhuo Chen (陳昌倬) <czchen@debian.org>",
                        "date": "Tue, 09 Jun 2026 09:48:23 +0800"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47770",
                                "url": "https://ubuntu.com/security/CVE-2026-47770",
                                "cve_description": "jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-25 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Cherry-pick upstream fix for CVE-2026-47770.",
                            "  * d/patches: Add no-forwarded for all upstream fixes.",
                            ""
                        ],
                        "package": "jq",
                        "version": "1.8.1-7",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "ChangZhuo Chen (陳昌倬) <czchen@debian.org>",
                        "date": "Wed, 27 May 2026 21:19:20 +0800"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-40612",
                                "url": "https://ubuntu.com/security/CVE-2026-40612",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-41256",
                                "url": "https://ubuntu.com/security/CVE-2026-41256",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-41257",
                                "url": "https://ubuntu.com/security/CVE-2026-41257",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-43894",
                                "url": "https://ubuntu.com/security/CVE-2026-43894",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-43895",
                                "url": "https://ubuntu.com/security/CVE-2026-43895",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-43896",
                                "url": "https://ubuntu.com/security/CVE-2026-43896",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-44777",
                                "url": "https://ubuntu.com/security/CVE-2026-44777",
                                "cve_description": "jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Cherry-pick upstream fix for the following CVE (Closes: #1136445):",
                            "    * CVE-2026-40612",
                            "    * CVE-2026-41256",
                            "    * CVE-2026-41257",
                            "    * CVE-2026-43894",
                            "    * CVE-2026-43895",
                            "    * CVE-2026-43896",
                            "    * CVE-2026-44777",
                            ""
                        ],
                        "package": "jq",
                        "version": "1.8.1-6",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "ChangZhuo Chen (陳昌倬) <czchen@debian.org>",
                        "date": "Sun, 17 May 2026 01:00:50 +0800"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-32316",
                                "url": "https://ubuntu.com/security/CVE-2026-32316",
                                "cve_description": "jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31 bytes causes a 32-bit unsigned integer overflow in the buffer allocation size calculation, resulting in a drastically undersized heap buffer. Subsequent memory copy operations then write the full string data into this undersized buffer, causing a heap buffer overflow classified as CWE-190 (Integer Overflow) leading to CWE-122 (Heap-based Buffer Overflow). Any system evaluating untrusted jq queries is affected, as an attacker can crash the process or potentially achieve further exploitation through heap corruption by crafting queries that produce extremely large strings. The root cause is the absence of string size bounds checking, unlike arrays and objects which already have size limits. The issue has been addressed in commit e47e56d226519635768e6aab2f38f0ab037c09e5.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-13 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-33947",
                                "url": "https://ubuntu.com/security/CVE-2026-33947",
                                "cve_description": "jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects the JSON parser, not runtime path operations where arrays can be programmatically constructed to arbitrary lengths. The impact is denial of service (unrecoverable crash) affecting any application or service that processes untrusted JSON input through jq's setpath, getpath, or delpaths builtins. This issue has been addressed in commit fb59f1491058d58bdc3e8dd28f1773d1ac690a1f.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-13 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-33948",
                                "url": "https://ubuntu.com/security/CVE-2026-33948",
                                "cve_description": "jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte count from fgets(), causing it to truncate input at the first NUL byte and parse only the preceding prefix. This enables an attacker to craft input with a benign JSON prefix before a NUL byte followed by malicious trailing data, where jq validates only the prefix as valid JSON while silently discarding the suffix. Workflows relying on jq to validate untrusted JSON before forwarding it to downstream consumers are susceptible to parser differential attacks, as those consumers may process the full input including the malicious trailing bytes. This issue has been patched by commit 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-14 00:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-39956",
                                "url": "https://ubuntu.com/security/CVE-2026-39956",
                                "cve_description": "jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks that are stripped in release builds compiled with -DNDEBUG. This allows an attacker to crash jq trivially with input like _strindices(0), and by crafting a numeric value whose IEEE-754 bit pattern maps to a chosen pointer, achieve a controlled pointer dereference and limited memory read/probe primitive. Any deployment that evaluates untrusted jq filters against a release build is vulnerable. This issue has been patched in commit fdf8ef0f0810e3d365cdd5160de43db46f57ed03.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-13 23:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-39979",
                                "url": "https://ubuntu.com/security/CVE-2026-39979",
                                "cve_description": "jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-13 23:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-40164",
                                "url": "https://ubuntu.com/security/CVE-2026-40164",
                                "cve_description": "jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to precompute key collisions offline. By supplying a crafted JSON object (~100 KB) where all keys hashed to the same bucket, hash table lookups degraded from O(1) to O(n), turning any jq expression into an O(n²) operation and causing significant CPU exhaustion. This affected common jq use cases such as CI/CD pipelines, web services, and data processing scripts, and was far more practical to exploit than existing heap overflow issues since it required only a small payload. This issue has been patched in commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-14 00:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/control: Bump Standards-Version to 4.7.4:",
                            "    * Remove unnecessary Priority, Rules-Required-Root.",
                            "  * Cherry-pick upstream fix for the following CVE (Closes: #1133921):",
                            "    * CVE-2026-32316",
                            "    * CVE-2026-33947",
                            "    * CVE-2026-33948",
                            "    * CVE-2026-39956",
                            "    * CVE-2026-39979",
                            "    * CVE-2026-40164",
                            ""
                        ],
                        "package": "jq",
                        "version": "1.8.1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "ChangZhuo Chen (陳昌倬) <czchen@debian.org>",
                        "date": "Fri, 17 Apr 2026 09:31:25 +0800"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libjs-sphinxdoc",
                "from_version": {
                    "source_package_name": "sphinx",
                    "source_package_version": "9.1.0-4",
                    "version": "9.1.0-4"
                },
                "to_version": {
                    "source_package_name": "sphinx",
                    "source_package_version": "9.1.0-6",
                    "version": "9.1.0-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Require texlive-latex-base >= 2026.20260711. Thanks to Hilmar Preuße",
                            "    for the hint!",
                            ""
                        ],
                        "package": "sphinx",
                        "version": "9.1.0-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Dmitry Shachnev <mitya57@debian.org>",
                        "date": "Sat, 18 Jul 2026 20:21:54 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Dmitry Shachnev ]",
                            "  * Replace snowball-3.1.0.diff with the version that was applied upstream.",
                            "  * Add a patch to bump Docutils upper limit to 0.24.",
                            "  * Backport upstream patch to fix LaTeX builds with June 2026 TeX Live",
                            "    (closes: #1142055).",
                            "  * Copy sphinx/locale to the test directory before running tests.",
                            "    This fixes tests when sphinx-common is not installed, e.g. for nodoc.",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * Salsa CI: test the nocheck & nodoc profiles.",
                            "  * Salsa CI: disable two jobs that are useless for packages only building",
                            "    for \"all\" architecture.",
                            ""
                        ],
                        "package": "sphinx",
                        "version": "9.1.0-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Dmitry Shachnev <mitya57@debian.org>",
                        "date": "Fri, 17 Jul 2026 09:59:49 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libk5crypto3:ppc64el",
                "from_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-2ubuntu4",
                    "version": "1.22.1-2ubuntu4"
                },
                "to_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-3ubuntu2",
                    "version": "1.22.1-3ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-11850",
                        "url": "https://ubuntu.com/security/CVE-2026-11850",
                        "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-11 10:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40355",
                        "url": "https://ubuntu.com/security/CVE-2026-40355",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40356",
                        "url": "https://ubuntu.com/security/CVE-2026-40356",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153198,
                    2155018
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:57:38 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153198, LP: #2155018). Remaining changes:",
                            "    - d/t/util: add test cleanup and log function",
                            "    - d/t/util: Prepend includedir /etc/krb5.conf.d/ for the configuration file",
                            "      created in create_realm.",
                            "    - d/t/includedir-ordering: Add new test.",
                            "    - Fix FTBFS test t_otp.py (LP #2142451):",
                            "      + d/p/set-fork-start-method-t-otpy.patch: Python 3.14 changes the default",
                            "        start method of multiprocessing to 'forkserver'. This introduces issues",
                            "        in the test t_otp.py that does not use a main block. Set the start",
                            "        method to force 'fork' instead.",
                            "    - d/p/default-enctype-list.patch: do not default to weak encryption",
                            "      algorithms (LP #2144909)",
                            "    - d/NEWS: explain weak algorithms are no longer default options",
                            "  * Dropped:",
                            "    - d/p/fix-strchr-conformance-to-c23.patch: Fix FTBFS with glibc2.43",
                            "      (LP #2142893)",
                            "      [In 1.22.1-3]",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153198,
                            2155018
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Mon, 29 Jun 2026 15:44:10 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11850",
                                "url": "https://ubuntu.com/security/CVE-2026-11850",
                                "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-11 10:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Emmanuel Arias ]",
                            "  * CVE-2026-11850: Prevent read overrun in libkdb_ldap (Closes: #1139821).",
                            "",
                            "  [ Sam Hartman ]",
                            "  * Fix C23 use of strchr, Closes: #1128877",
                            "  * Remove lintian tag that ldap plugin is linked against libc6; no longer needed",
                            "  * Upstream patch for OpenSSL 4.0 compatibility, Closes: #1138466",
                            "  * Upstream commit f5bbfa4 to use openssl facilities to verify certificates; needed to avoid discarding const qualifier from Openssl 4.0 patch",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sam Hartman <hartmans@debian.org>",
                        "date": "Fri, 19 Jun 2026 08:30:16 -0600"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-40355",
                                "url": "https://ubuntu.com/security/CVE-2026-40355",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-40356",
                                "url": "https://ubuntu.com/security/CVE-2026-40356",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Non-maintainer upload.",
                            "  * Fix two NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)",
                            "    (Closes: #1135317)",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-2.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Salvatore Bonaccorso <carnil@debian.org>",
                        "date": "Sun, 10 May 2026 09:08:30 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libkmod2:ppc64el",
                "from_version": {
                    "source_package_name": "kmod",
                    "source_package_version": "34.2-2ubuntu2",
                    "version": "34.2-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "kmod",
                    "source_package_version": "34.2-2ubuntu3",
                    "version": "34.2-2ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "kmod",
                        "version": "34.2-2ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 14:28:11 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libkrb5-3:ppc64el",
                "from_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-2ubuntu4",
                    "version": "1.22.1-2ubuntu4"
                },
                "to_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-3ubuntu2",
                    "version": "1.22.1-3ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-11850",
                        "url": "https://ubuntu.com/security/CVE-2026-11850",
                        "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-11 10:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40355",
                        "url": "https://ubuntu.com/security/CVE-2026-40355",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40356",
                        "url": "https://ubuntu.com/security/CVE-2026-40356",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153198,
                    2155018
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:57:38 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153198, LP: #2155018). Remaining changes:",
                            "    - d/t/util: add test cleanup and log function",
                            "    - d/t/util: Prepend includedir /etc/krb5.conf.d/ for the configuration file",
                            "      created in create_realm.",
                            "    - d/t/includedir-ordering: Add new test.",
                            "    - Fix FTBFS test t_otp.py (LP #2142451):",
                            "      + d/p/set-fork-start-method-t-otpy.patch: Python 3.14 changes the default",
                            "        start method of multiprocessing to 'forkserver'. This introduces issues",
                            "        in the test t_otp.py that does not use a main block. Set the start",
                            "        method to force 'fork' instead.",
                            "    - d/p/default-enctype-list.patch: do not default to weak encryption",
                            "      algorithms (LP #2144909)",
                            "    - d/NEWS: explain weak algorithms are no longer default options",
                            "  * Dropped:",
                            "    - d/p/fix-strchr-conformance-to-c23.patch: Fix FTBFS with glibc2.43",
                            "      (LP #2142893)",
                            "      [In 1.22.1-3]",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153198,
                            2155018
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Mon, 29 Jun 2026 15:44:10 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11850",
                                "url": "https://ubuntu.com/security/CVE-2026-11850",
                                "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-11 10:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Emmanuel Arias ]",
                            "  * CVE-2026-11850: Prevent read overrun in libkdb_ldap (Closes: #1139821).",
                            "",
                            "  [ Sam Hartman ]",
                            "  * Fix C23 use of strchr, Closes: #1128877",
                            "  * Remove lintian tag that ldap plugin is linked against libc6; no longer needed",
                            "  * Upstream patch for OpenSSL 4.0 compatibility, Closes: #1138466",
                            "  * Upstream commit f5bbfa4 to use openssl facilities to verify certificates; needed to avoid discarding const qualifier from Openssl 4.0 patch",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sam Hartman <hartmans@debian.org>",
                        "date": "Fri, 19 Jun 2026 08:30:16 -0600"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-40355",
                                "url": "https://ubuntu.com/security/CVE-2026-40355",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-40356",
                                "url": "https://ubuntu.com/security/CVE-2026-40356",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Non-maintainer upload.",
                            "  * Fix two NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)",
                            "    (Closes: #1135317)",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-2.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Salvatore Bonaccorso <carnil@debian.org>",
                        "date": "Sun, 10 May 2026 09:08:30 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libkrb5support0:ppc64el",
                "from_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-2ubuntu4",
                    "version": "1.22.1-2ubuntu4"
                },
                "to_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-3ubuntu2",
                    "version": "1.22.1-3ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-11850",
                        "url": "https://ubuntu.com/security/CVE-2026-11850",
                        "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-11 10:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40355",
                        "url": "https://ubuntu.com/security/CVE-2026-40355",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40356",
                        "url": "https://ubuntu.com/security/CVE-2026-40356",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153198,
                    2155018
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:57:38 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153198, LP: #2155018). Remaining changes:",
                            "    - d/t/util: add test cleanup and log function",
                            "    - d/t/util: Prepend includedir /etc/krb5.conf.d/ for the configuration file",
                            "      created in create_realm.",
                            "    - d/t/includedir-ordering: Add new test.",
                            "    - Fix FTBFS test t_otp.py (LP #2142451):",
                            "      + d/p/set-fork-start-method-t-otpy.patch: Python 3.14 changes the default",
                            "        start method of multiprocessing to 'forkserver'. This introduces issues",
                            "        in the test t_otp.py that does not use a main block. Set the start",
                            "        method to force 'fork' instead.",
                            "    - d/p/default-enctype-list.patch: do not default to weak encryption",
                            "      algorithms (LP #2144909)",
                            "    - d/NEWS: explain weak algorithms are no longer default options",
                            "  * Dropped:",
                            "    - d/p/fix-strchr-conformance-to-c23.patch: Fix FTBFS with glibc2.43",
                            "      (LP #2142893)",
                            "      [In 1.22.1-3]",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153198,
                            2155018
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Mon, 29 Jun 2026 15:44:10 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11850",
                                "url": "https://ubuntu.com/security/CVE-2026-11850",
                                "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-11 10:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Emmanuel Arias ]",
                            "  * CVE-2026-11850: Prevent read overrun in libkdb_ldap (Closes: #1139821).",
                            "",
                            "  [ Sam Hartman ]",
                            "  * Fix C23 use of strchr, Closes: #1128877",
                            "  * Remove lintian tag that ldap plugin is linked against libc6; no longer needed",
                            "  * Upstream patch for OpenSSL 4.0 compatibility, Closes: #1138466",
                            "  * Upstream commit f5bbfa4 to use openssl facilities to verify certificates; needed to avoid discarding const qualifier from Openssl 4.0 patch",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sam Hartman <hartmans@debian.org>",
                        "date": "Fri, 19 Jun 2026 08:30:16 -0600"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-40355",
                                "url": "https://ubuntu.com/security/CVE-2026-40355",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-40356",
                                "url": "https://ubuntu.com/security/CVE-2026-40356",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Non-maintainer upload.",
                            "  * Fix two NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)",
                            "    (Closes: #1135317)",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-2.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Salvatore Bonaccorso <carnil@debian.org>",
                        "date": "Sun, 10 May 2026 09:08:30 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libldap-common",
                "from_version": {
                    "source_package_name": "openldap",
                    "source_package_version": "2.6.13+dfsg-1ubuntu1",
                    "version": "2.6.13+dfsg-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "openldap",
                    "source_package_version": "2.6.13+dfsg-1ubuntu2",
                    "version": "2.6.13+dfsg-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "openldap",
                        "version": "2.6.13+dfsg-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:00:29 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libldap2:ppc64el",
                "from_version": {
                    "source_package_name": "openldap",
                    "source_package_version": "2.6.13+dfsg-1ubuntu1",
                    "version": "2.6.13+dfsg-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "openldap",
                    "source_package_version": "2.6.13+dfsg-1ubuntu2",
                    "version": "2.6.13+dfsg-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "openldap",
                        "version": "2.6.13+dfsg-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:00:29 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libmpathcmd0",
                "from_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-2ubuntu1",
                    "version": "0.14.3-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu1",
                    "version": "0.14.3-3ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153215
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153215). Remaining changes:",
                            "    - d/rules: don't build the multipath-tools binary package on i386; only kpartx.",
                            "    - d/p/enable-find-multipaths.patch: re-enable find_multipaths by",
                            "      default -- see the removed 'add_find-multipaths.patch' (LP 1463046)",
                            "    - d/NEWS: add removal of kpartx-boot package",
                            "    - d/rules: remove -Bsymbolic-functions from LDFLAGS",
                            "    - d/rules: install friendly names multipath.conf by default",
                            "    - d/initramfs/scripts/init-top: ensure the bindings file exists before",
                            "      calling multipathd -B in the initramfs. This prevents multipathd -B from",
                            "      failing and exiting immediately (LP #2120444).",
                            "    - d/p/testsuite-no-lto: disable lto to workaround testsuite symbol wrapping (LP #2135118)",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153215
                        ],
                        "author": "Jonas Jelten <jj@ubuntu.com>",
                        "date": "Sat, 01 Aug 2026 06:13:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * [55c6f80] multipath-tools-boot: add Depends: procps for pidof",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 07 May 2026 11:35:01 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libmpathpersist0",
                "from_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-2ubuntu1",
                    "version": "0.14.3-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu1",
                    "version": "0.14.3-3ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153215
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153215). Remaining changes:",
                            "    - d/rules: don't build the multipath-tools binary package on i386; only kpartx.",
                            "    - d/p/enable-find-multipaths.patch: re-enable find_multipaths by",
                            "      default -- see the removed 'add_find-multipaths.patch' (LP 1463046)",
                            "    - d/NEWS: add removal of kpartx-boot package",
                            "    - d/rules: remove -Bsymbolic-functions from LDFLAGS",
                            "    - d/rules: install friendly names multipath.conf by default",
                            "    - d/initramfs/scripts/init-top: ensure the bindings file exists before",
                            "      calling multipathd -B in the initramfs. This prevents multipathd -B from",
                            "      failing and exiting immediately (LP #2120444).",
                            "    - d/p/testsuite-no-lto: disable lto to workaround testsuite symbol wrapping (LP #2135118)",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153215
                        ],
                        "author": "Jonas Jelten <jj@ubuntu.com>",
                        "date": "Sat, 01 Aug 2026 06:13:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * [55c6f80] multipath-tools-boot: add Depends: procps for pidof",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 07 May 2026 11:35:01 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libmultipath0",
                "from_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-2ubuntu1",
                    "version": "0.14.3-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu1",
                    "version": "0.14.3-3ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153215
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153215). Remaining changes:",
                            "    - d/rules: don't build the multipath-tools binary package on i386; only kpartx.",
                            "    - d/p/enable-find-multipaths.patch: re-enable find_multipaths by",
                            "      default -- see the removed 'add_find-multipaths.patch' (LP 1463046)",
                            "    - d/NEWS: add removal of kpartx-boot package",
                            "    - d/rules: remove -Bsymbolic-functions from LDFLAGS",
                            "    - d/rules: install friendly names multipath.conf by default",
                            "    - d/initramfs/scripts/init-top: ensure the bindings file exists before",
                            "      calling multipathd -B in the initramfs. This prevents multipathd -B from",
                            "      failing and exiting immediately (LP #2120444).",
                            "    - d/p/testsuite-no-lto: disable lto to workaround testsuite symbol wrapping (LP #2135118)",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153215
                        ],
                        "author": "Jonas Jelten <jj@ubuntu.com>",
                        "date": "Sat, 01 Aug 2026 06:13:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * [55c6f80] multipath-tools-boot: add Depends: procps for pidof",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 07 May 2026 11:35:01 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libncurses6:ppc64el",
                "from_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20251231-1",
                    "version": "6.6+20251231-1"
                },
                "to_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20260608-2",
                    "version": "6.6+20260608-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Thu, 02 Jul 2026 17:00:27 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream patchlevel.",
                            "    - Add ech to screen terminfo (Closes: #707308).",
                            "  * Update symbols files.",
                            "  * Update upstream signing key.",
                            "  * Convert the watch files to version 5.",
                            "  * Update years in debian/copyright.",
                            "  * Upgrade Standards-Version to 4.7.4, no changes needed.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-1",
                        "urgency": "low",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Wed, 10 Jun 2026 17:50:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libncursesw6:ppc64el",
                "from_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20251231-1",
                    "version": "6.6+20251231-1"
                },
                "to_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20260608-2",
                    "version": "6.6+20260608-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Thu, 02 Jul 2026 17:00:27 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream patchlevel.",
                            "    - Add ech to screen terminfo (Closes: #707308).",
                            "  * Update symbols files.",
                            "  * Update upstream signing key.",
                            "  * Convert the watch files to version 5.",
                            "  * Update years in debian/copyright.",
                            "  * Upgrade Standards-Version to 4.7.4, no changes needed.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-1",
                        "urgency": "low",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Wed, 10 Jun 2026 17:50:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libnetplan1:ppc64el",
                "from_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.1-1ubuntu1",
                    "version": "1.2.1-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.2-1",
                    "version": "1.2.2-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153219,
                    2145061,
                    2147446,
                    2071747,
                    2139598,
                    2138802
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153219). Remaining changes:",
                            "    - Skip test_link_offloading to allow for a green baseline (LP 2126938)",
                            "      + d/p/lp-2126938-skip-test-link-offloading.patch",
                            "  * Dropped:",
                            "    - d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "      3.14 by handling BlockingIOError in addition to TypeError (LP 2138802)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "      execute udev rules before starting sriov apply service (LP 2139598)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "      (LP 2071747)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "      Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "      units. (LP 2145061)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "      networkd to apply dhcp labels to addresses (LP 2147446).",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "      permissions for files not managed by netplan in integration tests.",
                            "      [Included in Debian 1.2.1-1]",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153219
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Thu, 21 May 2026 16:24:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "    Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "    units. (LP: #2145061)",
                            "  * d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "    networkd to apply dhcp labels to addresses (LP: #2147446).",
                            "  * d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "    permissions for files not managed by netplan in integration tests.",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu5",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2145061,
                            2147446
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Wed, 08 Apr 2026 16:47:32 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "    (LP: #2071747)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2071747
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Fri, 20 Mar 2026 16:09:27 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "    execute udev rules before starting sriov apply service (LP: #2139598)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2139598
                        ],
                        "author": "Robert Malz <robert.malz@canonical.com>",
                        "date": "Tue, 03 Mar 2026 12:44:43 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "    3.14 by handling BlockingIOError in addition to TypeError (LP: #2138802)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2138802
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Fri, 20 Feb 2026 11:25:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip test_link_offloading to allow for a green baseline (LP: 2126938)",
                            "    - d/p/lp-2126938-skip-test-link-offloading.patch",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Lukas Märdian <slyon@ubuntu.com>",
                        "date": "Tue, 13 Jan 2026 17:58:24 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "libnghttp2-14:ppc64el",
                "from_version": {
                    "source_package_name": "nghttp2",
                    "source_package_version": "1.69.0-1",
                    "version": "1.69.0-1"
                },
                "to_version": {
                    "source_package_name": "nghttp2",
                    "source_package_version": "1.69.0-1ubuntu2",
                    "version": "1.69.0-1ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-58055",
                        "url": "https://ubuntu.com/security/CVE-2026-58055",
                        "cve_description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-28 02:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "nghttp2",
                        "version": "1.69.0-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:59:54 +0000"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58055",
                                "url": "https://ubuntu.com/security/CVE-2026-58055",
                                "cve_description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-28 02:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: HTTP request/response smuggling issue",
                            "    - debian/patches/CVE-2026-58055.patch: nghttpx: Tighten up CONNECT and HTTP",
                            "      Upgrade handling in src/shrpx_downstream.cc, src/shrpx_downstream.h,",
                            "      src/shrpx_http2_upstream.cc, src/shrpx_http3_upstream.cc,",
                            "      src/shrpx_http_downstream_connection.cc,",
                            "      src/shrpx_http_downstream_connection.h, src/shrpx_https_upstream.cc.",
                            "    - CVE-2026-58055",
                            ""
                        ],
                        "package": "nghttp2",
                        "version": "1.69.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Tue, 30 Jun 2026 12:28:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libnss-systemd:ppc64el",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libnss3:ppc64el",
                "from_version": {
                    "source_package_name": "nss",
                    "source_package_version": "2:3.126-1",
                    "version": "2:3.126-1"
                },
                "to_version": {
                    "source_package_name": "nss",
                    "source_package_version": "2:3.127-1",
                    "version": "2:3.127-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "nss",
                        "version": "2:3.127-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mike Hommey <glandium@debian.org>",
                        "date": "Wed, 19 Aug 2026 10:55:55 +0900"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libnvme1t64:ppc64el",
                "from_version": {
                    "source_package_name": "libnvme",
                    "source_package_version": "1.16.2-1",
                    "version": "1.16.2-1"
                },
                "to_version": {
                    "source_package_name": "libnvme",
                    "source_package_version": "1.16.2-1build1",
                    "version": "1.16.2-1build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "libnvme",
                        "version": "1.16.2-1build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 14:50:46 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libopeniscsiusr",
                "from_version": {
                    "source_package_name": "open-iscsi",
                    "source_package_version": "2.1.11-5ubuntu1",
                    "version": "2.1.11-5ubuntu1"
                },
                "to_version": {
                    "source_package_name": "open-iscsi",
                    "source_package_version": "2.1.11-5ubuntu4",
                    "version": "2.1.11-5ubuntu4"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2157328,
                    2147499
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "open-iscsi",
                        "version": "2.1.11-5ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 11:03:00 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Recommend busybox or busybox-static on Ubuntu as well (LP: #2157328)",
                            ""
                        ],
                        "package": "open-iscsi",
                        "version": "2.1.11-5ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2157328
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Fri, 17 Jul 2026 12:29:19 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/extra/initramfs/local-top/iscsi: normalize static bootproto for",
                            "    initramfs netplan conversion. In iscsi_auto flow, firmware reports",
                            "    bootproto as STATIC, but netinfo_to_netplan handles static IPv4",
                            "    through PROTO=none with address fields. Map STATIC to PROTO=none",
                            "    and record IPV4PROTO=static in net-*.conf. (LP: #2147499)",
                            ""
                        ],
                        "package": "open-iscsi",
                        "version": "2.1.11-5ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2147499
                        ],
                        "author": "Zhang Hua <joshua.zhang@canonical.com>",
                        "date": "Thu, 11 Jun 2026 18:33:04 +0800"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libp11-kit0:ppc64el",
                "from_version": {
                    "source_package_name": "p11-kit",
                    "source_package_version": "0.26.4-1",
                    "version": "0.26.4-1"
                },
                "to_version": {
                    "source_package_name": "p11-kit",
                    "source_package_version": "0.26.5-1",
                    "version": "0.26.5-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-18938",
                        "url": "https://ubuntu.com/security/CVE-2026-18938",
                        "cve_description": "A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-07 09:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-18938",
                                "url": "https://ubuntu.com/security/CVE-2026-18938",
                                "cve_description": "A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-07 09:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "    + rpc: guard against overflow when decoding nested attributes",
                            "      (CVE-2026-18938) Closes: #1144476",
                            ""
                        ],
                        "package": "p11-kit",
                        "version": "0.26.5-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Sat, 15 Aug 2026 17:51:12 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpam-systemd:ppc64el",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpcap0.8t64:ppc64el",
                "from_version": {
                    "source_package_name": "libpcap",
                    "source_package_version": "1.10.6-1ubuntu1",
                    "version": "1.10.6-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "libpcap",
                    "source_package_version": "1.10.6-2ubuntu1",
                    "version": "1.10.6-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable. Remaining changes:",
                            "    - Add Build-Depends on libibverbs-dev to enable RDMA support.",
                            "      LP #2006557.",
                            "    - Have -dev package depend on libibverbs-dev per pkgconfig",
                            "    - Don't require libverbs on i386",
                            ""
                        ],
                        "package": "libpcap",
                        "version": "1.10.6-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Gianfranco Costamagna <locutusofborg@debian.org>",
                        "date": "Wed, 15 Jul 2026 15:19:53 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "",
                            "  [ Debian Janitor ]",
                            "  * Move transitional package libpcap-dev to oldlibs/optional per policy 4.0.1.",
                            "",
                            "  [ Sven Geuer ]",
                            "  * d/p/hurd.diff: Fix FTBFS on hurd-*.",
                            "    Thanks to Samuel Thibault for the updated patch (Closes: #1141047).",
                            "  * d/p/: Add patch fixing lintian warning 'groff-message'.",
                            "  * d/control:",
                            "    - Bump Standards-Version.",
                            "    - Bump debhelper-compat to 14.",
                            "  * d/gbp.conf: Introduce gbp configuration file",
                            "  * d/salsa-ci.yml: Add variable SALSA_CI_DISABLE_BUILD_PACKAGE_ALL.",
                            "  * d/copyright: Update packaging copyright holders.",
                            ""
                        ],
                        "package": "libpcap",
                        "version": "1.10.6-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Geuer <sge@debian.org>",
                        "date": "Tue, 14 Jul 2026 16:11:07 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libplymouth5:ppc64el",
                "from_version": {
                    "source_package_name": "plymouth",
                    "source_package_version": "24.004.60+git20250831.4a3c171d-0ubuntu9",
                    "version": "24.004.60+git20250831.4a3c171d-0ubuntu9"
                },
                "to_version": {
                    "source_package_name": "plymouth",
                    "source_package_version": "24.004.60+git20250831.4a3c171d-0ubuntu10",
                    "version": "24.004.60+git20250831.4a3c171d-0ubuntu10"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2144770-Fix-reload-when-happening-early.patch: Correct DEP-3 tags.",
                            "    This patch was forwarded upstream, it did not come from upstream.",
                            "  * d/local, d/source/include-binaries: Revert spinner theme.",
                            "    The spinner shipped in 26.04 was targeted to celebrate 26.04 only.",
                            ""
                        ],
                        "package": "plymouth",
                        "version": "24.004.60+git20250831.4a3c171d-0ubuntu10",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Mon, 07 Sep 2026 13:43:02 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpsl5t64:ppc64el",
                "from_version": {
                    "source_package_name": "libpsl",
                    "source_package_version": "0.23.1-1",
                    "version": "0.23.1-1"
                },
                "to_version": {
                    "source_package_name": "libpsl",
                    "source_package_version": "0.23.3-1",
                    "version": "0.23.3-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 0.23.3",
                            ""
                        ],
                        "package": "libpsl",
                        "version": "0.23.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Florian Ernst <florian@debian.org>",
                        "date": "Mon, 17 Aug 2026 15:23:22 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 0.23.2",
                            ""
                        ],
                        "package": "libpsl",
                        "version": "0.23.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Florian Ernst <florian@debian.org>",
                        "date": "Tue, 11 Aug 2026 19:42:40 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsasl2-2:ppc64el",
                "from_version": {
                    "source_package_name": "cyrus-sasl2",
                    "source_package_version": "2.1.28+dfsg1-9ubuntu4",
                    "version": "2.1.28+dfsg1-9ubuntu4"
                },
                "to_version": {
                    "source_package_name": "cyrus-sasl2",
                    "source_package_version": "2.1.28+dfsg1-11ubuntu2",
                    "version": "2.1.28+dfsg1-11ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153186
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:30 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153186). Remaining changes:",
                            "    - Disable postgresql support in the libsasl2-modules-sql on i386 since",
                            "      postgresql is no longer build for that architecture (LP #2142320):",
                            "      + d/control: don't build-depend on libpq-dev on i386",
                            "      + d/rules: only enable pgsql if not on i386",
                            "    - d/t/saslauthd: refactor how tests are run, and run them a second time",
                            "      with a new socket path (LP #2098601)",
                            "  * Added:",
                            "    - d/sasl2-bin.saslauthd.service: simpler way to have saslauthd honor the",
                            "      settings from /etc/default/saslauthd (part of LP #2098601 adapted to the",
                            "      new debian upload)",
                            "  * Dropped:",
                            "    - d/sasl2-bin.saslauthd.service: drop hardcoded PIDFile",
                            "      [In 2.1.28+dfsg1-11]",
                            "    - d/rules: add -std=gnu17 to build it with gcc-15 on questing",
                            "      (LP #2124256)",
                            "      [Code fix in 2.1.28+dfsg1-10]",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153186
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 01 Jul 2026 09:58:30 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "",
                            "  [ Praveen Arimbrathodiyil ]",
                            "  * Update file sasl2-bin.saslauthd.service",
                            "",
                            "  [ Peter Wienemann ]",
                            "  * d/rules: Build and install saslcache (Closes: #1132010)",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Germann <bage@debian.org>",
                        "date": "Sat, 04 Apr 2026 21:56:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "  * d/copyright: Remove superfluous asterisks",
                            "  * Add compatibility for gcc 15 (Closes: #1096495)",
                            "",
                            "  [ Helmut Grohne ]",
                            "  * Fix FTCBFS: Annotate python3-sphinx dependency :native (Closes: #1101329)",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-10",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Germann <bage@debian.org>",
                        "date": "Mon, 06 Oct 2025 22:34:22 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsasl2-modules:ppc64el",
                "from_version": {
                    "source_package_name": "cyrus-sasl2",
                    "source_package_version": "2.1.28+dfsg1-9ubuntu4",
                    "version": "2.1.28+dfsg1-9ubuntu4"
                },
                "to_version": {
                    "source_package_name": "cyrus-sasl2",
                    "source_package_version": "2.1.28+dfsg1-11ubuntu2",
                    "version": "2.1.28+dfsg1-11ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153186
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:30 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153186). Remaining changes:",
                            "    - Disable postgresql support in the libsasl2-modules-sql on i386 since",
                            "      postgresql is no longer build for that architecture (LP #2142320):",
                            "      + d/control: don't build-depend on libpq-dev on i386",
                            "      + d/rules: only enable pgsql if not on i386",
                            "    - d/t/saslauthd: refactor how tests are run, and run them a second time",
                            "      with a new socket path (LP #2098601)",
                            "  * Added:",
                            "    - d/sasl2-bin.saslauthd.service: simpler way to have saslauthd honor the",
                            "      settings from /etc/default/saslauthd (part of LP #2098601 adapted to the",
                            "      new debian upload)",
                            "  * Dropped:",
                            "    - d/sasl2-bin.saslauthd.service: drop hardcoded PIDFile",
                            "      [In 2.1.28+dfsg1-11]",
                            "    - d/rules: add -std=gnu17 to build it with gcc-15 on questing",
                            "      (LP #2124256)",
                            "      [Code fix in 2.1.28+dfsg1-10]",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153186
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 01 Jul 2026 09:58:30 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "",
                            "  [ Praveen Arimbrathodiyil ]",
                            "  * Update file sasl2-bin.saslauthd.service",
                            "",
                            "  [ Peter Wienemann ]",
                            "  * d/rules: Build and install saslcache (Closes: #1132010)",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Germann <bage@debian.org>",
                        "date": "Sat, 04 Apr 2026 21:56:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "  * d/copyright: Remove superfluous asterisks",
                            "  * Add compatibility for gcc 15 (Closes: #1096495)",
                            "",
                            "  [ Helmut Grohne ]",
                            "  * Fix FTCBFS: Annotate python3-sphinx dependency :native (Closes: #1101329)",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-10",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Germann <bage@debian.org>",
                        "date": "Mon, 06 Oct 2025 22:34:22 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsasl2-modules-db:ppc64el",
                "from_version": {
                    "source_package_name": "cyrus-sasl2",
                    "source_package_version": "2.1.28+dfsg1-9ubuntu4",
                    "version": "2.1.28+dfsg1-9ubuntu4"
                },
                "to_version": {
                    "source_package_name": "cyrus-sasl2",
                    "source_package_version": "2.1.28+dfsg1-11ubuntu2",
                    "version": "2.1.28+dfsg1-11ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153186
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:30 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153186). Remaining changes:",
                            "    - Disable postgresql support in the libsasl2-modules-sql on i386 since",
                            "      postgresql is no longer build for that architecture (LP #2142320):",
                            "      + d/control: don't build-depend on libpq-dev on i386",
                            "      + d/rules: only enable pgsql if not on i386",
                            "    - d/t/saslauthd: refactor how tests are run, and run them a second time",
                            "      with a new socket path (LP #2098601)",
                            "  * Added:",
                            "    - d/sasl2-bin.saslauthd.service: simpler way to have saslauthd honor the",
                            "      settings from /etc/default/saslauthd (part of LP #2098601 adapted to the",
                            "      new debian upload)",
                            "  * Dropped:",
                            "    - d/sasl2-bin.saslauthd.service: drop hardcoded PIDFile",
                            "      [In 2.1.28+dfsg1-11]",
                            "    - d/rules: add -std=gnu17 to build it with gcc-15 on questing",
                            "      (LP #2124256)",
                            "      [Code fix in 2.1.28+dfsg1-10]",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153186
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 01 Jul 2026 09:58:30 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "",
                            "  [ Praveen Arimbrathodiyil ]",
                            "  * Update file sasl2-bin.saslauthd.service",
                            "",
                            "  [ Peter Wienemann ]",
                            "  * d/rules: Build and install saslcache (Closes: #1132010)",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Germann <bage@debian.org>",
                        "date": "Sat, 04 Apr 2026 21:56:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "  * d/copyright: Remove superfluous asterisks",
                            "  * Add compatibility for gcc 15 (Closes: #1096495)",
                            "",
                            "  [ Helmut Grohne ]",
                            "  * Fix FTCBFS: Annotate python3-sphinx dependency :native (Closes: #1101329)",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-10",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Germann <bage@debian.org>",
                        "date": "Mon, 06 Oct 2025 22:34:22 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libselinux1:ppc64el",
                "from_version": {
                    "source_package_name": "libselinux",
                    "source_package_version": "3.10-1",
                    "version": "3.10-1"
                },
                "to_version": {
                    "source_package_name": "libselinux",
                    "source_package_version": "3.11-2",
                    "version": "3.11-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move tmpfiles.d from libselinux1 to selinux-utils (Closes: #1140305)",
                            "",
                            "  [ Christian Göttsche ]",
                            "  * d/patches: add patches to please non-release architectures",
                            ""
                        ],
                        "package": "libselinux",
                        "version": "3.11-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Christian Göttsche <cgzones@googlemail.com>",
                        "date": "Sat, 11 Jul 2026 11:58:50 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 3.11",
                            "",
                            "  * d/patches: rebase and drop upstream applied patches",
                            "  * d/control:",
                            "    - bump Standards-Version to 4.7.4 (no further changes)",
                            "    - update homepage",
                            "    - bump libsepol build-dep version",
                            "    - bump to debhelper compat level 14",
                            "    - add python3-build as build-dep",
                            "    - add Replaces to libselinux-dev to ease transition",
                            "  * d/tests/control: switch to modern pkgconf dependency",
                            "  * d/selinux_compile_fcontexts: misc tweaks",
                            "  * d/rules: fix build during python transition",
                            ""
                        ],
                        "package": "libselinux",
                        "version": "3.11-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Christian Göttsche <cgzones@googlemail.com>",
                        "date": "Tue, 07 Jul 2026 21:03:26 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsemanage-common",
                "from_version": {
                    "source_package_name": "libsemanage",
                    "source_package_version": "3.10-1",
                    "version": "3.10-1"
                },
                "to_version": {
                    "source_package_name": "libsemanage",
                    "source_package_version": "3.11-1",
                    "version": "3.11-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Christian Göttsche ]",
                            "  * New upstream version 3.11",
                            "",
                            "  * d/patches: rebase",
                            "  * d/gitlab-ci.yml: drop obsolete build-twice job",
                            "  * d/control:",
                            "    - update homepage",
                            "    - bump Standards-Version to 4.7.4 (no further changes)",
                            "    - drop fields Priority and R^3 with default values",
                            "    - bump SELinux userland build-dep versions",
                            "    - bump to debhelper compat 14",
                            "    - add libaudit-dev to libsemanage-dev build-deps",
                            "    - drop unused substitution variables",
                            "  * d/clean: drop obsolete entries",
                            "",
                            "  [ Russell Coker ]",
                            "  * Uploading Christian's git committed code because it works well, is better",
                            "    than what's currently in Debian, and allows new versions of other",
                            "    packages to get into Debian.",
                            ""
                        ],
                        "package": "libsemanage",
                        "version": "3.11-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Russell Coker <russell@coker.com.au>",
                        "date": "Sat, 11 Jul 2026 11:45:36 +1000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsemanage2:ppc64el",
                "from_version": {
                    "source_package_name": "libsemanage",
                    "source_package_version": "3.10-1",
                    "version": "3.10-1"
                },
                "to_version": {
                    "source_package_name": "libsemanage",
                    "source_package_version": "3.11-1",
                    "version": "3.11-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Christian Göttsche ]",
                            "  * New upstream version 3.11",
                            "",
                            "  * d/patches: rebase",
                            "  * d/gitlab-ci.yml: drop obsolete build-twice job",
                            "  * d/control:",
                            "    - update homepage",
                            "    - bump Standards-Version to 4.7.4 (no further changes)",
                            "    - drop fields Priority and R^3 with default values",
                            "    - bump SELinux userland build-dep versions",
                            "    - bump to debhelper compat 14",
                            "    - add libaudit-dev to libsemanage-dev build-deps",
                            "    - drop unused substitution variables",
                            "  * d/clean: drop obsolete entries",
                            "",
                            "  [ Russell Coker ]",
                            "  * Uploading Christian's git committed code because it works well, is better",
                            "    than what's currently in Debian, and allows new versions of other",
                            "    packages to get into Debian.",
                            ""
                        ],
                        "package": "libsemanage",
                        "version": "3.11-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Russell Coker <russell@coker.com.au>",
                        "date": "Sat, 11 Jul 2026 11:45:36 +1000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsqlite3-0:ppc64el",
                "from_version": {
                    "source_package_name": "sqlite3",
                    "source_package_version": "3.46.1-9",
                    "version": "3.46.1-9"
                },
                "to_version": {
                    "source_package_name": "sqlite3",
                    "source_package_version": "3.53.4-2",
                    "version": "3.53.4-2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-50813",
                        "url": "https://ubuntu.com/security/CVE-2026-50813",
                        "cve_description": "An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11822",
                        "url": "https://ubuntu.com/security/CVE-2026-11822",
                        "cve_description": "SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 20:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11824",
                        "url": "https://ubuntu.com/security/CVE-2026-11824",
                        "cve_description": "SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 20:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-50813",
                                "url": "https://ubuntu.com/security/CVE-2026-50813",
                                "cve_description": "An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport upstream security fix for CVE-2026-50813: buffer overread in the",
                            "    session module.",
                            ""
                        ],
                        "package": "sqlite3",
                        "version": "3.53.4-2",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sat, 01 Aug 2026 12:03:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "sqlite3",
                        "version": "3.53.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sun, 26 Jul 2026 17:45:11 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Helmut Grohne <helmut@subdivi.de> ]",
                            "  * Fix FTCBFS (closes: #1140712):",
                            "    + The new TCL-based configure requires option values to be separated with",
                            "      equal signs.",
                            "    + Build a host architecture lemon.",
                            "    + Use a host architecture pkg-config for a host compilation step.",
                            "",
                            "  [ Laszlo Boszormenyi (GCS) ]",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "sqlite3",
                        "version": "3.53.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sat, 27 Jun 2026 11:28:50 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11822",
                                "url": "https://ubuntu.com/security/CVE-2026-11822",
                                "cve_description": "SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 20:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11824",
                                "url": "https://ubuntu.com/security/CVE-2026-11824",
                                "cve_description": "SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 20:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1139960):",
                            "    - fixes CVE-2026-11822: memory corruption vulnerabilities in the FTS5",
                            "      full-text search extension,",
                            "    - fixes CVE-2026-11824: heap-based buffer overflow vulnerability in the",
                            "      FTS5 full-text search extension.",
                            "  * Remove sqlite3JsonTableFunctions@Base, sqlite3TriggerStepSrc@Base and",
                            "    sqlite3VdbeCheckFk@Base symbols as no longer part of the library.",
                            "  * Update symbols file.",
                            "  * Update watch file.",
                            ""
                        ],
                        "package": "sqlite3",
                        "version": "3.53.2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sat, 13 Jun 2026 21:08:12 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libssh2-1t64:ppc64el",
                "from_version": {
                    "source_package_name": "libssh2",
                    "source_package_version": "1.11.1-4ubuntu1",
                    "version": "1.11.1-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "libssh2",
                    "source_package_version": "1.11.1-4ubuntu3",
                    "version": "1.11.1-4ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-66032",
                        "url": "https://ubuntu.com/security/CVE-2026-66032",
                        "cve_description": "libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-24 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-66033",
                        "url": "https://ubuntu.com/security/CVE-2026-66033",
                        "cve_description": "libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-24 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-66035",
                        "url": "https://ubuntu.com/security/CVE-2026-66035",
                        "cve_description": "libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-24 17:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-66032",
                                "url": "https://ubuntu.com/security/CVE-2026-66032",
                                "cve_description": "libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-24 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-66033",
                                "url": "https://ubuntu.com/security/CVE-2026-66033",
                                "cve_description": "libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-24 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-66035",
                                "url": "https://ubuntu.com/security/CVE-2026-66035",
                                "cve_description": "libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-24 17:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: double-free vulnerability in sftp_open()",
                            "    - debian/patches/CVE-2026-66032.patch: Prevent dangling pointer by",
                            "      nullifying data in src/sftp.c.",
                            "    - CVE-2026-66032",
                            "  * SECURITY UPDATE: pre-authentication integer underflow vulnerability",
                            "    - debian/patches/CVE-2026-66033.patch: fix potential OOB read/write with",
                            "      AES-GCM in `ssh2_cipher_crypt()` in src/openssl.c.",
                            "    - CVE-2026-66033",
                            "  * SECURITY UPDATE: pre-authentication heap buffer overflow vulnerability",
                            "    - debian/patches/CVE-2026-66035.patch: transport: fix potential heap",
                            "      overflow on ETM decrypt in src/transport.c.",
                            "    - CVE-2026-66035",
                            ""
                        ],
                        "package": "libssh2",
                        "version": "1.11.1-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Wed, 02 Sep 2026 07:45:31 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "libssh2",
                        "version": "1.11.1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:50:24 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libstdc++6:ppc64el",
                "from_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.1.0-2ubuntu1",
                    "version": "16.1.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-1ubuntu1",
                    "version": "16.2.0-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158577
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 09 Aug 2026 06:21:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * GCC 16.2.0 release.",
                            "    - Fix PR target/126581 (x86), PR tree-optimization/126504,",
                            "      PR tree-optimization/126503, PR middle-end/126497,",
                            "      PR tree-optimization/126490, PR tree-optimization/126464,",
                            "      PR tree-optimization/126476, PR tree-optimization/126464,",
                            "      PR middle-end/126084, PR tree-optimization/126471, PR target/126446,",
                            "      PR middle-end/126410, PR tree-optimization/126457,",
                            "      PR tree-optimization/126404, PR tree-optimization/126404,",
                            "      PR target/126438 (PPC), PR target/126450 (x86), PR middle-end/126447,",
                            "      PR middle-end/126405, PR rtl-optimization/126184,",
                            "      PR rtl-optimization/126184, PR target/126429 (x86),",
                            "      PR tree-optimization/125396, PR tree-optimization/125290,",
                            "      PR target/126320 (x86), PR middle-end/126341, PR target/123625 (AArch64),",
                            "      PR target/121957 (AArch64), PR rtl-optimization/125209,",
                            "      PR middle-end/124637, PR tree-optimization/126171,",
                            "      PR tree-optimization/126225, PR tree-optimization/124663, PR ipa/125207,",
                            "      PR target/119210 (AArch64), PR target/105116, PR driver/1240,",
                            "      PR ada/126553, PR ada/126379, PR ada/126482, PR algol68/126330,",
                            "      PR c++/126309, PR c++/126508, PR c++/126420, PR c++/126423,",
                            "      PR c++/126343, PR c++/126406, PR c++/119343, PR c++/126209,",
                            "      PR c++/126310, PR c++/126280, PR c++/126215, PR driver/124058,",
                            "      PR fortran/125866, PR fortran/126386, PR fortran/126303,",
                            "      PR fortran/97592, PR fortran/125998, PR sanitizer/126307,",
                            "      PR libstdc++/122197, PR libstdc++/124854, PR libstdc++/116110,",
                            "      PR libstdc++/124853, PR libstdc++/116110, PR libstdc++/124852,",
                            "      PR libstdc++/124852, PR libstdc++/124851, PR libstdc++/123165.",
                            "  * Update to git 20260809 from the gcc-16 branch.",
                            "    - Fix PR target/126484 (MIPS), PR tree-optimization/126576,",
                            "      PR tree-optimization/126547, PR tree-optimization/126549,",
                            "      PR tree-optimization/126564, PR tree-optimization/126601,",
                            "      PR target/124948, PR tree-optimization/126464, PR preprocessor/125048,",
                            "      PR libstdc++/125200, PR c++/125591, PR c++/125601, PR c++/125680,",
                            "      PR c++/125541, PR fortran/126205, PR target/126667 (S390),",
                            "      PR fortran/125263.",
                            "",
                            "  [ Matthias Klose ]",
                            "  * Update libgcc-s, libcc1, libasan and libgcobol symbols files.",
                            "  * d/rules2: Use rva23u64 with zifencei extension for Ubuntu (Vladimir Petko).",
                            "    LP: #2158577.",
                            "  * d/rules: Reformat riscv64 extensions for Debian.",
                            "  * Configure with --enable-checking=release on every architecture.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * d/rules2: Use rva20u64 with zifencei extension for Debian.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2158577
                        ],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 09 Aug 2026 06:10:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 19 Jul 2026 14:16:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260719 from the gcc-16 branch.",
                            "    - Fix PR tree-optimization/126262, PR tree-optimization/126257,",
                            "      PR middle-end/126084, PR tree-optimization/120201,",
                            "      PR tree-optimization/126194, PR tree-optimization/126150,",
                            "      PR tree-optimization/125953, PR middle-end/125875,",
                            "      PR tree-optimization/125786, PR tree-optimization/125668,",
                            "      PR tree-optimization/125296, PR tree-optimization/126008,",
                            "      PR tree-optimization/125730, PR tree-optimization/125040,",
                            "      PR ipa/125121, PR ipa/124128, PR target/126054 (S390),",
                            "      PR target/126148 (x86), PR tree-optimization/125597,",
                            "      PR tree-optimization/125597, PR tree-optimization/125597,",
                            "      PR target/126081 (or1k), PR target/126049 (RISCV),",
                            "      PR target/126098 (x86), PR target/67459 (SH), PR target/122948 (SH),",
                            "      PR target/125972 (S390), PR rtl-optimization/125173,",
                            "      PR target/124908 (AArch64), PR target/125838 (AArch64),",
                            "      PR target/125883 (x86), PR target/125818 (AArch64),",
                            "      PR target/125469 (x86), PR target/125469 (x86), PR target/125949 (x86),",
                            "      PR target/125992 (S390), PR middle-end/125977, PR target/125628 (MIPS),",
                            "      PR target/125478 (RISCV), PR target/106895 (PPC), PR target/122665 (PPC),",
                            "      PR target/125670 (RISCV), PR middle-end/125621,",
                            "      PR target/125148 (AArch64), PR tree-optimization/125431,",
                            "      PR target/125795 (AArch64), PR tree-optimization/125501,",
                            "      PR tree-optimization/125776, PR tree-optimization/125774,",
                            "      PR target/120144 (MIPS), PR ipa/125699, PR tree-optimization/125419,",
                            "      PR tree-optimization/125652, PR tree-optimization/125686,",
                            "      PR tree-optimization/125646, PR tree-optimization/125553,",
                            "      PR tree-optimization/125545, PR tree-optimization/125502,",
                            "      PR tree-optimization/125477, PR target/124948, PR c/125072, PR c/125935,",
                            "      PR c/125604, PR c/123569, PR c/125252, PR c/124303, PR c/124985,",
                            "      PR c++/126057, PR c++/126036, PR c++/126007, PR c++/125674, PR c++/91155,",
                            "      PR c++/126066, PR c++/125901, PR c++/126031, PR c++/121552, PR c++/124584,",
                            "      PR c++/121094, PR c++/117259, PR c++/123536, PR c++/125900, PR c++/125334,",
                            "      PR c++/125768, PR c++/125939, PR c++/125745, PR c++/125408, PR c++/124978,",
                            "      PR c++/115314, PR c++/125889, PR c++/125764, PR c++/125759, PR c++/65271,",
                            "      PR c++/125770, PR fortran/126234, PR fortran/125172, PR fortran/126210,",
                            "      PR fortran/126170, PR fortran/126127, PR fortran/103367,",
                            "      PR fortran/126018, PR fortran/125051, PR fortran/125902,",
                            "      PR fortran/125902, PR fortran/60576, PR fortran/125430,",
                            "      PR fortran/125527, PR fortran/125535, PR fortran/125650,",
                            "      PR fortran/125481, PR fortran/125527, PR fortran/125528,",
                            "      PR fortran/125529, PR fortran/125530, PR fortran/125531,",
                            "      PR fortran/125534, PR fortran/125535, PR lto/125257, PR libgcc/123976,",
                            "      PR target/125752 (AVR), PR libfortran/126116, PR libstdc++/126111,",
                            "      PR libstdc++/125956, PR libstdc++/118158, PR libstdc++/125228,",
                            "      PR libstdc++/125890.",
                            "  * Let the ada build fail on an alihash mismatch, if fail_on_alihash_mismatch",
                            "    is enabled.",
                            "  * Enable Modula-2 on powerpc and ppc64. Closes: #1141560, #1141596.",
                            "  * Enable LRA by default on m68k for snapshot builds (Adrian Glaubitz).",
                            "    Addresses: #1142039.",
                            "  * Disable running tests on Debian/riscv64 for meaningful build times.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 19 Jul 2026 13:28:39 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsystemd-shared:ppc64el",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsystemd0:ppc64el",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libtinfo6:ppc64el",
                "from_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20251231-1",
                    "version": "6.6+20251231-1"
                },
                "to_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20260608-2",
                    "version": "6.6+20260608-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Thu, 02 Jul 2026 17:00:27 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream patchlevel.",
                            "    - Add ech to screen terminfo (Closes: #707308).",
                            "  * Update symbols files.",
                            "  * Update upstream signing key.",
                            "  * Convert the watch files to version 5.",
                            "  * Update years in debian/copyright.",
                            "  * Upgrade Standards-Version to 4.7.4, no changes needed.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-1",
                        "urgency": "low",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Wed, 10 Jun 2026 17:50:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libudev1:ppc64el",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libudisks2-0:ppc64el",
                "from_version": {
                    "source_package_name": "udisks2",
                    "source_package_version": "2.11.1-2ubuntu1",
                    "version": "2.11.1-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "udisks2",
                    "source_package_version": "2.11.2-1ubuntu1",
                    "version": "2.11.2-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-7867",
                        "url": "https://ubuntu.com/security/CVE-2026-7867",
                        "cve_description": "A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-06 22:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable. Remaining changes:",
                            "  * d/p/nvme-disk-size.patch:",
                            "    - use upstream candidate fix for getting the size of nvme drives",
                            "      note: the upstream patch was merged as PR 1457 with different content.",
                            "      It should be syncable when 2.11.90 branch is released",
                            ""
                        ],
                        "package": "udisks2",
                        "version": "2.11.2-1ubuntu1",
                        "urgency": "low",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Gianfranco Costamagna <locutusofborg@debian.org>",
                        "date": "Mon, 24 Aug 2026 09:50:19 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-7867",
                                "url": "https://ubuntu.com/security/CVE-2026-7867",
                                "cve_description": "A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-06 22:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream version 2.11.2.",
                            "    - Fixes local privilege escalation via 'as-user' mount spoofing",
                            "      (CVE-2026-7867)",
                            ""
                        ],
                        "package": "udisks2",
                        "version": "2.11.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alberto Garcia <berto@igalia.com>",
                        "date": "Thu, 06 Aug 2026 17:41:56 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-base",
                "from_version": {
                    "source_package_name": "linux-base",
                    "source_package_version": "4.15ubuntu5",
                    "version": "4.15ubuntu5"
                },
                "to_version": {
                    "source_package_name": "linux-base",
                    "source_package_version": "4.16ubuntu1",
                    "version": "4.16ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1877088,
                    1929255,
                    1928700,
                    1867820,
                    1881338,
                    1932582,
                    2018128,
                    2098735,
                    21465330
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from debian unstable. Remaining changes:",
                            "    - Default to link_in_boot by default, on all architectures.",
                            "    - Add kernel postinst hook to update initrd softlinks to match the kernel",
                            "      version targets (LP: #1877088, #1929255).",
                            "    - Check for update-initramfs being installed before running the postinst",
                            "      hook which updates the softlinks (LP: #1928700).",
                            "    - Add linux-base-sgx package with SGX udev rules (LP: #1867820, #1881338,",
                            "      #1932582).",
                            "    - Add Apport package hook and links for kernel packages (LP: #2018128,",
                            "      #2098735, #21465330).",
                            "    - Change package maintainer to Ubuntu Kernel Team.",
                            ""
                        ],
                        "package": "linux-base",
                        "version": "4.16ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1877088,
                            1929255,
                            1928700,
                            1867820,
                            1881338,
                            1932582,
                            2018128,
                            2098735,
                            21465330
                        ],
                        "author": "Juerg Haefliger <juerg.haefliger@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:44:02 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Simplify install file.",
                            "  * Add hooks to copy vmlinuz file to /boot.",
                            ""
                        ],
                        "package": "linux-base",
                        "version": "4.16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Blank <waldi@debian.org>",
                        "date": "Sun, 16 Aug 2026 14:33:17 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-headers-generic",
                "from_version": {
                    "source_package_name": "linux-meta",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": "linux-meta",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1786013,
                    1786013,
                    1786013,
                    1786013
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-5.5",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 22:11:09 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry; drop unstable suffix",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ubuntu Kernel Team <kernel-team@lists.ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 22:10:08 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-4.4",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:50:12 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-3.3",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Packaging] Add IBM transitional packages",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Thu, 13 Aug 2026 21:42:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-2.2",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:30:30 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-1.1",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:08:22 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-0.0+1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:26 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry: rename to linux-meta-unstable and bump to 7.2.0",
                            "    (major-version bootstrap for the unstable family)",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 13:14:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-5.5",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:39:50 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-4.4",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Sat, 06 Jun 2026 14:34:18 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-3.3",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Wed, 03 Jun 2026 20:13:31 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-2.2",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Wed, 03 Jun 2026 16:03:47 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-1.1",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:19:19 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:10:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.0.0-15.15",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:05:08 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-headers-virtual",
                "from_version": {
                    "source_package_name": "linux-meta",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": "linux-meta",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1786013,
                    1786013,
                    1786013,
                    1786013
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-5.5",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 22:11:09 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry; drop unstable suffix",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ubuntu Kernel Team <kernel-team@lists.ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 22:10:08 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-4.4",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:50:12 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-3.3",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Packaging] Add IBM transitional packages",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Thu, 13 Aug 2026 21:42:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-2.2",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:30:30 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-1.1",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:08:22 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-0.0+1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:26 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry: rename to linux-meta-unstable and bump to 7.2.0",
                            "    (major-version bootstrap for the unstable family)",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 13:14:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-5.5",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:39:50 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-4.4",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Sat, 06 Jun 2026 14:34:18 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-3.3",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Wed, 03 Jun 2026 20:13:31 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-2.2",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Wed, 03 Jun 2026 16:03:47 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-1.1",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:19:19 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:10:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.0.0-15.15",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:05:08 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-image-virtual",
                "from_version": {
                    "source_package_name": "linux-meta",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": "linux-meta",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1786013,
                    1786013,
                    1786013,
                    1786013
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-5.5",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 22:11:09 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry; drop unstable suffix",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ubuntu Kernel Team <kernel-team@lists.ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 22:10:08 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-4.4",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:50:12 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-3.3",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Packaging] Add IBM transitional packages",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Thu, 13 Aug 2026 21:42:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-2.2",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:30:30 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-1.1",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:08:22 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-0.0+1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:26 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry: rename to linux-meta-unstable and bump to 7.2.0",
                            "    (major-version bootstrap for the unstable family)",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 13:14:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-5.5",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:39:50 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-4.4",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Sat, 06 Jun 2026 14:34:18 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-3.3",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Wed, 03 Jun 2026 20:13:31 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-2.2",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Wed, 03 Jun 2026 16:03:47 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-1.1",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:19:19 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:10:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.0.0-15.15",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:05:08 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-libc-dev:ppc64el",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-47337",
                        "url": "https://ubuntu.com/security/CVE-2026-47337",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47334",
                        "url": "https://ubuntu.com/security/CVE-2026-47334",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47333",
                        "url": "https://ubuntu.com/security/CVE-2026-47333",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47332",
                        "url": "https://ubuntu.com/security/CVE-2026-47332",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47330",
                        "url": "https://ubuntu.com/security/CVE-2026-47330",
                        "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47329",
                        "url": "https://ubuntu.com/security/CVE-2026-47329",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47327",
                        "url": "https://ubuntu.com/security/CVE-2026-47327",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47328",
                        "url": "https://ubuntu.com/security/CVE-2026-47328",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47326",
                        "url": "https://ubuntu.com/security/CVE-2026-47326",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163667,
                    2163401,
                    2147533,
                    1990064,
                    2144679,
                    2142956,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2160302,
                    2161304,
                    2160497,
                    1786013,
                    2159617,
                    1786013,
                    2156849,
                    2155837,
                    2146517,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2148809,
                    2151747,
                    2151747,
                    2151747,
                    1990064,
                    2144679,
                    2142956,
                    2139664,
                    2142956,
                    2141298,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2154256,
                    1786013,
                    2154174,
                    2152714,
                    2148866,
                    2149808,
                    2148718
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.2.0-5.5 -proposed tracker (LP: #2163667)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163667
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 16:59:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-4.4 -proposed tracker (LP: #2163401)",
                            "",
                            "  * AA: disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED (LP: #2147533)",
                            "    - [Config] disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.1.0 [60/61]: apparmor: skb: add the ability to use",
                            "      interface in network mediation.",
                            "    - SAUCE: apparmor5.1.0 [61/61]: apparmor: skb: switch to using sk_ctx crit",
                            "      section",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.1.0 [59/61]: apparmor: skb: fix",
                            "      apparmor_secmark_check() when !inet and secmark defined.",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.1.0 [1/61]: apparmor-next: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.1.0 [2/61]: apparmor-next: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.1.0 [3/61]: apparmor-next: apparmor: Initial support",
                            "      for compressed policies",
                            "    - SAUCE: apparmor5.1.0 [4/61]: apparmor-next: apparmor: fix alternate",
                            "      loaders ability to load compressed policy",
                            "    - SAUCE: apparmor5.1.0 [5/61]: apparmor-next: apparmor: replace",
                            "      decompress_zstd() prototype with its entity",
                            "    - SAUCE: apparmor5.1.0 [6/61]: apparmor-next: apparmor: leverage",
                            "      audit_log_n_untrustedstring() when possible",
                            "    - SAUCE: apparmor5.1.0 [7/61]: apparmor-next: apparmor: switch website",
                            "      link to https",
                            "    - SAUCE: apparmor5.1.0 [8/61]: apparmor-next: apparmor: compressed_data",
                            "      not described in aa_get_data_from_compressed",
                            "    - SAUCE: apparmor5.1.0 [9/61]: apparmor-next: apparmor: Fix build failure",
                            "      when ZSTD_DECOMPRESS is not enabled",
                            "    - SAUCE: apparmor5.1.0 [10/61]: apparmor-next: apparmor: fix implicit",
                            "      declaration of function 'decompress_zstd'",
                            "    - SAUCE: apparmor5.1.0 [11/61]: apparmor-next: apparmor: Fix warning:",
                            "      'decompress_zstd' defined but not used",
                            "    - SAUCE: apparmor5.1.0 [12/61]: apparmor-next: apparmor: use",
                            "      SEND_SIG_NOINFO instead of NULL in aa_audit()",
                            "    - SAUCE: apparmor5.1.0 [13/61]: apparmor-next: apparmor: fix cred UAF",
                            "      caused by begin_current_label_crit_section()",
                            "    - SAUCE: apparmor5.1.0 [14/61]: apparmor-next: apparmor: optimize",
                            "      current_label_crit_section() with needput",
                            "    - SAUCE: apparmor5.1.0 [15/61]: apparmor-next: apparmor: fix integer",
                            "      overflow in verify_tags() bounds check",
                            "    - SAUCE: apparmor5.1.0 [16/61]: apparmor-next: apparmor: fix out-of-bounds",
                            "      write when null terminating a label vec",
                            "    - SAUCE: apparmor5.1.0 [17/61]: apparmor-next: apparmor: fix error",
                            "      handling for copy_from_user in policy_update",
                            "    - SAUCE: apparmor5.1.0 [18/61]: apparmor-next: apparmor: make",
                            "      MEDIATES_AF_UNIX its own fn",
                            "    - SAUCE: apparmor5.1.0 [19/61]: apparmor-next: apparmor: refactor network",
                            "      sock mediation in preparation for inet mediation",
                            "    - SAUCE: apparmor5.1.0 [20/61]: apparmor-next: apparmor: push inet",
                            "      mediation into profile callbacks, and improve auditing",
                            "    - SAUCE: apparmor5.1.0 [21/61]: apparmor-next: apparmor: refactor network",
                            "      socket mediation to support compatibility",
                            "    - SAUCE: apparmor5.1.0 [22/61]: apparmor-next: apparmor: move netfilter",
                            "      functions next to the LSM network operations",
                            "    - SAUCE: apparmor5.1.0 [23/61]: apparmor-next: apparmor: move",
                            "      sock_rcv_skb() next to inet_conn_request",
                            "    - SAUCE: apparmor5.1.0 [24/61]: apparmor-next: apparmor: reserve mediation",
                            "      class for packet mediation",
                            "    - SAUCE: apparmor5.1.0 [25/61]: apparmor-next: apparmor: fix unconfined",
                            "      user namespace restriction forced stack",
                            "    - SAUCE: apparmor5.1.0 [26/61]: apparmor-next: apparmor: refactor xattr",
                            "      attachment, to take the file path",
                            "    - SAUCE: apparmor5.1.0 [27/61]: apparmor-next: apparmor: fix race",
                            "      condition in label replacement",
                            "    - SAUCE: apparmor5.1.0 [28/61]: apparmor-next: apparmor: make table entry",
                            "      count last enum for static tables",
                            "    - SAUCE: apparmor5.1.0 [29/61]: apparmor-next: apparmor: fix error debug",
                            "      output in fn_label_build",
                            "    - SAUCE: apparmor5.1.0 [30/61]: apparmor-next: apparmor: mark static",
                            "      tables and structs as read only",
                            "    - SAUCE: apparmor5.1.0 [31/61]: apparmor-next: apparmor: add audit mode to",
                            "      provide a mechanism to silence complain messages",
                            "    - SAUCE: apparmor5.1.0 [32/61]: apparmor-next: apparmor: fix auditing of",
                            "      mount binary data",
                            "    - SAUCE: apparmor5.1.0 [33/61]: apparmor-next: apparmor: refactory mount",
                            "      to use check_perms",
                            "    - SAUCE: apparmor5.1.0 [34/61]: apparmor-next: apparmor: drop use of",
                            "      _confined variant for iteration",
                            "    - SAUCE: apparmor5.1.0 [35/61]: apparmor-next: apparmor: constify aa_perms",
                            "      parameters that are read-only",
                            "    - SAUCE: apparmor5.1.0 [36/61]: apparmor-next: apparmor: constify",
                            "      aa_profile parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [37/61]: apparmor-next: apparmor: constify aa_dfa",
                            "      parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [38/61]: apparmor-next: apparmor: constify aa_label",
                            "      parameters on read-only query helpers",
                            "    - SAUCE: apparmor5.1.0 [39/61]: apparmor-next-next: apparmor: setup slab",
                            "      cache for audit data",
                            "    - SAUCE: apparmor5.1.0 [40/61]: apparmor-next-next: apparmor: add the",
                            "      ability for profiles to have a learning cache",
                            "    - SAUCE: apparmor5.1.0 [41/61]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.1.0 [42/61]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.1.0 [43/61]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.1.0 [44/61]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.1.0 [45/61]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.1.0 [46/61]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [47/61]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [48/61]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.1.0 [50/61]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.1.0 [51/61]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.1.0 [52/61]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.1.0 [53/61]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.1.0 [54/61]: apparmor: mqueue: prevent",
                            "      profile->disconnected double free in aa_free_profile",
                            "    - SAUCE: apparmor5.1.0 [55/61]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.1.0 [58/61]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.1.0 [56/61]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.1.0 [57/61]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.1.0 [49/61]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Drop DEP-8 tests from kernel packages (LP: #2160302)",
                            "    - [Packaging] Drop DEP-8 tests from kernel source",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] updateconfigs after rebase to v7.2-rc6",
                            "    - [Config] Enable SECURITY_APPARMOR_COMPRESSED_POLICY",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163401,
                            2147533,
                            1990064,
                            2144679,
                            2142956,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602,
                            2160302
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:46:26 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-2.2 -proposed tracker (LP: #2161304)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Changes.md: dropping reboot=pci quirks for sandy bridge hw",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161304
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:29:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-1.1 -proposed tracker (LP: #2160497)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160497,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:07:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-0.0 -proposed tracker (LP: #2159617)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] update annotations scripts",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.2-rc1 rebase",
                            "    - [Config] updateconfigs after v7.2-rc1 rebase",
                            "    - SAUCE: thunderbolt: fixup move of pci_device out of tb_nhi",
                            "    - [Packaging] integrate SBOM generation into the build",
                            "    - SAUCE: fixup s/strncpy/strscpy/ in compat_uts_machine= kernel command",
                            "      line override",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: media: venus: core: guard SC8280XP/SM8350 resources behind !IRIS",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159617,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47337",
                                "url": "https://ubuntu.com/security/CVE-2026-47337",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47334",
                                "url": "https://ubuntu.com/security/CVE-2026-47334",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47333",
                                "url": "https://ubuntu.com/security/CVE-2026-47333",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47332",
                                "url": "https://ubuntu.com/security/CVE-2026-47332",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47330",
                                "url": "https://ubuntu.com/security/CVE-2026-47330",
                                "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47329",
                                "url": "https://ubuntu.com/security/CVE-2026-47329",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47327",
                                "url": "https://ubuntu.com/security/CVE-2026-47327",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47328",
                                "url": "https://ubuntu.com/security/CVE-2026-47328",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47326",
                                "url": "https://ubuntu.com/security/CVE-2026-47326",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-5.5 -proposed tracker (LP: #2156849)",
                            "",
                            "  * MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260",
                            "    renders upside-down (LP: #2155837)",
                            "    - SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14",
                            "      Premium PA14260",
                            "",
                            "  * ov08x40 module mounted upside down on a certain DELL platforms",
                            "    (LP: #2146517)",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for new Dell XPS laptops with",
                            "      upside down sensors",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for Dell 14 laptops with upside",
                            "      down sensors",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747)",
                            "    - SAUCE: apparmor: pass big_resp to handler",
                            "    - SAUCE: apparmor: remove redundant kref_init for listener->count",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47337",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47334",
                            "    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47333",
                            "    - SAUCE: apparmor: fix dfa unpacking size of the notification filter",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47332",
                            "    - SAUCE: apparmor: fix size check against type instead of pointer",
                            "",
                            "  * apparmor: LLVM/clang build failure due to uninitialized variable in",
                            "    notify.c (LP: #2148809) // CVE-2026-47330",
                            "    - SAUCE: apparmor: initialize variable used in uninitialized context",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47329",
                            "    - SAUCE: apparmor: fix name validation bypass on notification",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47327 //",
                            "    CVE-2026-47328",
                            "    - SAUCE: apparmor: fix glob memory leak after kstrdup",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47326",
                            "    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.0.0 [57/57]: apparmor: add the ability to use interface",
                            "      in network mediation.",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [29/57]: apparmor: fix fine grained inet mediation",
                            "      sock_file_perm",
                            "    - SAUCE: apparmor5.0.0 [32/57]: apparmor-next 7.1: apparmor: enable",
                            "      differential encoding",
                            "    - SAUCE: apparmor5.0.0 [33/57]: apparmor-next 7.1: apparmor: propagate",
                            "      -ENOMEM correctly in unpack_table",
                            "    - SAUCE: apparmor5.0.0 [36/57]: apparmor-next 7.1: apparmor: use",
                            "      __label_make_stale in __aa_proxy_redirect",
                            "    - SAUCE: apparmor5.0.0 [37/57]: apparmor-next 7.1: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.0.0 [39/57]: apparmor-next 7.1: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1: apparmor: fix",
                            "      rawdata_f_data implicit flex array",
                            "    - SAUCE: apparmor5.0.0 [42/57]: apparmor-next 7.1: apparmor: free rawdata",
                            "      as soon as possible",
                            "    - SAUCE: apparmor5.0.0 [43/57]: apparmor-next 7.1: apparmor: Initial",
                            "      support for compressed policies",
                            "    - SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1: apparmor: fix potential",
                            "      UAF in aa_replace_profiles",
                            "    - SAUCE: apparmor5.0.0 [45/57]: apparmor-next 7.1: apparmor: hide unused",
                            "      get_loaddata_common_ref() function",
                            "    - SAUCE: apparmor5.0.0 [47/57]: apparmor: fix packed tag on v5 header",
                            "      struct",
                            "    - SAUCE: apparmor5.0.0 [48/57]: apparmor: add temporal caching to audit",
                            "      responses.",
                            "    - SAUCE: apparmor5.0.0 [49/57]: apparmor: change fn_label_build() call to",
                            "      not return NULL",
                            "    - SAUCE: apparmor5.0.0 [50/57]: apparmor: make fn_label_build() capable of",
                            "      handling not supported",
                            "    - SAUCE: apparmor5.0.0 [51/57]: apparmor: move netfilter functions next to",
                            "      the LSM network operations",
                            "    - SAUCE: apparmor5.0.0 [52/57]: apparmor: move sock_rvc_skb() next to",
                            "      inet_conn_request",
                            "    - SAUCE: apparmor5.0.0 [53/57]: apparmor: fix af_unix local addr mediation",
                            "      binding",
                            "    - SAUCE: apparmor5.0.0 [54/57]: cleanups of apparmor af_unix mediation",
                            "    - SAUCE: apparmor5.0.0 [55/57]: apparmor: fix apparmor_secmark_check()",
                            "      when !inet and secmark defined.",
                            "    - SAUCE: apparmor5.0.0 [56/57]: apparmor: fix auditing of non-mediation",
                            "      falures",
                            "",
                            "  * snap service cannot change apparmor hat (LP: #2139664) // Jellyfin Desktop",
                            "    Flatpak doesn't work with the current AppArmor profile (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1: apparmor: grab ns lock",
                            "      and refresh when looking up changehat child profiles",
                            "",
                            "  * AppArmor blocks write(2) to network sockets with Linux 6.19 (LP: #2141298)",
                            "    - SAUCE: apparmor5.0.0 [28/57]: apparmor: fix aa_label_sk_perm to check",
                            "      for RULE_MEDIATES_NET",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.0.0 [1/57]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.0.0 [2/57]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.0.0 [3/57]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.0.0 [4/57]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.0.0 [5/57]: Revert \"apparmor: gate make fine grained",
                            "      unix mediation behind v9 abi\"",
                            "    - SAUCE: apparmor5.0.0 [6/57]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.0.0 [7/57]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [8/57]: apparmor: lift compatibility check out of",
                            "      profile_af_perm",
                            "    - SAUCE: apparmor5.0.0 [9/57]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [10/57]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.0.0 [12/57]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.0.0 [13/57]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.0.0 [14/57]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.0.0 [15/57]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.0.0 [16/57]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.0.0 [19/57]: apparmor: prompt: setup slab cache for",
                            "      audit data",
                            "    - SAUCE: apparmor5.0.0 [20/57]: apparmor: prompt: add the ability for",
                            "      profiles to have a learning cache",
                            "    - SAUCE: apparmor5.0.0 [21/57]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "    - SAUCE: apparmor5.0.0 [22/57]: apparmor: prompt: pass prompt boolean",
                            "      through into path_name as well",
                            "    - SAUCE: apparmor5.0.0 [23/57]: apparmor: check for supported version in",
                            "      notification messages.",
                            "    - SAUCE: apparmor5.0.0 [24/57]: apparmor: refactor building notice so it",
                            "      is easier to extend",
                            "    - SAUCE: apparmor5.0.0 [25/57]: apparmor: switch from ENOTSUPP to",
                            "      EPROTONOSUPPORT",
                            "    - SAUCE: apparmor5.0.0 [26/57]: apparmor: add support for meta data tags",
                            "    - SAUCE: apparmor5.0.0 [27/57]: apparmor: prevent profile->disconnected",
                            "      double free in aa_free_profile",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.0.0 [17/57]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.0.0 [18/57]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.0.0 [11/57]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] enable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "    - [Packaging] Fix cross-builds",
                            "    - [Config] updateconfigs after v7.1 rebase",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2156849,
                            2155837,
                            2146517,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2148809,
                            2151747,
                            2151747,
                            2151747,
                            1990064,
                            2144679,
                            2142956,
                            2139664,
                            2142956,
                            2141298,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:38:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-1.1 -proposed tracker (LP: #2154256)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "",
                            "  * resolute ubuntu_kernel_selftests:seccomp_build test compilation issue",
                            "    (LP: #2154174)",
                            "    - SAUCE: selftests/seccomp fix compilation issue for amd64",
                            "",
                            "  * Kernel 6.19-rc8 does not include GPIB driver (LP: #2152714)",
                            "    - [Config] Enable CONFIG_GPIB for amd64",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.1-rc4 rebase",
                            "    - [packaging] Install gdb scripts again",
                            "    - [Config] updateconfigs after v7.1-rc5 rebase",
                            "    - [Packaging] templates: Use a for-loop for run-parts",
                            "    - [Packaging] Remove dead debian.master/rules.d/x32.mk",
                            "    - [Packaging] Remove orphaned debian/v4l2loopback-modules.ignore",
                            "    - [Packaging] Remove orphaned debian/zfs-modules.ignore",
                            "    - [Packaging] Remove deprecated linux-doc transitional stub",
                            "    - [Packaging] Remove dead comment referencing gcc-4.7 in control.stub.in",
                            "    - [Packaging] Remove dead comment in ppc64el.mk",
                            "    - [Packaging] Remove stale legacy code",
                            "    - [Packaging] rules: Drop an obsolete check for do_zstd_ko",
                            "    - [Config] toolchain version update",
                            "    - [Packaging] update Ubuntu.md",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154256,
                            1786013,
                            2154174,
                            2152714
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:08:55 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 09:59:13 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * resolute/linux: 7.0.0-15.15 -proposed tracker (LP: #2148866)",
                            "",
                            "  * Qualcomm X1E: Speaker overdrive causes hardware protection shutdown",
                            "    (LP: #2149808)",
                            "    - SAUCE: ASoC: qcom: x1e80100: limit speaker volumes",
                            "",
                            "  * intel-ipu7 / intel-ipu7-isys modules are shipped unsigned in latest",
                            "    Resolute kernels, breaking Secure Boot systems  (LP: #2148718)",
                            "    - [packaging] add intel-ipu7 to signature inclusion list",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2148866,
                            2149808,
                            2148718
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:02:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-perf",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-47337",
                        "url": "https://ubuntu.com/security/CVE-2026-47337",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47334",
                        "url": "https://ubuntu.com/security/CVE-2026-47334",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47333",
                        "url": "https://ubuntu.com/security/CVE-2026-47333",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47332",
                        "url": "https://ubuntu.com/security/CVE-2026-47332",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47330",
                        "url": "https://ubuntu.com/security/CVE-2026-47330",
                        "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47329",
                        "url": "https://ubuntu.com/security/CVE-2026-47329",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47327",
                        "url": "https://ubuntu.com/security/CVE-2026-47327",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47328",
                        "url": "https://ubuntu.com/security/CVE-2026-47328",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47326",
                        "url": "https://ubuntu.com/security/CVE-2026-47326",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163667,
                    2163401,
                    2147533,
                    1990064,
                    2144679,
                    2142956,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2160302,
                    2161304,
                    2160497,
                    1786013,
                    2159617,
                    1786013,
                    2156849,
                    2155837,
                    2146517,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2148809,
                    2151747,
                    2151747,
                    2151747,
                    1990064,
                    2144679,
                    2142956,
                    2139664,
                    2142956,
                    2141298,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2154256,
                    1786013,
                    2154174,
                    2152714,
                    2148866,
                    2149808,
                    2148718
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.2.0-5.5 -proposed tracker (LP: #2163667)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163667
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 16:59:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-4.4 -proposed tracker (LP: #2163401)",
                            "",
                            "  * AA: disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED (LP: #2147533)",
                            "    - [Config] disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.1.0 [60/61]: apparmor: skb: add the ability to use",
                            "      interface in network mediation.",
                            "    - SAUCE: apparmor5.1.0 [61/61]: apparmor: skb: switch to using sk_ctx crit",
                            "      section",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.1.0 [59/61]: apparmor: skb: fix",
                            "      apparmor_secmark_check() when !inet and secmark defined.",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.1.0 [1/61]: apparmor-next: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.1.0 [2/61]: apparmor-next: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.1.0 [3/61]: apparmor-next: apparmor: Initial support",
                            "      for compressed policies",
                            "    - SAUCE: apparmor5.1.0 [4/61]: apparmor-next: apparmor: fix alternate",
                            "      loaders ability to load compressed policy",
                            "    - SAUCE: apparmor5.1.0 [5/61]: apparmor-next: apparmor: replace",
                            "      decompress_zstd() prototype with its entity",
                            "    - SAUCE: apparmor5.1.0 [6/61]: apparmor-next: apparmor: leverage",
                            "      audit_log_n_untrustedstring() when possible",
                            "    - SAUCE: apparmor5.1.0 [7/61]: apparmor-next: apparmor: switch website",
                            "      link to https",
                            "    - SAUCE: apparmor5.1.0 [8/61]: apparmor-next: apparmor: compressed_data",
                            "      not described in aa_get_data_from_compressed",
                            "    - SAUCE: apparmor5.1.0 [9/61]: apparmor-next: apparmor: Fix build failure",
                            "      when ZSTD_DECOMPRESS is not enabled",
                            "    - SAUCE: apparmor5.1.0 [10/61]: apparmor-next: apparmor: fix implicit",
                            "      declaration of function 'decompress_zstd'",
                            "    - SAUCE: apparmor5.1.0 [11/61]: apparmor-next: apparmor: Fix warning:",
                            "      'decompress_zstd' defined but not used",
                            "    - SAUCE: apparmor5.1.0 [12/61]: apparmor-next: apparmor: use",
                            "      SEND_SIG_NOINFO instead of NULL in aa_audit()",
                            "    - SAUCE: apparmor5.1.0 [13/61]: apparmor-next: apparmor: fix cred UAF",
                            "      caused by begin_current_label_crit_section()",
                            "    - SAUCE: apparmor5.1.0 [14/61]: apparmor-next: apparmor: optimize",
                            "      current_label_crit_section() with needput",
                            "    - SAUCE: apparmor5.1.0 [15/61]: apparmor-next: apparmor: fix integer",
                            "      overflow in verify_tags() bounds check",
                            "    - SAUCE: apparmor5.1.0 [16/61]: apparmor-next: apparmor: fix out-of-bounds",
                            "      write when null terminating a label vec",
                            "    - SAUCE: apparmor5.1.0 [17/61]: apparmor-next: apparmor: fix error",
                            "      handling for copy_from_user in policy_update",
                            "    - SAUCE: apparmor5.1.0 [18/61]: apparmor-next: apparmor: make",
                            "      MEDIATES_AF_UNIX its own fn",
                            "    - SAUCE: apparmor5.1.0 [19/61]: apparmor-next: apparmor: refactor network",
                            "      sock mediation in preparation for inet mediation",
                            "    - SAUCE: apparmor5.1.0 [20/61]: apparmor-next: apparmor: push inet",
                            "      mediation into profile callbacks, and improve auditing",
                            "    - SAUCE: apparmor5.1.0 [21/61]: apparmor-next: apparmor: refactor network",
                            "      socket mediation to support compatibility",
                            "    - SAUCE: apparmor5.1.0 [22/61]: apparmor-next: apparmor: move netfilter",
                            "      functions next to the LSM network operations",
                            "    - SAUCE: apparmor5.1.0 [23/61]: apparmor-next: apparmor: move",
                            "      sock_rcv_skb() next to inet_conn_request",
                            "    - SAUCE: apparmor5.1.0 [24/61]: apparmor-next: apparmor: reserve mediation",
                            "      class for packet mediation",
                            "    - SAUCE: apparmor5.1.0 [25/61]: apparmor-next: apparmor: fix unconfined",
                            "      user namespace restriction forced stack",
                            "    - SAUCE: apparmor5.1.0 [26/61]: apparmor-next: apparmor: refactor xattr",
                            "      attachment, to take the file path",
                            "    - SAUCE: apparmor5.1.0 [27/61]: apparmor-next: apparmor: fix race",
                            "      condition in label replacement",
                            "    - SAUCE: apparmor5.1.0 [28/61]: apparmor-next: apparmor: make table entry",
                            "      count last enum for static tables",
                            "    - SAUCE: apparmor5.1.0 [29/61]: apparmor-next: apparmor: fix error debug",
                            "      output in fn_label_build",
                            "    - SAUCE: apparmor5.1.0 [30/61]: apparmor-next: apparmor: mark static",
                            "      tables and structs as read only",
                            "    - SAUCE: apparmor5.1.0 [31/61]: apparmor-next: apparmor: add audit mode to",
                            "      provide a mechanism to silence complain messages",
                            "    - SAUCE: apparmor5.1.0 [32/61]: apparmor-next: apparmor: fix auditing of",
                            "      mount binary data",
                            "    - SAUCE: apparmor5.1.0 [33/61]: apparmor-next: apparmor: refactory mount",
                            "      to use check_perms",
                            "    - SAUCE: apparmor5.1.0 [34/61]: apparmor-next: apparmor: drop use of",
                            "      _confined variant for iteration",
                            "    - SAUCE: apparmor5.1.0 [35/61]: apparmor-next: apparmor: constify aa_perms",
                            "      parameters that are read-only",
                            "    - SAUCE: apparmor5.1.0 [36/61]: apparmor-next: apparmor: constify",
                            "      aa_profile parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [37/61]: apparmor-next: apparmor: constify aa_dfa",
                            "      parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [38/61]: apparmor-next: apparmor: constify aa_label",
                            "      parameters on read-only query helpers",
                            "    - SAUCE: apparmor5.1.0 [39/61]: apparmor-next-next: apparmor: setup slab",
                            "      cache for audit data",
                            "    - SAUCE: apparmor5.1.0 [40/61]: apparmor-next-next: apparmor: add the",
                            "      ability for profiles to have a learning cache",
                            "    - SAUCE: apparmor5.1.0 [41/61]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.1.0 [42/61]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.1.0 [43/61]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.1.0 [44/61]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.1.0 [45/61]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.1.0 [46/61]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [47/61]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [48/61]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.1.0 [50/61]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.1.0 [51/61]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.1.0 [52/61]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.1.0 [53/61]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.1.0 [54/61]: apparmor: mqueue: prevent",
                            "      profile->disconnected double free in aa_free_profile",
                            "    - SAUCE: apparmor5.1.0 [55/61]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.1.0 [58/61]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.1.0 [56/61]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.1.0 [57/61]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.1.0 [49/61]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Drop DEP-8 tests from kernel packages (LP: #2160302)",
                            "    - [Packaging] Drop DEP-8 tests from kernel source",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] updateconfigs after rebase to v7.2-rc6",
                            "    - [Config] Enable SECURITY_APPARMOR_COMPRESSED_POLICY",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163401,
                            2147533,
                            1990064,
                            2144679,
                            2142956,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602,
                            2160302
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:46:26 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-2.2 -proposed tracker (LP: #2161304)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Changes.md: dropping reboot=pci quirks for sandy bridge hw",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161304
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:29:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-1.1 -proposed tracker (LP: #2160497)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160497,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:07:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-0.0 -proposed tracker (LP: #2159617)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] update annotations scripts",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.2-rc1 rebase",
                            "    - [Config] updateconfigs after v7.2-rc1 rebase",
                            "    - SAUCE: thunderbolt: fixup move of pci_device out of tb_nhi",
                            "    - [Packaging] integrate SBOM generation into the build",
                            "    - SAUCE: fixup s/strncpy/strscpy/ in compat_uts_machine= kernel command",
                            "      line override",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: media: venus: core: guard SC8280XP/SM8350 resources behind !IRIS",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159617,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47337",
                                "url": "https://ubuntu.com/security/CVE-2026-47337",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47334",
                                "url": "https://ubuntu.com/security/CVE-2026-47334",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47333",
                                "url": "https://ubuntu.com/security/CVE-2026-47333",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47332",
                                "url": "https://ubuntu.com/security/CVE-2026-47332",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47330",
                                "url": "https://ubuntu.com/security/CVE-2026-47330",
                                "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47329",
                                "url": "https://ubuntu.com/security/CVE-2026-47329",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47327",
                                "url": "https://ubuntu.com/security/CVE-2026-47327",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47328",
                                "url": "https://ubuntu.com/security/CVE-2026-47328",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47326",
                                "url": "https://ubuntu.com/security/CVE-2026-47326",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-5.5 -proposed tracker (LP: #2156849)",
                            "",
                            "  * MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260",
                            "    renders upside-down (LP: #2155837)",
                            "    - SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14",
                            "      Premium PA14260",
                            "",
                            "  * ov08x40 module mounted upside down on a certain DELL platforms",
                            "    (LP: #2146517)",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for new Dell XPS laptops with",
                            "      upside down sensors",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for Dell 14 laptops with upside",
                            "      down sensors",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747)",
                            "    - SAUCE: apparmor: pass big_resp to handler",
                            "    - SAUCE: apparmor: remove redundant kref_init for listener->count",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47337",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47334",
                            "    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47333",
                            "    - SAUCE: apparmor: fix dfa unpacking size of the notification filter",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47332",
                            "    - SAUCE: apparmor: fix size check against type instead of pointer",
                            "",
                            "  * apparmor: LLVM/clang build failure due to uninitialized variable in",
                            "    notify.c (LP: #2148809) // CVE-2026-47330",
                            "    - SAUCE: apparmor: initialize variable used in uninitialized context",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47329",
                            "    - SAUCE: apparmor: fix name validation bypass on notification",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47327 //",
                            "    CVE-2026-47328",
                            "    - SAUCE: apparmor: fix glob memory leak after kstrdup",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47326",
                            "    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.0.0 [57/57]: apparmor: add the ability to use interface",
                            "      in network mediation.",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [29/57]: apparmor: fix fine grained inet mediation",
                            "      sock_file_perm",
                            "    - SAUCE: apparmor5.0.0 [32/57]: apparmor-next 7.1: apparmor: enable",
                            "      differential encoding",
                            "    - SAUCE: apparmor5.0.0 [33/57]: apparmor-next 7.1: apparmor: propagate",
                            "      -ENOMEM correctly in unpack_table",
                            "    - SAUCE: apparmor5.0.0 [36/57]: apparmor-next 7.1: apparmor: use",
                            "      __label_make_stale in __aa_proxy_redirect",
                            "    - SAUCE: apparmor5.0.0 [37/57]: apparmor-next 7.1: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.0.0 [39/57]: apparmor-next 7.1: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1: apparmor: fix",
                            "      rawdata_f_data implicit flex array",
                            "    - SAUCE: apparmor5.0.0 [42/57]: apparmor-next 7.1: apparmor: free rawdata",
                            "      as soon as possible",
                            "    - SAUCE: apparmor5.0.0 [43/57]: apparmor-next 7.1: apparmor: Initial",
                            "      support for compressed policies",
                            "    - SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1: apparmor: fix potential",
                            "      UAF in aa_replace_profiles",
                            "    - SAUCE: apparmor5.0.0 [45/57]: apparmor-next 7.1: apparmor: hide unused",
                            "      get_loaddata_common_ref() function",
                            "    - SAUCE: apparmor5.0.0 [47/57]: apparmor: fix packed tag on v5 header",
                            "      struct",
                            "    - SAUCE: apparmor5.0.0 [48/57]: apparmor: add temporal caching to audit",
                            "      responses.",
                            "    - SAUCE: apparmor5.0.0 [49/57]: apparmor: change fn_label_build() call to",
                            "      not return NULL",
                            "    - SAUCE: apparmor5.0.0 [50/57]: apparmor: make fn_label_build() capable of",
                            "      handling not supported",
                            "    - SAUCE: apparmor5.0.0 [51/57]: apparmor: move netfilter functions next to",
                            "      the LSM network operations",
                            "    - SAUCE: apparmor5.0.0 [52/57]: apparmor: move sock_rvc_skb() next to",
                            "      inet_conn_request",
                            "    - SAUCE: apparmor5.0.0 [53/57]: apparmor: fix af_unix local addr mediation",
                            "      binding",
                            "    - SAUCE: apparmor5.0.0 [54/57]: cleanups of apparmor af_unix mediation",
                            "    - SAUCE: apparmor5.0.0 [55/57]: apparmor: fix apparmor_secmark_check()",
                            "      when !inet and secmark defined.",
                            "    - SAUCE: apparmor5.0.0 [56/57]: apparmor: fix auditing of non-mediation",
                            "      falures",
                            "",
                            "  * snap service cannot change apparmor hat (LP: #2139664) // Jellyfin Desktop",
                            "    Flatpak doesn't work with the current AppArmor profile (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1: apparmor: grab ns lock",
                            "      and refresh when looking up changehat child profiles",
                            "",
                            "  * AppArmor blocks write(2) to network sockets with Linux 6.19 (LP: #2141298)",
                            "    - SAUCE: apparmor5.0.0 [28/57]: apparmor: fix aa_label_sk_perm to check",
                            "      for RULE_MEDIATES_NET",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.0.0 [1/57]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.0.0 [2/57]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.0.0 [3/57]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.0.0 [4/57]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.0.0 [5/57]: Revert \"apparmor: gate make fine grained",
                            "      unix mediation behind v9 abi\"",
                            "    - SAUCE: apparmor5.0.0 [6/57]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.0.0 [7/57]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [8/57]: apparmor: lift compatibility check out of",
                            "      profile_af_perm",
                            "    - SAUCE: apparmor5.0.0 [9/57]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [10/57]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.0.0 [12/57]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.0.0 [13/57]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.0.0 [14/57]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.0.0 [15/57]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.0.0 [16/57]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.0.0 [19/57]: apparmor: prompt: setup slab cache for",
                            "      audit data",
                            "    - SAUCE: apparmor5.0.0 [20/57]: apparmor: prompt: add the ability for",
                            "      profiles to have a learning cache",
                            "    - SAUCE: apparmor5.0.0 [21/57]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "    - SAUCE: apparmor5.0.0 [22/57]: apparmor: prompt: pass prompt boolean",
                            "      through into path_name as well",
                            "    - SAUCE: apparmor5.0.0 [23/57]: apparmor: check for supported version in",
                            "      notification messages.",
                            "    - SAUCE: apparmor5.0.0 [24/57]: apparmor: refactor building notice so it",
                            "      is easier to extend",
                            "    - SAUCE: apparmor5.0.0 [25/57]: apparmor: switch from ENOTSUPP to",
                            "      EPROTONOSUPPORT",
                            "    - SAUCE: apparmor5.0.0 [26/57]: apparmor: add support for meta data tags",
                            "    - SAUCE: apparmor5.0.0 [27/57]: apparmor: prevent profile->disconnected",
                            "      double free in aa_free_profile",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.0.0 [17/57]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.0.0 [18/57]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.0.0 [11/57]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] enable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "    - [Packaging] Fix cross-builds",
                            "    - [Config] updateconfigs after v7.1 rebase",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2156849,
                            2155837,
                            2146517,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2148809,
                            2151747,
                            2151747,
                            2151747,
                            1990064,
                            2144679,
                            2142956,
                            2139664,
                            2142956,
                            2141298,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:38:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-1.1 -proposed tracker (LP: #2154256)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "",
                            "  * resolute ubuntu_kernel_selftests:seccomp_build test compilation issue",
                            "    (LP: #2154174)",
                            "    - SAUCE: selftests/seccomp fix compilation issue for amd64",
                            "",
                            "  * Kernel 6.19-rc8 does not include GPIB driver (LP: #2152714)",
                            "    - [Config] Enable CONFIG_GPIB for amd64",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.1-rc4 rebase",
                            "    - [packaging] Install gdb scripts again",
                            "    - [Config] updateconfigs after v7.1-rc5 rebase",
                            "    - [Packaging] templates: Use a for-loop for run-parts",
                            "    - [Packaging] Remove dead debian.master/rules.d/x32.mk",
                            "    - [Packaging] Remove orphaned debian/v4l2loopback-modules.ignore",
                            "    - [Packaging] Remove orphaned debian/zfs-modules.ignore",
                            "    - [Packaging] Remove deprecated linux-doc transitional stub",
                            "    - [Packaging] Remove dead comment referencing gcc-4.7 in control.stub.in",
                            "    - [Packaging] Remove dead comment in ppc64el.mk",
                            "    - [Packaging] Remove stale legacy code",
                            "    - [Packaging] rules: Drop an obsolete check for do_zstd_ko",
                            "    - [Config] toolchain version update",
                            "    - [Packaging] update Ubuntu.md",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154256,
                            1786013,
                            2154174,
                            2152714
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:08:55 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 09:59:13 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * resolute/linux: 7.0.0-15.15 -proposed tracker (LP: #2148866)",
                            "",
                            "  * Qualcomm X1E: Speaker overdrive causes hardware protection shutdown",
                            "    (LP: #2149808)",
                            "    - SAUCE: ASoC: qcom: x1e80100: limit speaker volumes",
                            "",
                            "  * intel-ipu7 / intel-ipu7-isys modules are shipped unsigned in latest",
                            "    Resolute kernels, breaking Secure Boot systems  (LP: #2148718)",
                            "    - [packaging] add intel-ipu7 to signature inclusion list",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2148866,
                            2149808,
                            2148718
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:02:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-sysctl-defaults",
                "from_version": {
                    "source_package_name": "linux-base",
                    "source_package_version": "4.15ubuntu5",
                    "version": "4.15ubuntu5"
                },
                "to_version": {
                    "source_package_name": "linux-base",
                    "source_package_version": "4.16ubuntu1",
                    "version": "4.16ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1877088,
                    1929255,
                    1928700,
                    1867820,
                    1881338,
                    1932582,
                    2018128,
                    2098735,
                    21465330
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from debian unstable. Remaining changes:",
                            "    - Default to link_in_boot by default, on all architectures.",
                            "    - Add kernel postinst hook to update initrd softlinks to match the kernel",
                            "      version targets (LP: #1877088, #1929255).",
                            "    - Check for update-initramfs being installed before running the postinst",
                            "      hook which updates the softlinks (LP: #1928700).",
                            "    - Add linux-base-sgx package with SGX udev rules (LP: #1867820, #1881338,",
                            "      #1932582).",
                            "    - Add Apport package hook and links for kernel packages (LP: #2018128,",
                            "      #2098735, #21465330).",
                            "    - Change package maintainer to Ubuntu Kernel Team.",
                            ""
                        ],
                        "package": "linux-base",
                        "version": "4.16ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1877088,
                            1929255,
                            1928700,
                            1867820,
                            1881338,
                            1932582,
                            2018128,
                            2098735,
                            21465330
                        ],
                        "author": "Juerg Haefliger <juerg.haefliger@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:44:02 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Simplify install file.",
                            "  * Add hooks to copy vmlinuz file to /boot.",
                            ""
                        ],
                        "package": "linux-base",
                        "version": "4.16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Blank <waldi@debian.org>",
                        "date": "Sun, 16 Aug 2026 14:33:17 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-tools-common",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-47337",
                        "url": "https://ubuntu.com/security/CVE-2026-47337",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47334",
                        "url": "https://ubuntu.com/security/CVE-2026-47334",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47333",
                        "url": "https://ubuntu.com/security/CVE-2026-47333",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47332",
                        "url": "https://ubuntu.com/security/CVE-2026-47332",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47330",
                        "url": "https://ubuntu.com/security/CVE-2026-47330",
                        "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47329",
                        "url": "https://ubuntu.com/security/CVE-2026-47329",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47327",
                        "url": "https://ubuntu.com/security/CVE-2026-47327",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47328",
                        "url": "https://ubuntu.com/security/CVE-2026-47328",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47326",
                        "url": "https://ubuntu.com/security/CVE-2026-47326",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163667,
                    2163401,
                    2147533,
                    1990064,
                    2144679,
                    2142956,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2160302,
                    2161304,
                    2160497,
                    1786013,
                    2159617,
                    1786013,
                    2156849,
                    2155837,
                    2146517,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2148809,
                    2151747,
                    2151747,
                    2151747,
                    1990064,
                    2144679,
                    2142956,
                    2139664,
                    2142956,
                    2141298,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2154256,
                    1786013,
                    2154174,
                    2152714,
                    2148866,
                    2149808,
                    2148718
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.2.0-5.5 -proposed tracker (LP: #2163667)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163667
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 16:59:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-4.4 -proposed tracker (LP: #2163401)",
                            "",
                            "  * AA: disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED (LP: #2147533)",
                            "    - [Config] disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.1.0 [60/61]: apparmor: skb: add the ability to use",
                            "      interface in network mediation.",
                            "    - SAUCE: apparmor5.1.0 [61/61]: apparmor: skb: switch to using sk_ctx crit",
                            "      section",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.1.0 [59/61]: apparmor: skb: fix",
                            "      apparmor_secmark_check() when !inet and secmark defined.",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.1.0 [1/61]: apparmor-next: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.1.0 [2/61]: apparmor-next: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.1.0 [3/61]: apparmor-next: apparmor: Initial support",
                            "      for compressed policies",
                            "    - SAUCE: apparmor5.1.0 [4/61]: apparmor-next: apparmor: fix alternate",
                            "      loaders ability to load compressed policy",
                            "    - SAUCE: apparmor5.1.0 [5/61]: apparmor-next: apparmor: replace",
                            "      decompress_zstd() prototype with its entity",
                            "    - SAUCE: apparmor5.1.0 [6/61]: apparmor-next: apparmor: leverage",
                            "      audit_log_n_untrustedstring() when possible",
                            "    - SAUCE: apparmor5.1.0 [7/61]: apparmor-next: apparmor: switch website",
                            "      link to https",
                            "    - SAUCE: apparmor5.1.0 [8/61]: apparmor-next: apparmor: compressed_data",
                            "      not described in aa_get_data_from_compressed",
                            "    - SAUCE: apparmor5.1.0 [9/61]: apparmor-next: apparmor: Fix build failure",
                            "      when ZSTD_DECOMPRESS is not enabled",
                            "    - SAUCE: apparmor5.1.0 [10/61]: apparmor-next: apparmor: fix implicit",
                            "      declaration of function 'decompress_zstd'",
                            "    - SAUCE: apparmor5.1.0 [11/61]: apparmor-next: apparmor: Fix warning:",
                            "      'decompress_zstd' defined but not used",
                            "    - SAUCE: apparmor5.1.0 [12/61]: apparmor-next: apparmor: use",
                            "      SEND_SIG_NOINFO instead of NULL in aa_audit()",
                            "    - SAUCE: apparmor5.1.0 [13/61]: apparmor-next: apparmor: fix cred UAF",
                            "      caused by begin_current_label_crit_section()",
                            "    - SAUCE: apparmor5.1.0 [14/61]: apparmor-next: apparmor: optimize",
                            "      current_label_crit_section() with needput",
                            "    - SAUCE: apparmor5.1.0 [15/61]: apparmor-next: apparmor: fix integer",
                            "      overflow in verify_tags() bounds check",
                            "    - SAUCE: apparmor5.1.0 [16/61]: apparmor-next: apparmor: fix out-of-bounds",
                            "      write when null terminating a label vec",
                            "    - SAUCE: apparmor5.1.0 [17/61]: apparmor-next: apparmor: fix error",
                            "      handling for copy_from_user in policy_update",
                            "    - SAUCE: apparmor5.1.0 [18/61]: apparmor-next: apparmor: make",
                            "      MEDIATES_AF_UNIX its own fn",
                            "    - SAUCE: apparmor5.1.0 [19/61]: apparmor-next: apparmor: refactor network",
                            "      sock mediation in preparation for inet mediation",
                            "    - SAUCE: apparmor5.1.0 [20/61]: apparmor-next: apparmor: push inet",
                            "      mediation into profile callbacks, and improve auditing",
                            "    - SAUCE: apparmor5.1.0 [21/61]: apparmor-next: apparmor: refactor network",
                            "      socket mediation to support compatibility",
                            "    - SAUCE: apparmor5.1.0 [22/61]: apparmor-next: apparmor: move netfilter",
                            "      functions next to the LSM network operations",
                            "    - SAUCE: apparmor5.1.0 [23/61]: apparmor-next: apparmor: move",
                            "      sock_rcv_skb() next to inet_conn_request",
                            "    - SAUCE: apparmor5.1.0 [24/61]: apparmor-next: apparmor: reserve mediation",
                            "      class for packet mediation",
                            "    - SAUCE: apparmor5.1.0 [25/61]: apparmor-next: apparmor: fix unconfined",
                            "      user namespace restriction forced stack",
                            "    - SAUCE: apparmor5.1.0 [26/61]: apparmor-next: apparmor: refactor xattr",
                            "      attachment, to take the file path",
                            "    - SAUCE: apparmor5.1.0 [27/61]: apparmor-next: apparmor: fix race",
                            "      condition in label replacement",
                            "    - SAUCE: apparmor5.1.0 [28/61]: apparmor-next: apparmor: make table entry",
                            "      count last enum for static tables",
                            "    - SAUCE: apparmor5.1.0 [29/61]: apparmor-next: apparmor: fix error debug",
                            "      output in fn_label_build",
                            "    - SAUCE: apparmor5.1.0 [30/61]: apparmor-next: apparmor: mark static",
                            "      tables and structs as read only",
                            "    - SAUCE: apparmor5.1.0 [31/61]: apparmor-next: apparmor: add audit mode to",
                            "      provide a mechanism to silence complain messages",
                            "    - SAUCE: apparmor5.1.0 [32/61]: apparmor-next: apparmor: fix auditing of",
                            "      mount binary data",
                            "    - SAUCE: apparmor5.1.0 [33/61]: apparmor-next: apparmor: refactory mount",
                            "      to use check_perms",
                            "    - SAUCE: apparmor5.1.0 [34/61]: apparmor-next: apparmor: drop use of",
                            "      _confined variant for iteration",
                            "    - SAUCE: apparmor5.1.0 [35/61]: apparmor-next: apparmor: constify aa_perms",
                            "      parameters that are read-only",
                            "    - SAUCE: apparmor5.1.0 [36/61]: apparmor-next: apparmor: constify",
                            "      aa_profile parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [37/61]: apparmor-next: apparmor: constify aa_dfa",
                            "      parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [38/61]: apparmor-next: apparmor: constify aa_label",
                            "      parameters on read-only query helpers",
                            "    - SAUCE: apparmor5.1.0 [39/61]: apparmor-next-next: apparmor: setup slab",
                            "      cache for audit data",
                            "    - SAUCE: apparmor5.1.0 [40/61]: apparmor-next-next: apparmor: add the",
                            "      ability for profiles to have a learning cache",
                            "    - SAUCE: apparmor5.1.0 [41/61]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.1.0 [42/61]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.1.0 [43/61]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.1.0 [44/61]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.1.0 [45/61]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.1.0 [46/61]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [47/61]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [48/61]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.1.0 [50/61]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.1.0 [51/61]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.1.0 [52/61]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.1.0 [53/61]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.1.0 [54/61]: apparmor: mqueue: prevent",
                            "      profile->disconnected double free in aa_free_profile",
                            "    - SAUCE: apparmor5.1.0 [55/61]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.1.0 [58/61]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.1.0 [56/61]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.1.0 [57/61]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.1.0 [49/61]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Drop DEP-8 tests from kernel packages (LP: #2160302)",
                            "    - [Packaging] Drop DEP-8 tests from kernel source",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] updateconfigs after rebase to v7.2-rc6",
                            "    - [Config] Enable SECURITY_APPARMOR_COMPRESSED_POLICY",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163401,
                            2147533,
                            1990064,
                            2144679,
                            2142956,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602,
                            2160302
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:46:26 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-2.2 -proposed tracker (LP: #2161304)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Changes.md: dropping reboot=pci quirks for sandy bridge hw",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161304
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:29:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-1.1 -proposed tracker (LP: #2160497)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160497,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:07:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-0.0 -proposed tracker (LP: #2159617)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] update annotations scripts",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.2-rc1 rebase",
                            "    - [Config] updateconfigs after v7.2-rc1 rebase",
                            "    - SAUCE: thunderbolt: fixup move of pci_device out of tb_nhi",
                            "    - [Packaging] integrate SBOM generation into the build",
                            "    - SAUCE: fixup s/strncpy/strscpy/ in compat_uts_machine= kernel command",
                            "      line override",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: media: venus: core: guard SC8280XP/SM8350 resources behind !IRIS",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159617,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47337",
                                "url": "https://ubuntu.com/security/CVE-2026-47337",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47334",
                                "url": "https://ubuntu.com/security/CVE-2026-47334",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47333",
                                "url": "https://ubuntu.com/security/CVE-2026-47333",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47332",
                                "url": "https://ubuntu.com/security/CVE-2026-47332",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47330",
                                "url": "https://ubuntu.com/security/CVE-2026-47330",
                                "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47329",
                                "url": "https://ubuntu.com/security/CVE-2026-47329",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47327",
                                "url": "https://ubuntu.com/security/CVE-2026-47327",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47328",
                                "url": "https://ubuntu.com/security/CVE-2026-47328",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47326",
                                "url": "https://ubuntu.com/security/CVE-2026-47326",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-5.5 -proposed tracker (LP: #2156849)",
                            "",
                            "  * MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260",
                            "    renders upside-down (LP: #2155837)",
                            "    - SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14",
                            "      Premium PA14260",
                            "",
                            "  * ov08x40 module mounted upside down on a certain DELL platforms",
                            "    (LP: #2146517)",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for new Dell XPS laptops with",
                            "      upside down sensors",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for Dell 14 laptops with upside",
                            "      down sensors",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747)",
                            "    - SAUCE: apparmor: pass big_resp to handler",
                            "    - SAUCE: apparmor: remove redundant kref_init for listener->count",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47337",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47334",
                            "    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47333",
                            "    - SAUCE: apparmor: fix dfa unpacking size of the notification filter",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47332",
                            "    - SAUCE: apparmor: fix size check against type instead of pointer",
                            "",
                            "  * apparmor: LLVM/clang build failure due to uninitialized variable in",
                            "    notify.c (LP: #2148809) // CVE-2026-47330",
                            "    - SAUCE: apparmor: initialize variable used in uninitialized context",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47329",
                            "    - SAUCE: apparmor: fix name validation bypass on notification",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47327 //",
                            "    CVE-2026-47328",
                            "    - SAUCE: apparmor: fix glob memory leak after kstrdup",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47326",
                            "    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.0.0 [57/57]: apparmor: add the ability to use interface",
                            "      in network mediation.",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [29/57]: apparmor: fix fine grained inet mediation",
                            "      sock_file_perm",
                            "    - SAUCE: apparmor5.0.0 [32/57]: apparmor-next 7.1: apparmor: enable",
                            "      differential encoding",
                            "    - SAUCE: apparmor5.0.0 [33/57]: apparmor-next 7.1: apparmor: propagate",
                            "      -ENOMEM correctly in unpack_table",
                            "    - SAUCE: apparmor5.0.0 [36/57]: apparmor-next 7.1: apparmor: use",
                            "      __label_make_stale in __aa_proxy_redirect",
                            "    - SAUCE: apparmor5.0.0 [37/57]: apparmor-next 7.1: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.0.0 [39/57]: apparmor-next 7.1: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1: apparmor: fix",
                            "      rawdata_f_data implicit flex array",
                            "    - SAUCE: apparmor5.0.0 [42/57]: apparmor-next 7.1: apparmor: free rawdata",
                            "      as soon as possible",
                            "    - SAUCE: apparmor5.0.0 [43/57]: apparmor-next 7.1: apparmor: Initial",
                            "      support for compressed policies",
                            "    - SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1: apparmor: fix potential",
                            "      UAF in aa_replace_profiles",
                            "    - SAUCE: apparmor5.0.0 [45/57]: apparmor-next 7.1: apparmor: hide unused",
                            "      get_loaddata_common_ref() function",
                            "    - SAUCE: apparmor5.0.0 [47/57]: apparmor: fix packed tag on v5 header",
                            "      struct",
                            "    - SAUCE: apparmor5.0.0 [48/57]: apparmor: add temporal caching to audit",
                            "      responses.",
                            "    - SAUCE: apparmor5.0.0 [49/57]: apparmor: change fn_label_build() call to",
                            "      not return NULL",
                            "    - SAUCE: apparmor5.0.0 [50/57]: apparmor: make fn_label_build() capable of",
                            "      handling not supported",
                            "    - SAUCE: apparmor5.0.0 [51/57]: apparmor: move netfilter functions next to",
                            "      the LSM network operations",
                            "    - SAUCE: apparmor5.0.0 [52/57]: apparmor: move sock_rvc_skb() next to",
                            "      inet_conn_request",
                            "    - SAUCE: apparmor5.0.0 [53/57]: apparmor: fix af_unix local addr mediation",
                            "      binding",
                            "    - SAUCE: apparmor5.0.0 [54/57]: cleanups of apparmor af_unix mediation",
                            "    - SAUCE: apparmor5.0.0 [55/57]: apparmor: fix apparmor_secmark_check()",
                            "      when !inet and secmark defined.",
                            "    - SAUCE: apparmor5.0.0 [56/57]: apparmor: fix auditing of non-mediation",
                            "      falures",
                            "",
                            "  * snap service cannot change apparmor hat (LP: #2139664) // Jellyfin Desktop",
                            "    Flatpak doesn't work with the current AppArmor profile (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1: apparmor: grab ns lock",
                            "      and refresh when looking up changehat child profiles",
                            "",
                            "  * AppArmor blocks write(2) to network sockets with Linux 6.19 (LP: #2141298)",
                            "    - SAUCE: apparmor5.0.0 [28/57]: apparmor: fix aa_label_sk_perm to check",
                            "      for RULE_MEDIATES_NET",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.0.0 [1/57]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.0.0 [2/57]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.0.0 [3/57]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.0.0 [4/57]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.0.0 [5/57]: Revert \"apparmor: gate make fine grained",
                            "      unix mediation behind v9 abi\"",
                            "    - SAUCE: apparmor5.0.0 [6/57]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.0.0 [7/57]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [8/57]: apparmor: lift compatibility check out of",
                            "      profile_af_perm",
                            "    - SAUCE: apparmor5.0.0 [9/57]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [10/57]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.0.0 [12/57]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.0.0 [13/57]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.0.0 [14/57]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.0.0 [15/57]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.0.0 [16/57]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.0.0 [19/57]: apparmor: prompt: setup slab cache for",
                            "      audit data",
                            "    - SAUCE: apparmor5.0.0 [20/57]: apparmor: prompt: add the ability for",
                            "      profiles to have a learning cache",
                            "    - SAUCE: apparmor5.0.0 [21/57]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "    - SAUCE: apparmor5.0.0 [22/57]: apparmor: prompt: pass prompt boolean",
                            "      through into path_name as well",
                            "    - SAUCE: apparmor5.0.0 [23/57]: apparmor: check for supported version in",
                            "      notification messages.",
                            "    - SAUCE: apparmor5.0.0 [24/57]: apparmor: refactor building notice so it",
                            "      is easier to extend",
                            "    - SAUCE: apparmor5.0.0 [25/57]: apparmor: switch from ENOTSUPP to",
                            "      EPROTONOSUPPORT",
                            "    - SAUCE: apparmor5.0.0 [26/57]: apparmor: add support for meta data tags",
                            "    - SAUCE: apparmor5.0.0 [27/57]: apparmor: prevent profile->disconnected",
                            "      double free in aa_free_profile",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.0.0 [17/57]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.0.0 [18/57]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.0.0 [11/57]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] enable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "    - [Packaging] Fix cross-builds",
                            "    - [Config] updateconfigs after v7.1 rebase",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2156849,
                            2155837,
                            2146517,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2148809,
                            2151747,
                            2151747,
                            2151747,
                            1990064,
                            2144679,
                            2142956,
                            2139664,
                            2142956,
                            2141298,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:38:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-1.1 -proposed tracker (LP: #2154256)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "",
                            "  * resolute ubuntu_kernel_selftests:seccomp_build test compilation issue",
                            "    (LP: #2154174)",
                            "    - SAUCE: selftests/seccomp fix compilation issue for amd64",
                            "",
                            "  * Kernel 6.19-rc8 does not include GPIB driver (LP: #2152714)",
                            "    - [Config] Enable CONFIG_GPIB for amd64",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.1-rc4 rebase",
                            "    - [packaging] Install gdb scripts again",
                            "    - [Config] updateconfigs after v7.1-rc5 rebase",
                            "    - [Packaging] templates: Use a for-loop for run-parts",
                            "    - [Packaging] Remove dead debian.master/rules.d/x32.mk",
                            "    - [Packaging] Remove orphaned debian/v4l2loopback-modules.ignore",
                            "    - [Packaging] Remove orphaned debian/zfs-modules.ignore",
                            "    - [Packaging] Remove deprecated linux-doc transitional stub",
                            "    - [Packaging] Remove dead comment referencing gcc-4.7 in control.stub.in",
                            "    - [Packaging] Remove dead comment in ppc64el.mk",
                            "    - [Packaging] Remove stale legacy code",
                            "    - [Packaging] rules: Drop an obsolete check for do_zstd_ko",
                            "    - [Config] toolchain version update",
                            "    - [Packaging] update Ubuntu.md",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154256,
                            1786013,
                            2154174,
                            2152714
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:08:55 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 09:59:13 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * resolute/linux: 7.0.0-15.15 -proposed tracker (LP: #2148866)",
                            "",
                            "  * Qualcomm X1E: Speaker overdrive causes hardware protection shutdown",
                            "    (LP: #2149808)",
                            "    - SAUCE: ASoC: qcom: x1e80100: limit speaker volumes",
                            "",
                            "  * intel-ipu7 / intel-ipu7-isys modules are shipped unsigned in latest",
                            "    Resolute kernels, breaking Secure Boot systems  (LP: #2148718)",
                            "    - [packaging] add intel-ipu7 to signature inclusion list",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2148866,
                            2149808,
                            2148718
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:02:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-virtual",
                "from_version": {
                    "source_package_name": "linux-meta",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": "linux-meta",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1786013,
                    1786013,
                    1786013,
                    1786013
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-5.5",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 22:11:09 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry; drop unstable suffix",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ubuntu Kernel Team <kernel-team@lists.ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 22:10:08 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-4.4",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:50:12 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-3.3",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Packaging] Add IBM transitional packages",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Thu, 13 Aug 2026 21:42:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-2.2",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:30:30 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-1.1",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:08:22 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-0.0+1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:26 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry: rename to linux-meta-unstable and bump to 7.2.0",
                            "    (major-version bootstrap for the unstable family)",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 13:14:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-5.5",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:39:50 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-4.4",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Sat, 06 Jun 2026 14:34:18 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-3.3",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Wed, 03 Jun 2026 20:13:31 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-2.2",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Wed, 03 Jun 2026 16:03:47 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-1.1",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:19:19 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:10:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.0.0-15.15",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:05:08 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "locales",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2",
                    "version": "2.43-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2.3",
                    "version": "2.43-2ubuntu2.3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: assertion failure via IBM1390 or IBM1399 charsets",
                            "    - debian/patches/CVE-2026-4046.patch: Use pending character state in",
                            "      IBM1390, IBM1399 character sets in iconvdata/Makefile,",
                            "      iconvdata/ibm1364.c, iconvdata/tst-bug33980.c.",
                            "    - CVE-2026-4046",
                            "  * SECURITY UPDATE: out-of-bounds write in deprecated debugging function",
                            "    - debian/patches/CVE-2026-5435.patch: resolv: More types as unknown in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - CVE-2026-5435",
                            "  * SECURITY UPDATE: one byte heap buffer overflow in scanf %mc",
                            "    - debian/patches/CVE-2026-5450.patch: stdio-common: Fix buffer overflow in",
                            "      scanf %mc [BZ #34008] in stdio-common/Makefile, stdio-common/tst-vfscanf-",
                            "      bz34008.c, stdio-common/vfscanf-internal.c.",
                            "    - CVE-2026-5450",
                            "  * SECURITY UPDATE: crash or info disclosure in ungetwc function",
                            "    - debian/patches/CVE-2026-5928.patch: libio: Fix ungetwc operating on byte",
                            "      stream in libio/Makefile, libio/bug-wgenops-bz33998.c, libio/wgenops.c.",
                            "    - CVE-2026-5928",
                            "  * SECURITY UPDATE: crash in deprecated debugging functions",
                            "    - debian/patches/CVE-2026-6238-pre1.patch: resolv: Declare __p_class_syms,",
                            "      __p_type_syms for internal use in include/resolv.h, resolv/res_debug.c.",
                            "    - debian/patches/CVE-2026-6238-pre2.patch: resolv: Fix ns_sprintrrf",
                            "      formatting of class, type values in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre3.patch: resolv: Improve formatting of",
                            "      unknown records in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre4.patch: resolv: Check for inet_ntop",
                            "      failure in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-1.patch: resolv: Fix buffer overreads in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-2.patch: resolv: Add test case tst-",
                            "      ns_sprintrr in resolv/Makefile, resolv/tst-ns_sprintrr.c.",
                            "    - CVE-2026-6238",
                            "  * Disable failing tests because of rust-coreutils (LP: 2161727)",
                            "    - debian/testsuite-xfail-debian.mk: added tst-spawn-chdir and",
                            "      tst-spawn-chdir-pidfd.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-2ubuntu2.3",
                        "urgency": "medium",
                        "distributions": "resolute-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Wed, 22 Jul 2026 13:24:47 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "multipath-tools",
                "from_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-2ubuntu1",
                    "version": "0.14.3-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu1",
                    "version": "0.14.3-3ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153215
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153215). Remaining changes:",
                            "    - d/rules: don't build the multipath-tools binary package on i386; only kpartx.",
                            "    - d/p/enable-find-multipaths.patch: re-enable find_multipaths by",
                            "      default -- see the removed 'add_find-multipaths.patch' (LP 1463046)",
                            "    - d/NEWS: add removal of kpartx-boot package",
                            "    - d/rules: remove -Bsymbolic-functions from LDFLAGS",
                            "    - d/rules: install friendly names multipath.conf by default",
                            "    - d/initramfs/scripts/init-top: ensure the bindings file exists before",
                            "      calling multipathd -B in the initramfs. This prevents multipathd -B from",
                            "      failing and exiting immediately (LP #2120444).",
                            "    - d/p/testsuite-no-lto: disable lto to workaround testsuite symbol wrapping (LP #2135118)",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153215
                        ],
                        "author": "Jonas Jelten <jj@ubuntu.com>",
                        "date": "Sat, 01 Aug 2026 06:13:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * [55c6f80] multipath-tools-boot: add Depends: procps for pidof",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 07 May 2026 11:35:01 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ncurses-base",
                "from_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20251231-1",
                    "version": "6.6+20251231-1"
                },
                "to_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20260608-2",
                    "version": "6.6+20260608-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Thu, 02 Jul 2026 17:00:27 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream patchlevel.",
                            "    - Add ech to screen terminfo (Closes: #707308).",
                            "  * Update symbols files.",
                            "  * Update upstream signing key.",
                            "  * Convert the watch files to version 5.",
                            "  * Update years in debian/copyright.",
                            "  * Upgrade Standards-Version to 4.7.4, no changes needed.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-1",
                        "urgency": "low",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Wed, 10 Jun 2026 17:50:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ncurses-bin",
                "from_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20251231-1",
                    "version": "6.6+20251231-1"
                },
                "to_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20260608-2",
                    "version": "6.6+20260608-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Thu, 02 Jul 2026 17:00:27 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream patchlevel.",
                            "    - Add ech to screen terminfo (Closes: #707308).",
                            "  * Update symbols files.",
                            "  * Update upstream signing key.",
                            "  * Convert the watch files to version 5.",
                            "  * Update years in debian/copyright.",
                            "  * Upgrade Standards-Version to 4.7.4, no changes needed.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-1",
                        "urgency": "low",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Wed, 10 Jun 2026 17:50:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ncurses-term",
                "from_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20251231-1",
                    "version": "6.6+20251231-1"
                },
                "to_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20260608-2",
                    "version": "6.6+20260608-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Thu, 02 Jul 2026 17:00:27 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream patchlevel.",
                            "    - Add ech to screen terminfo (Closes: #707308).",
                            "  * Update symbols files.",
                            "  * Update upstream signing key.",
                            "  * Convert the watch files to version 5.",
                            "  * Update years in debian/copyright.",
                            "  * Upgrade Standards-Version to 4.7.4, no changes needed.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-1",
                        "urgency": "low",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Wed, 10 Jun 2026 17:50:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "netplan-generator",
                "from_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.1-1ubuntu1",
                    "version": "1.2.1-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.2-1",
                    "version": "1.2.2-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153219,
                    2145061,
                    2147446,
                    2071747,
                    2139598,
                    2138802
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153219). Remaining changes:",
                            "    - Skip test_link_offloading to allow for a green baseline (LP 2126938)",
                            "      + d/p/lp-2126938-skip-test-link-offloading.patch",
                            "  * Dropped:",
                            "    - d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "      3.14 by handling BlockingIOError in addition to TypeError (LP 2138802)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "      execute udev rules before starting sriov apply service (LP 2139598)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "      (LP 2071747)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "      Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "      units. (LP 2145061)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "      networkd to apply dhcp labels to addresses (LP 2147446).",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "      permissions for files not managed by netplan in integration tests.",
                            "      [Included in Debian 1.2.1-1]",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153219
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Thu, 21 May 2026 16:24:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "    Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "    units. (LP: #2145061)",
                            "  * d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "    networkd to apply dhcp labels to addresses (LP: #2147446).",
                            "  * d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "    permissions for files not managed by netplan in integration tests.",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu5",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2145061,
                            2147446
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Wed, 08 Apr 2026 16:47:32 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "    (LP: #2071747)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2071747
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Fri, 20 Mar 2026 16:09:27 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "    execute udev rules before starting sriov apply service (LP: #2139598)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2139598
                        ],
                        "author": "Robert Malz <robert.malz@canonical.com>",
                        "date": "Tue, 03 Mar 2026 12:44:43 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "    3.14 by handling BlockingIOError in addition to TypeError (LP: #2138802)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2138802
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Fri, 20 Feb 2026 11:25:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip test_link_offloading to allow for a green baseline (LP: 2126938)",
                            "    - d/p/lp-2126938-skip-test-link-offloading.patch",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Lukas Märdian <slyon@ubuntu.com>",
                        "date": "Tue, 13 Jan 2026 17:58:24 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "netplan.io",
                "from_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.1-1ubuntu1",
                    "version": "1.2.1-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.2-1",
                    "version": "1.2.2-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153219,
                    2145061,
                    2147446,
                    2071747,
                    2139598,
                    2138802
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153219). Remaining changes:",
                            "    - Skip test_link_offloading to allow for a green baseline (LP 2126938)",
                            "      + d/p/lp-2126938-skip-test-link-offloading.patch",
                            "  * Dropped:",
                            "    - d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "      3.14 by handling BlockingIOError in addition to TypeError (LP 2138802)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "      execute udev rules before starting sriov apply service (LP 2139598)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "      (LP 2071747)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "      Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "      units. (LP 2145061)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "      networkd to apply dhcp labels to addresses (LP 2147446).",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "      permissions for files not managed by netplan in integration tests.",
                            "      [Included in Debian 1.2.1-1]",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153219
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Thu, 21 May 2026 16:24:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "    Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "    units. (LP: #2145061)",
                            "  * d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "    networkd to apply dhcp labels to addresses (LP: #2147446).",
                            "  * d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "    permissions for files not managed by netplan in integration tests.",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu5",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2145061,
                            2147446
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Wed, 08 Apr 2026 16:47:32 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "    (LP: #2071747)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2071747
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Fri, 20 Mar 2026 16:09:27 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "    execute udev rules before starting sriov apply service (LP: #2139598)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2139598
                        ],
                        "author": "Robert Malz <robert.malz@canonical.com>",
                        "date": "Tue, 03 Mar 2026 12:44:43 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "    3.14 by handling BlockingIOError in addition to TypeError (LP: #2138802)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2138802
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Fri, 20 Feb 2026 11:25:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip test_link_offloading to allow for a green baseline (LP: 2126938)",
                            "    - d/p/lp-2126938-skip-test-link-offloading.patch",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Lukas Märdian <slyon@ubuntu.com>",
                        "date": "Tue, 13 Jan 2026 17:58:24 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "open-iscsi",
                "from_version": {
                    "source_package_name": "open-iscsi",
                    "source_package_version": "2.1.11-5ubuntu1",
                    "version": "2.1.11-5ubuntu1"
                },
                "to_version": {
                    "source_package_name": "open-iscsi",
                    "source_package_version": "2.1.11-5ubuntu4",
                    "version": "2.1.11-5ubuntu4"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2157328,
                    2147499
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "open-iscsi",
                        "version": "2.1.11-5ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 11:03:00 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Recommend busybox or busybox-static on Ubuntu as well (LP: #2157328)",
                            ""
                        ],
                        "package": "open-iscsi",
                        "version": "2.1.11-5ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2157328
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Fri, 17 Jul 2026 12:29:19 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/extra/initramfs/local-top/iscsi: normalize static bootproto for",
                            "    initramfs netplan conversion. In iscsi_auto flow, firmware reports",
                            "    bootproto as STATIC, but netinfo_to_netplan handles static IPv4",
                            "    through PROTO=none with address fields. Map STATIC to PROTO=none",
                            "    and record IPV4PROTO=static in net-*.conf. (LP: #2147499)",
                            ""
                        ],
                        "package": "open-iscsi",
                        "version": "2.1.11-5ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2147499
                        ],
                        "author": "Zhang Hua <joshua.zhang@canonical.com>",
                        "date": "Thu, 11 Jun 2026 18:33:04 +0800"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "openssh-client",
                "from_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.3p1-4ubuntu1",
                    "version": "1:10.3p1-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.3p1-4ubuntu2",
                    "version": "1:10.3p1-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:01:03 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "openssh-server",
                "from_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.3p1-4ubuntu1",
                    "version": "1:10.3p1-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.3p1-4ubuntu2",
                    "version": "1:10.3p1-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:01:03 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "openssh-sftp-server",
                "from_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.3p1-4ubuntu1",
                    "version": "1:10.3p1-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.3p1-4ubuntu2",
                    "version": "1:10.3p1-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:01:03 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "openssl",
                "from_version": {
                    "source_package_name": "openssl",
                    "source_package_version": "3.5.5-1ubuntu4",
                    "version": "3.5.5-1ubuntu4"
                },
                "to_version": {
                    "source_package_name": "openssl",
                    "source_package_version": "4.0.1-1ubuntu4",
                    "version": "4.0.1-1ubuntu4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-7383",
                        "url": "https://ubuntu.com/security/CVE-2026-7383",
                        "cve_description": "Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow.  Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefined behaviour.  In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination size for Unicode output is computed in a signed int: by left shift of the input character count for BMPSTRING (UTF-16) and UNIVERSALSTRING (UTF-32), and by summing per-character byte counts for UTF8STRING. The calculation overflows when the input reaches around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30 characters) the size wraps to zero, OPENSSL_malloc(1) is called, and the subsequent character copy writes several gigabytes past the one-byte allocation.  X.509 certificate processing routes through ASN1_STRING_set_by_NID(), whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID size limits cap the input length; no network protocol or certificate-handling path in OpenSSL exercises the overflow. Triggering the bug requires an application that calls ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers a custom string type via ASN1_STRING_TABLE_add(), with attacker-controlled input on the order of half a gigabyte or more. For these reasons this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-9076",
                        "url": "https://ubuntu.com/security/CVE-2026-9076",
                        "cve_description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key().  Impact summary: A heap buffer over-read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not revealed to the attacker.  The key unwrapping function performs a check-byte test as specified in the RFC that reads 7 bytes from a heap allocation that is based on the wrapped key length from the message. There is a minimum length check based on the block length of the wrapping cipher. However the cipher is selected from an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no requirement that the cipher be a block cipher. When an attacker selects a stream-mode cipher the guard will be ineffective and the allocated buffer containing the unwrapped key can be too small to fit the check-bytes specified in the RFC and a buffer over-read can happen.  Applications calling CMS_decrypt() or CMS_decrypt_set1_password() (equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS data are vulnerable to this issue. No password knowledge is required: the over-read happens during the unwrap attempt before any authentication succeeds.  The over-read is limited to a few bytes and is not written to output, so there is no information disclosure. Triggering a crash requires the allocation to border unmapped memory, which is unlikely with the normal allocator.  The FIPS modules are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34180",
                        "url": "https://ubuntu.com/security/CVE-2026-34180",
                        "cve_description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms.  Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer.  More typically such ASN.1 elements would instead be truncated.  An integer truncation in OpenSSL's ASN.1 decoder causes the content length of an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the worst case the truncated length is treated as a request to scan the binary content for a terminating zero byte, possibly causing OpenSSL to read either less than or beyond the end of the allocated buffer.  Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or any other d2i_* decoding function are affected. OpenSSL's own command-line tools are not vulnerable, as data read through the BIO layer is checked before it reaches the affected code. The issue only affects 64-bit Unix and Unix-like platforms; 32-bit platforms and 64-bit Windows are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34181",
                        "url": "https://ubuntu.com/security/CVE-2026-34181",
                        "cve_description": "Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery.  Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability.  If a service accepting PKCS#12 files is using passwords for authenticating the received files, the attacker can create unencrypted PKCS#12 files that use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing them to craft a file that will be accepted with a 1 in 256 probability. That would then cause the service to accept a certificate and private key controlled by the attacker.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34182",
                        "url": "https://ubuntu.com/security/CVE-2026-34182",
                        "cve_description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises.  Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message.  In one use case, an attacker may send a CMS message containing AuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL erroneously allows this selection, and attempts to decrypt and validate the message.  An on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData addressed to the victim can re-emit it with the recipientInfos set left byte-for-byte intact, so the victim's private key still unwraps the genuine CEK (the content-encryption key), but with the inner OID rewritten to AES-256-OFB (Output Feedback Mode, an unauthenticated keystream mode) and with an attacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the real CEK, never consults the MAC field, and CMS_decrypt() returns success.  If the application under attack responds to the attacker with any indicator showing success or failure of the decryption effort, it is possible for the attacker to use this as an oracle to obtain key equivalent functionality for the CEK used for the chosen recipient of the message.  In another use case, an attacker can reduce the tag length of the chosen AEAD cipher for a given AuthEnvelopedData container to be a single byte long, allowing an attacker to brute force CMS decryption, producing an integrity bypass for applications that trust CMS_decrypt() to reject modified content.  The FIPS modules are not affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34183",
                        "url": "https://ubuntu.com/security/CVE-2026-34183",
                        "cve_description": "Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames.  Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service.  A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-35188",
                        "url": "https://ubuntu.com/security/CVE-2026-35188",
                        "cve_description": "Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path.  Impact summary: Successful exploitation allows an attacker to corrupt heap memory via a double-free, potentially leading to a Denial of Service or possibly an attacker controlled code execution or other undefined behavior.  If OCSP stapling is enabled and the TLS client connects to a malicious server, a crafted OCSP stapled response can trigger a double free in the TLS client when the stapled response is checked.  The OCSP stapling is not enabled by default. Reliable code execution through a double-free is technically complex and highly environment-dependent but the Denial of Service impact is straightforward to achieve, warranting Moderate severity.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42764",
                        "url": "https://ubuntu.com/security/CVE-2026-42764",
                        "cve_description": "Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled.  Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service.  If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token.  By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the default configuration not vulnerable to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with the SSL_new_listener() call, the address validation is disabled making the vulnerable code reachable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42765",
                        "url": "https://ubuntu.com/security/CVE-2026-42765",
                        "cve_description": "Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens.  This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verification. Both flags are disabled by default. For that reason, we have assigned Low severity to the issue.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42766",
                        "url": "https://ubuntu.com/security/CVE-2026-42766",
                        "cve_description": "Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as OPTIONAL in the ASN.1 specification and may therefore be absent in specially crafted inputs. During the password-based CMS decryption the OpenSSL CMS implementation dereferences this field without first checking whether it was present.  An attacker who supplies such a CMS message to an application performing password-based CMS decryption can trigger an application crash, leading to a Denial of Service.  Applications that process password-encrypted CMS messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42767",
                        "url": "https://ubuntu.com/security/CVE-2026-42767",
                        "cve_description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42768",
                        "url": "https://ubuntu.com/security/CVE-2026-42768",
                        "cve_description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output.  Impact summary: The Bleichenbacher-style attack allows an attacker to use the victim's vulnerable application as a way to decrypt or sign messages with the victim's private RSA key.  The attack is possible in 2 variants.  1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without providing the recipient certificate. In this case OpenSSL iterates over every KeyTransRecipientInfo (KTRI) without stopping at the first success.  An attacker who authors a message with two KTRI entries — the first one wrapping a real CEK under the victim's public key, the second with an arbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to get a valid PKCS#1 v1.5 padding if the error code of the application is available.  That is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an adaptive-chosen-ciphertext side channel from which the attacker decrypts any RSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under it.  2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with the recipient certificate, and the recipient is not found, a random key is substituted.  An attacker who authors a message and is able to compare both error code and the result of the decryption, can mount a Bleichenbacher oracle.  We are not aware of any applications that provide a remote attacker an opportunity to mount an attack described in these scenarios. We consider the existence of such application very unlikely, and for this reason this CVE has been evaluated as Low severity.  To avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the invoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described in draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit rejection was explicitly disabled.  The implicit rejection mechanism always returns a plaintext value, the symmetric key. This result is deterministic for the ciphertext and the private key.  The length of the decryption result can happen to match the length of the key of the symmetric cipher that was used for the content encryption. When a certificate is not provided, the last RecipientInfo producing a key that looks valid will be used. It may cause getting garbage content on decryption. As a proper way to deal with this a recipient certificate has to be provided to identify the particular RecipientInfo for decryption.  The FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as CMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42769",
                        "url": "https://ubuntu.com/security/CVE-2026-42769",
                        "cve_description": "Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level.  Impact Summary: The Registration Autority could replace the root CA certificate for the CMP clients with an arbitrary root CA certificate.  One of the parts of the Certificate Management Protocol (CMP), specified in RFC 9810, is Root Certification Authority (root CA) key Rollover, which is sent by the server in a message with type 'id-it-rootCaKeyUpdate'. As part of these messages, 'newWithOld' certificate, the new root CA certificate signed with the old root CA key, is provided, and verifying its signature is crucial for transferring the trust from the old CA key to the new one.  The 'id-it-rootCaKeyUpdate' messages are expected to be processed with OSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld' certificate.  A typo in the certificate chain building code led to adding an incorrect certificate ('newWithOld' instead of 'oldRoot') to the certificate chain, rendering the certificate verification process ineffectual (only the issuer name and the algorithm OIDs were verified by other parts of the verification code).  An attacker who already has credentials that satisfy the CMP message protection checks can generate a new key pair and use a crafted self-signed certificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP clients would accept as a new trust anchor.  Significant preconditions for the attack (having valid RA-level credentials) are the reason the issue was assigned Low severity.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42770",
                        "url": "https://ubuntu.com/security/CVE-2026-42770",
                        "cve_description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership.  Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts.  When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared.  A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack).  The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42771",
                        "url": "https://ubuntu.com/security/CVE-2026-42771",
                        "cve_description": "Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen.  Impact summary: This out of bounds read will not directly exfiltrate the data read to the attacker so the most likely result is a crash and a Denial of Service.  An internal helper function called from X509_VERIFY_PARAM_[set|add]_email() used a wrong length when validating the local part of an email address. This could cause the 64 octet limit on the local part of an email address to be not enforced, or cause an out of bound read and potentially a crash.  The bug is reachable via S-MIME validation with a crafted From: address supplied in an email message that can potentially cause a crash.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45445",
                        "url": "https://ubuntu.com/security/CVE-2026-45445",
                        "cve_description": "Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded.  Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality.  If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not on the plaintext or ciphertext, allowing universal forgery of arbitrary ciphertext from a single captured message.  OpenSSL provides two ways to drive a cipher: the documented streaming interface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level one-shot, EVP_Cipher(), whose documentation explicitly recommends against use by applications in favour of EVP_CipherUpdate() and EVP_CipherFinal_ex().  The OCB provider's streaming handler flushes the application-supplied IV into the OCB context before processing data; the one-shot handler did not.  Every call to EVP_Cipher() on an AES-OCB context therefore ran with the all-zero key-derived offset state left by cipher initialisation, regardless of the caller's IV.  If EVP_EncryptFinal_ex() is subsequently used to obtain the authentication tag, the deferred IV setup runs at that point and clears the running checksum that should have been accumulated over the plaintext.  The resulting tag is a function of (key, IV) only and verifies against any ciphertext produced under the same (key, IV) pair.  The OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a TLS cipher suite, and libssl does not call EVP_Cipher() in any case. Applications that drive AES-OCB through the documented streaming AEAD API (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only applications that combine the AES-OCB cipher with the EVP_Cipher() one-shot API are vulnerable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45446",
                        "url": "https://ubuntu.com/security/CVE-2026-45446",
                        "cve_description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages.  Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers.  AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not encrypted), and plaintext, and produces ciphertext plus a 16-byte tag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only if the tag is verified succesfully.  In OpenSSL's provider implementation of these ciphers, the expected tag is computed only when decryption function is invoked with non-empty data. If the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without invocation of the ciphertext update, which can happen when the received ciphertext length is zero, the tag is never recalculated and still holds its all-zeros value.  When AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty ciphertext, and all-zeros tag passes authentication under any key they do not know, single-shot. When AES-SIV is used, for mounting the attack it's necessary for the application to reuse the decryption context without resetting the key.  AES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since OpenSSL 3.2.  No protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support either AES-GCM-SIV or AES-SIV. To mount an attack, the applications must implement their own protocol and use the EVP interface. Also they must skip the ciphertext update when a message with an empty ciphertext arrives.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as these algorithms are not FIPS approved and the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45447",
                        "url": "https://ubuntu.com/security/CVE-2026-45447",
                        "cve_description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.  Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution.  When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition.  In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution.  Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-2673",
                        "url": "https://ubuntu.com/security/CVE-2026-2673",
                        "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-03-13 19:54:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28387",
                        "url": "https://ubuntu.com/security/CVE-2026-28387",
                        "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28388",
                        "url": "https://ubuntu.com/security/CVE-2026-28388",
                        "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28389",
                        "url": "https://ubuntu.com/security/CVE-2026-28389",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28390",
                        "url": "https://ubuntu.com/security/CVE-2026-28390",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31789",
                        "url": "https://ubuntu.com/security/CVE-2026-31789",
                        "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31790",
                        "url": "https://ubuntu.com/security/CVE-2026-31790",
                        "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-2673",
                        "url": "https://ubuntu.com/security/CVE-2026-2673",
                        "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-03-13 19:54:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28387",
                        "url": "https://ubuntu.com/security/CVE-2026-28387",
                        "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28389",
                        "url": "https://ubuntu.com/security/CVE-2026-28389",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28390",
                        "url": "https://ubuntu.com/security/CVE-2026-28390",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31789",
                        "url": "https://ubuntu.com/security/CVE-2026-31789",
                        "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31790",
                        "url": "https://ubuntu.com/security/CVE-2026-31790",
                        "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28386",
                        "url": "https://ubuntu.com/security/CVE-2026-28386",
                        "cve_description": "Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output.  The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy.  Only x86-64 systems with AVX-512 and VAES instruction support are affected. Other architectures and systems without VAES support use different code paths that are not affected.  OpenSSL FIPS module in 3.6 version is affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28388",
                        "url": "https://ubuntu.com/security/CVE-2026-28388",
                        "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-11187",
                        "url": "https://ubuntu.com/security/CVE-2025-11187",
                        "cve_description": "Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification.  Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations.  When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without validation. If the value of keylength exceeds the size of the fixed stack buffer used for the derived key (64 bytes), the key derivation will overflow the buffer. The overflow length is attacker-controlled. Also, if the salt parameter is not an OCTET STRING type this can lead to invalid or NULL pointer dereference.  Exploiting this issue requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For this reason the issue was assessed as Moderate severity.  The FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as PKCS#12 processing is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue.  OpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do not support PBMAC1 in PKCS#12.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15467",
                        "url": "https://ubuntu.com/security/CVE-2025-15467",
                        "cve_description": "Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.  Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.  When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs.  Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.  OpenSSL 1.1.1 and 1.0.2 are not affected by this issue. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15468",
                        "url": "https://ubuntu.com/security/CVE-2025-15468",
                        "cve_description": "Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.  Impact summary: A NULL pointer dereference leads to abnormal termination of the running process causing Denial of Service.  Some applications call SSL_CIPHER_find() from the client_hello_cb callback on the cipher ID received from the peer. If this is done with an SSL object implementing the QUIC protocol, NULL pointer dereference will happen if the examined cipher ID is unknown or unsupported.  As it is not very common to call this function in applications using the QUIC protocol and the worst outcome is Denial of Service, the issue was assessed as Low severity.  The vulnerable code was introduced in the 3.2 version with the addition of the QUIC protocol support.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the QUIC implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15469",
                        "url": "https://ubuntu.com/security/CVE-2025-15469",
                        "cve_description": "Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error.  Impact summary: A user signing or verifying files larger than 16MB with one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire file is authenticated while trailing data beyond 16MB remains unauthenticated.  When the 'openssl dgst' command is used with algorithms that only support one-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input is buffered with a 16MB limit. If the input exceeds this limit, the tool silently truncates to the first 16MB and continues without signaling an error, contrary to what the documentation states. This creates an integrity gap where trailing bytes can be modified without detection if both signing and verification are performed using the same affected codepath.  The issue affects only the command-line tool behavior. Verifiers that process the full message using library APIs will reject the signature, so the risk primarily affects workflows that both sign and verify with the affected 'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and library users are unaffected.  The FIPS modules in 3.5 and 3.6 are not affected by this issue, as the command-line tools are outside the OpenSSL FIPS module boundary.  OpenSSL 3.5 and 3.6 are vulnerable to this issue.  OpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-66199",
                        "url": "https://ubuntu.com/security/CVE-2025-66199",
                        "cve_description": "Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.  Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work, potentially leading to service degradation or resource exhaustion (Denial of Service).  In affected configurations, the peer-supplied uncompressed certificate length from a CompressedCertificate message is used to grow a heap buffer prior to decompression. This length is not bounded by the max_cert_list setting, which otherwise constrains certificate message sizes. An attacker can exploit this to cause large per-connection allocations followed by handshake failure. No memory corruption or information disclosure occurs.  This issue only affects builds where TLS 1.3 certificate compression is compiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression algorithm (brotli, zlib, or zstd) is available, and where the compression extension is negotiated. Both clients receiving a server CompressedCertificate and servers in mutual TLS scenarios receiving a client CompressedCertificate are affected. Servers that do not request client certificates are not vulnerable to client-initiated attacks.  Users can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION to disable receiving compressed certificates.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the TLS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-68160",
                        "url": "https://ubuntu.com/security/CVE-2025-68160",
                        "cve_description": "Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.  Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application.  The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69418",
                        "url": "https://ubuntu.com/security/CVE-2025-69418",
                        "cve_description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69419",
                        "url": "https://ubuntu.com/security/CVE-2025-69419",
                        "cve_description": "Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.  Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service.  The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer.  The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer. The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69420",
                        "url": "https://ubuntu.com/security/CVE-2025-69420",
                        "cve_description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.  Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69421",
                        "url": "https://ubuntu.com/security/CVE-2025-69421",
                        "cve_description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.  Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files.  The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure.  Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-22795",
                        "url": "https://ubuntu.com/security/CVE-2026-22795",
                        "cve_description": "Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.  Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service.  A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read.  The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-22796",
                        "url": "https://ubuntu.com/security/CVE-2026-22796",
                        "cve_description": "Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.  Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163146,
                    2158026,
                    2158026,
                    2160606,
                    2147669,
                    2153135
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/default-configuration-read-dropins-and-crypto-config.patch:",
                            "    partially restore patch, needed by src:crypto-policies",
                            "    (LP: #2163146)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163146
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 12 Aug 2026 15:20:38 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert \"Add Depends on libjitterentropy3-dev, zlib1g-dev, and libzstd-dev.",
                            "    (LP: #2158026)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158026
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Mon, 10 Aug 2026 11:49:51 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add Depends on libjitterentropy3-dev, zlib1g-dev, and libzstd-dev.",
                            "    libcrypto.pc declares these as static private dependencies",
                            "    (Libs.private) but libssl-dev did not pull them in, breaking static",
                            "    linking against libcrypto. (LP: #2158026)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158026
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Mon, 03 Aug 2026 16:49:15 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Ravi Kant Sharma ]",
                            "  * Merge with Debian experimental (LP: #2160606). Remaining changes:",
                            "    - Use perl:native in the autopkgtest for installability on i386.",
                            "    - Symlink copyright/changelog.Debian.gz in libssl3* to libssl-dev/openssl",
                            "    - Disable LTO with which the codebase is generally incompatible",
                            "      (LP #2058017)",
                            "    - Don't enable or package anything FIPS (LP #2087955)",
                            "    - Match last filename for output in ecp_nistp521-ppc64.pl (LP #2137464)",
                            "    - Enable CPU jitter fluctuations",
                            "    - fips patches (debian/patches/fips):",
                            "      - crypto: Add kernel FIPS mode detection",
                            "      - crypto: Automatically use the FIPS provider...",
                            "      - apps/speed: Omit unavailable algorithms in FIPS mode",
                            "      - apps: pass -propquery arg to the libctx DRBG fetches",
                            "      - test: Ensure encoding runs with the correct context...",
                            "      - Add Ubuntu-specific defines to help FIPS certification (LP #2073991)",
                            "        + UBUNTU_OSSL_SELF_TEST_DESC_PCT_DH",
                            "        + UBUNTU_OSSL_PROV_FIPS_PARAM_UNAPPROVED_USAGE",
                            "      - Detect FIPS jitterentropy mode and load jitterentropy enabled FIPS",
                            "        provider",
                            "      - Fallback to default provider when FIPS provider is missing.",
                            "  * Dropped patches, not required anymore in Ubuntu",
                            "    - d/p/default-configuration-read-dropins-and-crypto-config.patch",
                            "",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160606
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Tue, 14 Jul 2026 12:53:05 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-7383",
                                "url": "https://ubuntu.com/security/CVE-2026-7383",
                                "cve_description": "Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow.  Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefined behaviour.  In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination size for Unicode output is computed in a signed int: by left shift of the input character count for BMPSTRING (UTF-16) and UNIVERSALSTRING (UTF-32), and by summing per-character byte counts for UTF8STRING. The calculation overflows when the input reaches around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30 characters) the size wraps to zero, OPENSSL_malloc(1) is called, and the subsequent character copy writes several gigabytes past the one-byte allocation.  X.509 certificate processing routes through ASN1_STRING_set_by_NID(), whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID size limits cap the input length; no network protocol or certificate-handling path in OpenSSL exercises the overflow. Triggering the bug requires an application that calls ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers a custom string type via ASN1_STRING_TABLE_add(), with attacker-controlled input on the order of half a gigabyte or more. For these reasons this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-9076",
                                "url": "https://ubuntu.com/security/CVE-2026-9076",
                                "cve_description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key().  Impact summary: A heap buffer over-read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not revealed to the attacker.  The key unwrapping function performs a check-byte test as specified in the RFC that reads 7 bytes from a heap allocation that is based on the wrapped key length from the message. There is a minimum length check based on the block length of the wrapping cipher. However the cipher is selected from an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no requirement that the cipher be a block cipher. When an attacker selects a stream-mode cipher the guard will be ineffective and the allocated buffer containing the unwrapped key can be too small to fit the check-bytes specified in the RFC and a buffer over-read can happen.  Applications calling CMS_decrypt() or CMS_decrypt_set1_password() (equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS data are vulnerable to this issue. No password knowledge is required: the over-read happens during the unwrap attempt before any authentication succeeds.  The over-read is limited to a few bytes and is not written to output, so there is no information disclosure. Triggering a crash requires the allocation to border unmapped memory, which is unlikely with the normal allocator.  The FIPS modules are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34180",
                                "url": "https://ubuntu.com/security/CVE-2026-34180",
                                "cve_description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms.  Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer.  More typically such ASN.1 elements would instead be truncated.  An integer truncation in OpenSSL's ASN.1 decoder causes the content length of an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the worst case the truncated length is treated as a request to scan the binary content for a terminating zero byte, possibly causing OpenSSL to read either less than or beyond the end of the allocated buffer.  Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or any other d2i_* decoding function are affected. OpenSSL's own command-line tools are not vulnerable, as data read through the BIO layer is checked before it reaches the affected code. The issue only affects 64-bit Unix and Unix-like platforms; 32-bit platforms and 64-bit Windows are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34181",
                                "url": "https://ubuntu.com/security/CVE-2026-34181",
                                "cve_description": "Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery.  Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability.  If a service accepting PKCS#12 files is using passwords for authenticating the received files, the attacker can create unencrypted PKCS#12 files that use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing them to craft a file that will be accepted with a 1 in 256 probability. That would then cause the service to accept a certificate and private key controlled by the attacker.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34182",
                                "url": "https://ubuntu.com/security/CVE-2026-34182",
                                "cve_description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises.  Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message.  In one use case, an attacker may send a CMS message containing AuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL erroneously allows this selection, and attempts to decrypt and validate the message.  An on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData addressed to the victim can re-emit it with the recipientInfos set left byte-for-byte intact, so the victim's private key still unwraps the genuine CEK (the content-encryption key), but with the inner OID rewritten to AES-256-OFB (Output Feedback Mode, an unauthenticated keystream mode) and with an attacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the real CEK, never consults the MAC field, and CMS_decrypt() returns success.  If the application under attack responds to the attacker with any indicator showing success or failure of the decryption effort, it is possible for the attacker to use this as an oracle to obtain key equivalent functionality for the CEK used for the chosen recipient of the message.  In another use case, an attacker can reduce the tag length of the chosen AEAD cipher for a given AuthEnvelopedData container to be a single byte long, allowing an attacker to brute force CMS decryption, producing an integrity bypass for applications that trust CMS_decrypt() to reject modified content.  The FIPS modules are not affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34183",
                                "url": "https://ubuntu.com/security/CVE-2026-34183",
                                "cve_description": "Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames.  Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service.  A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-35188",
                                "url": "https://ubuntu.com/security/CVE-2026-35188",
                                "cve_description": "Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path.  Impact summary: Successful exploitation allows an attacker to corrupt heap memory via a double-free, potentially leading to a Denial of Service or possibly an attacker controlled code execution or other undefined behavior.  If OCSP stapling is enabled and the TLS client connects to a malicious server, a crafted OCSP stapled response can trigger a double free in the TLS client when the stapled response is checked.  The OCSP stapling is not enabled by default. Reliable code execution through a double-free is technically complex and highly environment-dependent but the Denial of Service impact is straightforward to achieve, warranting Moderate severity.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42764",
                                "url": "https://ubuntu.com/security/CVE-2026-42764",
                                "cve_description": "Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled.  Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service.  If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token.  By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the default configuration not vulnerable to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with the SSL_new_listener() call, the address validation is disabled making the vulnerable code reachable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42765",
                                "url": "https://ubuntu.com/security/CVE-2026-42765",
                                "cve_description": "Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens.  This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verification. Both flags are disabled by default. For that reason, we have assigned Low severity to the issue.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42766",
                                "url": "https://ubuntu.com/security/CVE-2026-42766",
                                "cve_description": "Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as OPTIONAL in the ASN.1 specification and may therefore be absent in specially crafted inputs. During the password-based CMS decryption the OpenSSL CMS implementation dereferences this field without first checking whether it was present.  An attacker who supplies such a CMS message to an application performing password-based CMS decryption can trigger an application crash, leading to a Denial of Service.  Applications that process password-encrypted CMS messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42767",
                                "url": "https://ubuntu.com/security/CVE-2026-42767",
                                "cve_description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42768",
                                "url": "https://ubuntu.com/security/CVE-2026-42768",
                                "cve_description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output.  Impact summary: The Bleichenbacher-style attack allows an attacker to use the victim's vulnerable application as a way to decrypt or sign messages with the victim's private RSA key.  The attack is possible in 2 variants.  1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without providing the recipient certificate. In this case OpenSSL iterates over every KeyTransRecipientInfo (KTRI) without stopping at the first success.  An attacker who authors a message with two KTRI entries — the first one wrapping a real CEK under the victim's public key, the second with an arbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to get a valid PKCS#1 v1.5 padding if the error code of the application is available.  That is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an adaptive-chosen-ciphertext side channel from which the attacker decrypts any RSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under it.  2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with the recipient certificate, and the recipient is not found, a random key is substituted.  An attacker who authors a message and is able to compare both error code and the result of the decryption, can mount a Bleichenbacher oracle.  We are not aware of any applications that provide a remote attacker an opportunity to mount an attack described in these scenarios. We consider the existence of such application very unlikely, and for this reason this CVE has been evaluated as Low severity.  To avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the invoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described in draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit rejection was explicitly disabled.  The implicit rejection mechanism always returns a plaintext value, the symmetric key. This result is deterministic for the ciphertext and the private key.  The length of the decryption result can happen to match the length of the key of the symmetric cipher that was used for the content encryption. When a certificate is not provided, the last RecipientInfo producing a key that looks valid will be used. It may cause getting garbage content on decryption. As a proper way to deal with this a recipient certificate has to be provided to identify the particular RecipientInfo for decryption.  The FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as CMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42769",
                                "url": "https://ubuntu.com/security/CVE-2026-42769",
                                "cve_description": "Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level.  Impact Summary: The Registration Autority could replace the root CA certificate for the CMP clients with an arbitrary root CA certificate.  One of the parts of the Certificate Management Protocol (CMP), specified in RFC 9810, is Root Certification Authority (root CA) key Rollover, which is sent by the server in a message with type 'id-it-rootCaKeyUpdate'. As part of these messages, 'newWithOld' certificate, the new root CA certificate signed with the old root CA key, is provided, and verifying its signature is crucial for transferring the trust from the old CA key to the new one.  The 'id-it-rootCaKeyUpdate' messages are expected to be processed with OSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld' certificate.  A typo in the certificate chain building code led to adding an incorrect certificate ('newWithOld' instead of 'oldRoot') to the certificate chain, rendering the certificate verification process ineffectual (only the issuer name and the algorithm OIDs were verified by other parts of the verification code).  An attacker who already has credentials that satisfy the CMP message protection checks can generate a new key pair and use a crafted self-signed certificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP clients would accept as a new trust anchor.  Significant preconditions for the attack (having valid RA-level credentials) are the reason the issue was assigned Low severity.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42770",
                                "url": "https://ubuntu.com/security/CVE-2026-42770",
                                "cve_description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership.  Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts.  When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared.  A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack).  The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42771",
                                "url": "https://ubuntu.com/security/CVE-2026-42771",
                                "cve_description": "Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen.  Impact summary: This out of bounds read will not directly exfiltrate the data read to the attacker so the most likely result is a crash and a Denial of Service.  An internal helper function called from X509_VERIFY_PARAM_[set|add]_email() used a wrong length when validating the local part of an email address. This could cause the 64 octet limit on the local part of an email address to be not enforced, or cause an out of bound read and potentially a crash.  The bug is reachable via S-MIME validation with a crafted From: address supplied in an email message that can potentially cause a crash.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45445",
                                "url": "https://ubuntu.com/security/CVE-2026-45445",
                                "cve_description": "Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded.  Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality.  If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not on the plaintext or ciphertext, allowing universal forgery of arbitrary ciphertext from a single captured message.  OpenSSL provides two ways to drive a cipher: the documented streaming interface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level one-shot, EVP_Cipher(), whose documentation explicitly recommends against use by applications in favour of EVP_CipherUpdate() and EVP_CipherFinal_ex().  The OCB provider's streaming handler flushes the application-supplied IV into the OCB context before processing data; the one-shot handler did not.  Every call to EVP_Cipher() on an AES-OCB context therefore ran with the all-zero key-derived offset state left by cipher initialisation, regardless of the caller's IV.  If EVP_EncryptFinal_ex() is subsequently used to obtain the authentication tag, the deferred IV setup runs at that point and clears the running checksum that should have been accumulated over the plaintext.  The resulting tag is a function of (key, IV) only and verifies against any ciphertext produced under the same (key, IV) pair.  The OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a TLS cipher suite, and libssl does not call EVP_Cipher() in any case. Applications that drive AES-OCB through the documented streaming AEAD API (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only applications that combine the AES-OCB cipher with the EVP_Cipher() one-shot API are vulnerable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45446",
                                "url": "https://ubuntu.com/security/CVE-2026-45446",
                                "cve_description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages.  Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers.  AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not encrypted), and plaintext, and produces ciphertext plus a 16-byte tag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only if the tag is verified succesfully.  In OpenSSL's provider implementation of these ciphers, the expected tag is computed only when decryption function is invoked with non-empty data. If the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without invocation of the ciphertext update, which can happen when the received ciphertext length is zero, the tag is never recalculated and still holds its all-zeros value.  When AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty ciphertext, and all-zeros tag passes authentication under any key they do not know, single-shot. When AES-SIV is used, for mounting the attack it's necessary for the application to reuse the decryption context without resetting the key.  AES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since OpenSSL 3.2.  No protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support either AES-GCM-SIV or AES-SIV. To mount an attack, the applications must implement their own protocol and use the EVP interface. Also they must skip the ciphertext update when a message with an empty ciphertext arrives.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as these algorithms are not FIPS approved and the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45447",
                                "url": "https://ubuntu.com/security/CVE-2026-45447",
                                "cve_description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.  Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution.  When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition.  In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution.  Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Import 4.0.1",
                            "   - CVE-2026-7383 (\"Possible Heap Buffer Overflow in ASN.1 Multibyte String",
                            "     Conversion\")",
                            "   - CVE-2026-9076 (\"Out-of-Bounds Read in CMS Password-Based Decryption\")",
                            "   - CVE-2026-34180 (\"Heap Buffer Over-read in ASN.1 Content Parsing\")",
                            "   - CVE-2026-34181 (\"PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC",
                            "     Keys\")",
                            "   - CVE-2026-34182 (\"CMS AuthEnvelopedData Processing May Accept Forged",
                            "     Messages\")",
                            "   - CVE-2026-34183 (\"Unbounded Memory Growth in the QUIC PATH_CHALLENGE",
                            "     Handler\")",
                            "   - CVE-2026-35188 (\"Double-free When Checking OCSP Stapled Response\")",
                            "   - CVE-2026-42764 (\"NULL pointer dereference in QUIC server initial packet",
                            "     handling\")",
                            "   - CVE-2026-42765 (\"NULL Dereference in Certificate Verification with OCSP",
                            "     Checking\")",
                            "   - CVE-2026-42766 (\"Possible NULL Dereference in Password-Based CMS",
                            "     Decryption\")",
                            "   - CVE-2026-42767 (\"NULL Pointer Dereference in CRMF EncryptedValue",
                            "     Decryption\")",
                            "   - CVE-2026-42768 (\"Multi-RecipientInfo Bleichenbacher Oracle in",
                            "     CMS_decrypt() and PKCS7_decrypt()\")",
                            "   - CVE-2026-42769 (\"Trust-Anchor Substitution via cert/issuer Typo in CMP",
                            "     rootCaKeyUpdate\")",
                            "   - CVE-2026-42770 (\"FFC-DH Peer Validation Uses Attacker-Supplied q\")",
                            "   - CVE-2026-42771 (\"Possible Out of Bounds Read in",
                            "     X509_VERIFY_PARAM_set1_email()\")",
                            "   - CVE-2026-45445 (\"AES-OCB IV Ignored on EVP_Cipher() Path\")",
                            "   - CVE-2026-45446 (\"Incorrect Tag Processing for Empty Messages in",
                            "     AES-GCM-SIV and AES-SIV modes\")",
                            "   - CVE-2026-45447 (\"Heap Use-After-Free in OpenSSL PKCS7_verify()\")",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Sat, 13 Jun 2026 20:01:42 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-2673",
                                "url": "https://ubuntu.com/security/CVE-2026-2673",
                                "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-03-13 19:54:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28387",
                                "url": "https://ubuntu.com/security/CVE-2026-28387",
                                "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28388",
                                "url": "https://ubuntu.com/security/CVE-2026-28388",
                                "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28389",
                                "url": "https://ubuntu.com/security/CVE-2026-28389",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28390",
                                "url": "https://ubuntu.com/security/CVE-2026-28390",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31789",
                                "url": "https://ubuntu.com/security/CVE-2026-31789",
                                "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31790",
                                "url": "https://ubuntu.com/security/CVE-2026-31790",
                                "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Eric Berry ]",
                            "  * OpenSSL crashes in resolute when userspace entropy",
                            "    is enabled but fips provider is not installed (LP: #2147669)",
                            "",
                            "  [ Ravi Kant Sharma ]",
                            "  * Merge with Debian experimental (LP: #2153135). Remaining changes:",
                            "    - Use perl:native in the autopkgtest for installability on i386.",
                            "    - Symlink copyright/changelog.Debian.gz in libssl3* to libssl-dev/openssl",
                            "    - Disable LTO with which the codebase is generally incompatible",
                            "      (LP #2058017)",
                            "    - Default config reads crypto-config and /etc/ssl/openssl.cnf.d dropins",
                            "    - Don't enable or package anything FIPS (LP #2087955)",
                            "    - Match last filename for output in ecp_nistp521-ppc64.pl (LP #2137464)",
                            "    - Enable CPU jitter fluctuations",
                            "    - fips patches (debian/patches/fips):",
                            "      - crypto: Add kernel FIPS mode detection",
                            "      - crypto: Automatically use the FIPS provider...",
                            "      - apps/speed: Omit unavailable algorithms in FIPS mode",
                            "      - apps: pass -propquery arg to the libctx DRBG fetches",
                            "      - test: Ensure encoding runs with the correct context...",
                            "      - Add Ubuntu-specific defines to help FIPS certification (LP #2073991)",
                            "        + UBUNTU_OSSL_SELF_TEST_DESC_PCT_DH",
                            "        + UBUNTU_OSSL_PROV_FIPS_PARAM_UNAPPROVED_USAGE",
                            "      - Detect FIPS jitterentropy mode and load jitterentropy enabled FIPS",
                            "        provider",
                            "      - Fallback to default provider when FIPS provider is missing.",
                            "  * Refreshed patches",
                            "    - fips/apps-speed-Omit-unavailable-algorithms-in-FIPS-mode.patch",
                            "    - fips/crypto-Add-kernel-FIPS-mode-detection.patch",
                            "    - fips/crypto-add-userspace-fips-mode-detection.patch",
                            "    - fips/crypto-Automatically-use-the-FIPS-provider-when-the-kerne.patch",
                            "  * Dropped patches, merged upstream",
                            "    - CVE-2026-2673.patch",
                            "    - CVE-2026-28387.patch",
                            "    - CVE-2026-28388-1.patch",
                            "    - CVE-2026-28388-2.patch",
                            "    - CVE-2026-28389.patch",
                            "    - CVE-2026-28390.patch",
                            "    - CVE-2026-31789.patch",
                            "    - CVE-2026-31790-1.patch",
                            "    - CVE-2026-31790-2.patch",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2147669,
                            2153135
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Wed, 20 May 2026 12:14:25 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-2673",
                                "url": "https://ubuntu.com/security/CVE-2026-2673",
                                "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-03-13 19:54:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28387",
                                "url": "https://ubuntu.com/security/CVE-2026-28387",
                                "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28389",
                                "url": "https://ubuntu.com/security/CVE-2026-28389",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28390",
                                "url": "https://ubuntu.com/security/CVE-2026-28390",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31789",
                                "url": "https://ubuntu.com/security/CVE-2026-31789",
                                "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31790",
                                "url": "https://ubuntu.com/security/CVE-2026-31790",
                                "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28386",
                                "url": "https://ubuntu.com/security/CVE-2026-28386",
                                "cve_description": "Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output.  The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy.  Only x86-64 systems with AVX-512 and VAES instruction support are affected. Other architectures and systems without VAES support use different code paths that are not affected.  OpenSSL FIPS module in 3.6 version is affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28388",
                                "url": "https://ubuntu.com/security/CVE-2026-28388",
                                "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Import 4.0.0",
                            "    - CVE-2026-2673 (\"OpenSSL TLS 1.3 server may choose unexpected key agreement",
                            "      group\") (Closes: #1130650).",
                            "    - CVE-2026-28387 (\"Potential use-after-free in DANE client code\")",
                            "    - CVE-2026-28389 (\"Possible NULL dereference when processing CMS",
                            "      KeyAgreeRecipientInfo\")",
                            "    - CVE-2026-28390 (\"Possible NULL dereference when processing CMS",
                            "      KeyTransportRecipient Info\")",
                            "    - CVE-2026-31789 (\"Heap buffer overflow in hexadecimal conversion\")",
                            "    - CVE-2026-31790 (\"Incorrect failure handling in RSA KEM RSASVE",
                            "      encapsulation\")",
                            "    - CVE-2026-28386 (\"Out-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512",
                            "      Support\")",
                            "    - CVE-2026-28388 (\"NULL Pointer Dereference When Processing a Delta CRL\")",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 16 Apr 2026 20:31:23 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 4.0.0-beta1",
                            "  * Add musl targets (Closes: #1131164).",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0~beta1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 26 Mar 2026 22:34:26 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 4.0.0-alpha1 (Closes: #1126531).",
                            "  * Update Standards-Version.",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0~alpha1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Fri, 13 Mar 2026 18:16:34 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 12 Mar 2026 21:00:23 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2025-11187",
                                "url": "https://ubuntu.com/security/CVE-2025-11187",
                                "cve_description": "Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification.  Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations.  When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without validation. If the value of keylength exceeds the size of the fixed stack buffer used for the derived key (64 bytes), the key derivation will overflow the buffer. The overflow length is attacker-controlled. Also, if the salt parameter is not an OCTET STRING type this can lead to invalid or NULL pointer dereference.  Exploiting this issue requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For this reason the issue was assessed as Moderate severity.  The FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as PKCS#12 processing is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue.  OpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do not support PBMAC1 in PKCS#12.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-15467",
                                "url": "https://ubuntu.com/security/CVE-2025-15467",
                                "cve_description": "Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.  Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.  When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs.  Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.  OpenSSL 1.1.1 and 1.0.2 are not affected by this issue. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-15468",
                                "url": "https://ubuntu.com/security/CVE-2025-15468",
                                "cve_description": "Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.  Impact summary: A NULL pointer dereference leads to abnormal termination of the running process causing Denial of Service.  Some applications call SSL_CIPHER_find() from the client_hello_cb callback on the cipher ID received from the peer. If this is done with an SSL object implementing the QUIC protocol, NULL pointer dereference will happen if the examined cipher ID is unknown or unsupported.  As it is not very common to call this function in applications using the QUIC protocol and the worst outcome is Denial of Service, the issue was assessed as Low severity.  The vulnerable code was introduced in the 3.2 version with the addition of the QUIC protocol support.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the QUIC implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-15469",
                                "url": "https://ubuntu.com/security/CVE-2025-15469",
                                "cve_description": "Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error.  Impact summary: A user signing or verifying files larger than 16MB with one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire file is authenticated while trailing data beyond 16MB remains unauthenticated.  When the 'openssl dgst' command is used with algorithms that only support one-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input is buffered with a 16MB limit. If the input exceeds this limit, the tool silently truncates to the first 16MB and continues without signaling an error, contrary to what the documentation states. This creates an integrity gap where trailing bytes can be modified without detection if both signing and verification are performed using the same affected codepath.  The issue affects only the command-line tool behavior. Verifiers that process the full message using library APIs will reject the signature, so the risk primarily affects workflows that both sign and verify with the affected 'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and library users are unaffected.  The FIPS modules in 3.5 and 3.6 are not affected by this issue, as the command-line tools are outside the OpenSSL FIPS module boundary.  OpenSSL 3.5 and 3.6 are vulnerable to this issue.  OpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-66199",
                                "url": "https://ubuntu.com/security/CVE-2025-66199",
                                "cve_description": "Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.  Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work, potentially leading to service degradation or resource exhaustion (Denial of Service).  In affected configurations, the peer-supplied uncompressed certificate length from a CompressedCertificate message is used to grow a heap buffer prior to decompression. This length is not bounded by the max_cert_list setting, which otherwise constrains certificate message sizes. An attacker can exploit this to cause large per-connection allocations followed by handshake failure. No memory corruption or information disclosure occurs.  This issue only affects builds where TLS 1.3 certificate compression is compiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression algorithm (brotli, zlib, or zstd) is available, and where the compression extension is negotiated. Both clients receiving a server CompressedCertificate and servers in mutual TLS scenarios receiving a client CompressedCertificate are affected. Servers that do not request client certificates are not vulnerable to client-initiated attacks.  Users can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION to disable receiving compressed certificates.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the TLS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-68160",
                                "url": "https://ubuntu.com/security/CVE-2025-68160",
                                "cve_description": "Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.  Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application.  The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69418",
                                "url": "https://ubuntu.com/security/CVE-2025-69418",
                                "cve_description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69419",
                                "url": "https://ubuntu.com/security/CVE-2025-69419",
                                "cve_description": "Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.  Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service.  The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer.  The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer. The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69420",
                                "url": "https://ubuntu.com/security/CVE-2025-69420",
                                "cve_description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.  Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69421",
                                "url": "https://ubuntu.com/security/CVE-2025-69421",
                                "cve_description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.  Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files.  The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure.  Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-22795",
                                "url": "https://ubuntu.com/security/CVE-2026-22795",
                                "cve_description": "Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.  Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service.  A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read.  The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-22796",
                                "url": "https://ubuntu.com/security/CVE-2026-22796",
                                "cve_description": "Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.  Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Import 3.6.1",
                            "   - CVE-2025-11187 (Improper validation of PBMAC1 parameters in PKCS#12 MAC",
                            "     verification)",
                            "   - CVE-2025-15467 (Stack buffer overflow in CMS AuthEnvelopedData parsing)",
                            "   - CVE-2025-15468 (NULL dereference in SSL_CIPHER_find() function on unknown",
                            "     cipher ID)",
                            "   - CVE-2025-15469 (\"openssl dgst\" one-shot codepath silently truncates inputs",
                            "     >16MB)",
                            "   - CVE-2025-66199 (TLS 1.3 CompressedCertificate excessive memory allocation)",
                            "   - CVE-2025-68160 (Heap out-of-bounds write in BIO_f_linebuffer on short",
                            "     writes)",
                            "   - CVE-2025-69418 (Unauthenticated/unencrypted trailing bytes with low-level",
                            "     OCB function calls)",
                            "   - CVE-2025-69419 (Out of bounds write in PKCS12_get_friendlyname() UTF-8",
                            "     conversion)",
                            "   - CVE-2025-69420 (Missing ASN1_TYPE validation in TS_RESP_verify_response()",
                            "     function)",
                            "   - CVE-2025-69421 (NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex",
                            "     function)",
                            "   - CVE-2026-22795 (Missing ASN1_TYPE validation in PKCS#12 parsing)",
                            "   - CVE-2026-22796 (ASN1_TYPE Type Confusion in the",
                            "   - PKCS7_digest_from_attributes() function)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Tue, 27 Jan 2026 21:32:02 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Apply fix for upstream issue #28902",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Fri, 26 Dec 2025 17:01:03 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 3.6.0",
                            "  * Stop shipping c_rehash. It bas been long replaced by \"openssl rehash\"",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Fri, 03 Oct 2025 17:40:10 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 3.6.0-beta1",
                            "  * Drop pic & Bsymbolic patches. This shouldn't be needed anymore.",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0~~beta1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 18 Sep 2025 21:36:20 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 3.6.0-alpha1",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0~~alpha1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Sat, 06 Sep 2025 20:21:28 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "openssl-provider-legacy",
                "from_version": {
                    "source_package_name": "openssl",
                    "source_package_version": "3.5.5-1ubuntu4",
                    "version": "3.5.5-1ubuntu4"
                },
                "to_version": {
                    "source_package_name": "openssl",
                    "source_package_version": "4.0.1-1ubuntu4",
                    "version": "4.0.1-1ubuntu4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-7383",
                        "url": "https://ubuntu.com/security/CVE-2026-7383",
                        "cve_description": "Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow.  Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefined behaviour.  In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination size for Unicode output is computed in a signed int: by left shift of the input character count for BMPSTRING (UTF-16) and UNIVERSALSTRING (UTF-32), and by summing per-character byte counts for UTF8STRING. The calculation overflows when the input reaches around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30 characters) the size wraps to zero, OPENSSL_malloc(1) is called, and the subsequent character copy writes several gigabytes past the one-byte allocation.  X.509 certificate processing routes through ASN1_STRING_set_by_NID(), whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID size limits cap the input length; no network protocol or certificate-handling path in OpenSSL exercises the overflow. Triggering the bug requires an application that calls ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers a custom string type via ASN1_STRING_TABLE_add(), with attacker-controlled input on the order of half a gigabyte or more. For these reasons this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-9076",
                        "url": "https://ubuntu.com/security/CVE-2026-9076",
                        "cve_description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key().  Impact summary: A heap buffer over-read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not revealed to the attacker.  The key unwrapping function performs a check-byte test as specified in the RFC that reads 7 bytes from a heap allocation that is based on the wrapped key length from the message. There is a minimum length check based on the block length of the wrapping cipher. However the cipher is selected from an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no requirement that the cipher be a block cipher. When an attacker selects a stream-mode cipher the guard will be ineffective and the allocated buffer containing the unwrapped key can be too small to fit the check-bytes specified in the RFC and a buffer over-read can happen.  Applications calling CMS_decrypt() or CMS_decrypt_set1_password() (equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS data are vulnerable to this issue. No password knowledge is required: the over-read happens during the unwrap attempt before any authentication succeeds.  The over-read is limited to a few bytes and is not written to output, so there is no information disclosure. Triggering a crash requires the allocation to border unmapped memory, which is unlikely with the normal allocator.  The FIPS modules are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34180",
                        "url": "https://ubuntu.com/security/CVE-2026-34180",
                        "cve_description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms.  Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer.  More typically such ASN.1 elements would instead be truncated.  An integer truncation in OpenSSL's ASN.1 decoder causes the content length of an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the worst case the truncated length is treated as a request to scan the binary content for a terminating zero byte, possibly causing OpenSSL to read either less than or beyond the end of the allocated buffer.  Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or any other d2i_* decoding function are affected. OpenSSL's own command-line tools are not vulnerable, as data read through the BIO layer is checked before it reaches the affected code. The issue only affects 64-bit Unix and Unix-like platforms; 32-bit platforms and 64-bit Windows are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34181",
                        "url": "https://ubuntu.com/security/CVE-2026-34181",
                        "cve_description": "Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery.  Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability.  If a service accepting PKCS#12 files is using passwords for authenticating the received files, the attacker can create unencrypted PKCS#12 files that use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing them to craft a file that will be accepted with a 1 in 256 probability. That would then cause the service to accept a certificate and private key controlled by the attacker.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34182",
                        "url": "https://ubuntu.com/security/CVE-2026-34182",
                        "cve_description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises.  Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message.  In one use case, an attacker may send a CMS message containing AuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL erroneously allows this selection, and attempts to decrypt and validate the message.  An on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData addressed to the victim can re-emit it with the recipientInfos set left byte-for-byte intact, so the victim's private key still unwraps the genuine CEK (the content-encryption key), but with the inner OID rewritten to AES-256-OFB (Output Feedback Mode, an unauthenticated keystream mode) and with an attacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the real CEK, never consults the MAC field, and CMS_decrypt() returns success.  If the application under attack responds to the attacker with any indicator showing success or failure of the decryption effort, it is possible for the attacker to use this as an oracle to obtain key equivalent functionality for the CEK used for the chosen recipient of the message.  In another use case, an attacker can reduce the tag length of the chosen AEAD cipher for a given AuthEnvelopedData container to be a single byte long, allowing an attacker to brute force CMS decryption, producing an integrity bypass for applications that trust CMS_decrypt() to reject modified content.  The FIPS modules are not affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34183",
                        "url": "https://ubuntu.com/security/CVE-2026-34183",
                        "cve_description": "Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames.  Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service.  A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-35188",
                        "url": "https://ubuntu.com/security/CVE-2026-35188",
                        "cve_description": "Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path.  Impact summary: Successful exploitation allows an attacker to corrupt heap memory via a double-free, potentially leading to a Denial of Service or possibly an attacker controlled code execution or other undefined behavior.  If OCSP stapling is enabled and the TLS client connects to a malicious server, a crafted OCSP stapled response can trigger a double free in the TLS client when the stapled response is checked.  The OCSP stapling is not enabled by default. Reliable code execution through a double-free is technically complex and highly environment-dependent but the Denial of Service impact is straightforward to achieve, warranting Moderate severity.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42764",
                        "url": "https://ubuntu.com/security/CVE-2026-42764",
                        "cve_description": "Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled.  Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service.  If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token.  By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the default configuration not vulnerable to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with the SSL_new_listener() call, the address validation is disabled making the vulnerable code reachable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42765",
                        "url": "https://ubuntu.com/security/CVE-2026-42765",
                        "cve_description": "Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens.  This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verification. Both flags are disabled by default. For that reason, we have assigned Low severity to the issue.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42766",
                        "url": "https://ubuntu.com/security/CVE-2026-42766",
                        "cve_description": "Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as OPTIONAL in the ASN.1 specification and may therefore be absent in specially crafted inputs. During the password-based CMS decryption the OpenSSL CMS implementation dereferences this field without first checking whether it was present.  An attacker who supplies such a CMS message to an application performing password-based CMS decryption can trigger an application crash, leading to a Denial of Service.  Applications that process password-encrypted CMS messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42767",
                        "url": "https://ubuntu.com/security/CVE-2026-42767",
                        "cve_description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42768",
                        "url": "https://ubuntu.com/security/CVE-2026-42768",
                        "cve_description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output.  Impact summary: The Bleichenbacher-style attack allows an attacker to use the victim's vulnerable application as a way to decrypt or sign messages with the victim's private RSA key.  The attack is possible in 2 variants.  1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without providing the recipient certificate. In this case OpenSSL iterates over every KeyTransRecipientInfo (KTRI) without stopping at the first success.  An attacker who authors a message with two KTRI entries — the first one wrapping a real CEK under the victim's public key, the second with an arbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to get a valid PKCS#1 v1.5 padding if the error code of the application is available.  That is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an adaptive-chosen-ciphertext side channel from which the attacker decrypts any RSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under it.  2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with the recipient certificate, and the recipient is not found, a random key is substituted.  An attacker who authors a message and is able to compare both error code and the result of the decryption, can mount a Bleichenbacher oracle.  We are not aware of any applications that provide a remote attacker an opportunity to mount an attack described in these scenarios. We consider the existence of such application very unlikely, and for this reason this CVE has been evaluated as Low severity.  To avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the invoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described in draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit rejection was explicitly disabled.  The implicit rejection mechanism always returns a plaintext value, the symmetric key. This result is deterministic for the ciphertext and the private key.  The length of the decryption result can happen to match the length of the key of the symmetric cipher that was used for the content encryption. When a certificate is not provided, the last RecipientInfo producing a key that looks valid will be used. It may cause getting garbage content on decryption. As a proper way to deal with this a recipient certificate has to be provided to identify the particular RecipientInfo for decryption.  The FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as CMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42769",
                        "url": "https://ubuntu.com/security/CVE-2026-42769",
                        "cve_description": "Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level.  Impact Summary: The Registration Autority could replace the root CA certificate for the CMP clients with an arbitrary root CA certificate.  One of the parts of the Certificate Management Protocol (CMP), specified in RFC 9810, is Root Certification Authority (root CA) key Rollover, which is sent by the server in a message with type 'id-it-rootCaKeyUpdate'. As part of these messages, 'newWithOld' certificate, the new root CA certificate signed with the old root CA key, is provided, and verifying its signature is crucial for transferring the trust from the old CA key to the new one.  The 'id-it-rootCaKeyUpdate' messages are expected to be processed with OSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld' certificate.  A typo in the certificate chain building code led to adding an incorrect certificate ('newWithOld' instead of 'oldRoot') to the certificate chain, rendering the certificate verification process ineffectual (only the issuer name and the algorithm OIDs were verified by other parts of the verification code).  An attacker who already has credentials that satisfy the CMP message protection checks can generate a new key pair and use a crafted self-signed certificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP clients would accept as a new trust anchor.  Significant preconditions for the attack (having valid RA-level credentials) are the reason the issue was assigned Low severity.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42770",
                        "url": "https://ubuntu.com/security/CVE-2026-42770",
                        "cve_description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership.  Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts.  When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared.  A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack).  The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42771",
                        "url": "https://ubuntu.com/security/CVE-2026-42771",
                        "cve_description": "Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen.  Impact summary: This out of bounds read will not directly exfiltrate the data read to the attacker so the most likely result is a crash and a Denial of Service.  An internal helper function called from X509_VERIFY_PARAM_[set|add]_email() used a wrong length when validating the local part of an email address. This could cause the 64 octet limit on the local part of an email address to be not enforced, or cause an out of bound read and potentially a crash.  The bug is reachable via S-MIME validation with a crafted From: address supplied in an email message that can potentially cause a crash.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45445",
                        "url": "https://ubuntu.com/security/CVE-2026-45445",
                        "cve_description": "Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded.  Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality.  If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not on the plaintext or ciphertext, allowing universal forgery of arbitrary ciphertext from a single captured message.  OpenSSL provides two ways to drive a cipher: the documented streaming interface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level one-shot, EVP_Cipher(), whose documentation explicitly recommends against use by applications in favour of EVP_CipherUpdate() and EVP_CipherFinal_ex().  The OCB provider's streaming handler flushes the application-supplied IV into the OCB context before processing data; the one-shot handler did not.  Every call to EVP_Cipher() on an AES-OCB context therefore ran with the all-zero key-derived offset state left by cipher initialisation, regardless of the caller's IV.  If EVP_EncryptFinal_ex() is subsequently used to obtain the authentication tag, the deferred IV setup runs at that point and clears the running checksum that should have been accumulated over the plaintext.  The resulting tag is a function of (key, IV) only and verifies against any ciphertext produced under the same (key, IV) pair.  The OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a TLS cipher suite, and libssl does not call EVP_Cipher() in any case. Applications that drive AES-OCB through the documented streaming AEAD API (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only applications that combine the AES-OCB cipher with the EVP_Cipher() one-shot API are vulnerable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45446",
                        "url": "https://ubuntu.com/security/CVE-2026-45446",
                        "cve_description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages.  Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers.  AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not encrypted), and plaintext, and produces ciphertext plus a 16-byte tag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only if the tag is verified succesfully.  In OpenSSL's provider implementation of these ciphers, the expected tag is computed only when decryption function is invoked with non-empty data. If the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without invocation of the ciphertext update, which can happen when the received ciphertext length is zero, the tag is never recalculated and still holds its all-zeros value.  When AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty ciphertext, and all-zeros tag passes authentication under any key they do not know, single-shot. When AES-SIV is used, for mounting the attack it's necessary for the application to reuse the decryption context without resetting the key.  AES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since OpenSSL 3.2.  No protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support either AES-GCM-SIV or AES-SIV. To mount an attack, the applications must implement their own protocol and use the EVP interface. Also they must skip the ciphertext update when a message with an empty ciphertext arrives.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as these algorithms are not FIPS approved and the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45447",
                        "url": "https://ubuntu.com/security/CVE-2026-45447",
                        "cve_description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.  Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution.  When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition.  In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution.  Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-2673",
                        "url": "https://ubuntu.com/security/CVE-2026-2673",
                        "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-03-13 19:54:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28387",
                        "url": "https://ubuntu.com/security/CVE-2026-28387",
                        "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28388",
                        "url": "https://ubuntu.com/security/CVE-2026-28388",
                        "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28389",
                        "url": "https://ubuntu.com/security/CVE-2026-28389",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28390",
                        "url": "https://ubuntu.com/security/CVE-2026-28390",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31789",
                        "url": "https://ubuntu.com/security/CVE-2026-31789",
                        "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31790",
                        "url": "https://ubuntu.com/security/CVE-2026-31790",
                        "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-2673",
                        "url": "https://ubuntu.com/security/CVE-2026-2673",
                        "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-03-13 19:54:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28387",
                        "url": "https://ubuntu.com/security/CVE-2026-28387",
                        "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28389",
                        "url": "https://ubuntu.com/security/CVE-2026-28389",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28390",
                        "url": "https://ubuntu.com/security/CVE-2026-28390",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31789",
                        "url": "https://ubuntu.com/security/CVE-2026-31789",
                        "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31790",
                        "url": "https://ubuntu.com/security/CVE-2026-31790",
                        "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28386",
                        "url": "https://ubuntu.com/security/CVE-2026-28386",
                        "cve_description": "Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output.  The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy.  Only x86-64 systems with AVX-512 and VAES instruction support are affected. Other architectures and systems without VAES support use different code paths that are not affected.  OpenSSL FIPS module in 3.6 version is affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28388",
                        "url": "https://ubuntu.com/security/CVE-2026-28388",
                        "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-11187",
                        "url": "https://ubuntu.com/security/CVE-2025-11187",
                        "cve_description": "Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification.  Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations.  When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without validation. If the value of keylength exceeds the size of the fixed stack buffer used for the derived key (64 bytes), the key derivation will overflow the buffer. The overflow length is attacker-controlled. Also, if the salt parameter is not an OCTET STRING type this can lead to invalid or NULL pointer dereference.  Exploiting this issue requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For this reason the issue was assessed as Moderate severity.  The FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as PKCS#12 processing is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue.  OpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do not support PBMAC1 in PKCS#12.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15467",
                        "url": "https://ubuntu.com/security/CVE-2025-15467",
                        "cve_description": "Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.  Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.  When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs.  Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.  OpenSSL 1.1.1 and 1.0.2 are not affected by this issue. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15468",
                        "url": "https://ubuntu.com/security/CVE-2025-15468",
                        "cve_description": "Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.  Impact summary: A NULL pointer dereference leads to abnormal termination of the running process causing Denial of Service.  Some applications call SSL_CIPHER_find() from the client_hello_cb callback on the cipher ID received from the peer. If this is done with an SSL object implementing the QUIC protocol, NULL pointer dereference will happen if the examined cipher ID is unknown or unsupported.  As it is not very common to call this function in applications using the QUIC protocol and the worst outcome is Denial of Service, the issue was assessed as Low severity.  The vulnerable code was introduced in the 3.2 version with the addition of the QUIC protocol support.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the QUIC implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15469",
                        "url": "https://ubuntu.com/security/CVE-2025-15469",
                        "cve_description": "Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error.  Impact summary: A user signing or verifying files larger than 16MB with one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire file is authenticated while trailing data beyond 16MB remains unauthenticated.  When the 'openssl dgst' command is used with algorithms that only support one-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input is buffered with a 16MB limit. If the input exceeds this limit, the tool silently truncates to the first 16MB and continues without signaling an error, contrary to what the documentation states. This creates an integrity gap where trailing bytes can be modified without detection if both signing and verification are performed using the same affected codepath.  The issue affects only the command-line tool behavior. Verifiers that process the full message using library APIs will reject the signature, so the risk primarily affects workflows that both sign and verify with the affected 'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and library users are unaffected.  The FIPS modules in 3.5 and 3.6 are not affected by this issue, as the command-line tools are outside the OpenSSL FIPS module boundary.  OpenSSL 3.5 and 3.6 are vulnerable to this issue.  OpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-66199",
                        "url": "https://ubuntu.com/security/CVE-2025-66199",
                        "cve_description": "Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.  Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work, potentially leading to service degradation or resource exhaustion (Denial of Service).  In affected configurations, the peer-supplied uncompressed certificate length from a CompressedCertificate message is used to grow a heap buffer prior to decompression. This length is not bounded by the max_cert_list setting, which otherwise constrains certificate message sizes. An attacker can exploit this to cause large per-connection allocations followed by handshake failure. No memory corruption or information disclosure occurs.  This issue only affects builds where TLS 1.3 certificate compression is compiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression algorithm (brotli, zlib, or zstd) is available, and where the compression extension is negotiated. Both clients receiving a server CompressedCertificate and servers in mutual TLS scenarios receiving a client CompressedCertificate are affected. Servers that do not request client certificates are not vulnerable to client-initiated attacks.  Users can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION to disable receiving compressed certificates.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the TLS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-68160",
                        "url": "https://ubuntu.com/security/CVE-2025-68160",
                        "cve_description": "Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.  Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application.  The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69418",
                        "url": "https://ubuntu.com/security/CVE-2025-69418",
                        "cve_description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69419",
                        "url": "https://ubuntu.com/security/CVE-2025-69419",
                        "cve_description": "Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.  Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service.  The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer.  The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer. The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69420",
                        "url": "https://ubuntu.com/security/CVE-2025-69420",
                        "cve_description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.  Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69421",
                        "url": "https://ubuntu.com/security/CVE-2025-69421",
                        "cve_description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.  Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files.  The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure.  Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-22795",
                        "url": "https://ubuntu.com/security/CVE-2026-22795",
                        "cve_description": "Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.  Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service.  A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read.  The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-22796",
                        "url": "https://ubuntu.com/security/CVE-2026-22796",
                        "cve_description": "Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.  Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163146,
                    2158026,
                    2158026,
                    2160606,
                    2147669,
                    2153135
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/default-configuration-read-dropins-and-crypto-config.patch:",
                            "    partially restore patch, needed by src:crypto-policies",
                            "    (LP: #2163146)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163146
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 12 Aug 2026 15:20:38 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert \"Add Depends on libjitterentropy3-dev, zlib1g-dev, and libzstd-dev.",
                            "    (LP: #2158026)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158026
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Mon, 10 Aug 2026 11:49:51 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add Depends on libjitterentropy3-dev, zlib1g-dev, and libzstd-dev.",
                            "    libcrypto.pc declares these as static private dependencies",
                            "    (Libs.private) but libssl-dev did not pull them in, breaking static",
                            "    linking against libcrypto. (LP: #2158026)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158026
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Mon, 03 Aug 2026 16:49:15 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Ravi Kant Sharma ]",
                            "  * Merge with Debian experimental (LP: #2160606). Remaining changes:",
                            "    - Use perl:native in the autopkgtest for installability on i386.",
                            "    - Symlink copyright/changelog.Debian.gz in libssl3* to libssl-dev/openssl",
                            "    - Disable LTO with which the codebase is generally incompatible",
                            "      (LP #2058017)",
                            "    - Don't enable or package anything FIPS (LP #2087955)",
                            "    - Match last filename for output in ecp_nistp521-ppc64.pl (LP #2137464)",
                            "    - Enable CPU jitter fluctuations",
                            "    - fips patches (debian/patches/fips):",
                            "      - crypto: Add kernel FIPS mode detection",
                            "      - crypto: Automatically use the FIPS provider...",
                            "      - apps/speed: Omit unavailable algorithms in FIPS mode",
                            "      - apps: pass -propquery arg to the libctx DRBG fetches",
                            "      - test: Ensure encoding runs with the correct context...",
                            "      - Add Ubuntu-specific defines to help FIPS certification (LP #2073991)",
                            "        + UBUNTU_OSSL_SELF_TEST_DESC_PCT_DH",
                            "        + UBUNTU_OSSL_PROV_FIPS_PARAM_UNAPPROVED_USAGE",
                            "      - Detect FIPS jitterentropy mode and load jitterentropy enabled FIPS",
                            "        provider",
                            "      - Fallback to default provider when FIPS provider is missing.",
                            "  * Dropped patches, not required anymore in Ubuntu",
                            "    - d/p/default-configuration-read-dropins-and-crypto-config.patch",
                            "",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160606
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Tue, 14 Jul 2026 12:53:05 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-7383",
                                "url": "https://ubuntu.com/security/CVE-2026-7383",
                                "cve_description": "Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow.  Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefined behaviour.  In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination size for Unicode output is computed in a signed int: by left shift of the input character count for BMPSTRING (UTF-16) and UNIVERSALSTRING (UTF-32), and by summing per-character byte counts for UTF8STRING. The calculation overflows when the input reaches around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30 characters) the size wraps to zero, OPENSSL_malloc(1) is called, and the subsequent character copy writes several gigabytes past the one-byte allocation.  X.509 certificate processing routes through ASN1_STRING_set_by_NID(), whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID size limits cap the input length; no network protocol or certificate-handling path in OpenSSL exercises the overflow. Triggering the bug requires an application that calls ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers a custom string type via ASN1_STRING_TABLE_add(), with attacker-controlled input on the order of half a gigabyte or more. For these reasons this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-9076",
                                "url": "https://ubuntu.com/security/CVE-2026-9076",
                                "cve_description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key().  Impact summary: A heap buffer over-read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not revealed to the attacker.  The key unwrapping function performs a check-byte test as specified in the RFC that reads 7 bytes from a heap allocation that is based on the wrapped key length from the message. There is a minimum length check based on the block length of the wrapping cipher. However the cipher is selected from an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no requirement that the cipher be a block cipher. When an attacker selects a stream-mode cipher the guard will be ineffective and the allocated buffer containing the unwrapped key can be too small to fit the check-bytes specified in the RFC and a buffer over-read can happen.  Applications calling CMS_decrypt() or CMS_decrypt_set1_password() (equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS data are vulnerable to this issue. No password knowledge is required: the over-read happens during the unwrap attempt before any authentication succeeds.  The over-read is limited to a few bytes and is not written to output, so there is no information disclosure. Triggering a crash requires the allocation to border unmapped memory, which is unlikely with the normal allocator.  The FIPS modules are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34180",
                                "url": "https://ubuntu.com/security/CVE-2026-34180",
                                "cve_description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms.  Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer.  More typically such ASN.1 elements would instead be truncated.  An integer truncation in OpenSSL's ASN.1 decoder causes the content length of an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the worst case the truncated length is treated as a request to scan the binary content for a terminating zero byte, possibly causing OpenSSL to read either less than or beyond the end of the allocated buffer.  Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or any other d2i_* decoding function are affected. OpenSSL's own command-line tools are not vulnerable, as data read through the BIO layer is checked before it reaches the affected code. The issue only affects 64-bit Unix and Unix-like platforms; 32-bit platforms and 64-bit Windows are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34181",
                                "url": "https://ubuntu.com/security/CVE-2026-34181",
                                "cve_description": "Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery.  Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability.  If a service accepting PKCS#12 files is using passwords for authenticating the received files, the attacker can create unencrypted PKCS#12 files that use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing them to craft a file that will be accepted with a 1 in 256 probability. That would then cause the service to accept a certificate and private key controlled by the attacker.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34182",
                                "url": "https://ubuntu.com/security/CVE-2026-34182",
                                "cve_description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises.  Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message.  In one use case, an attacker may send a CMS message containing AuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL erroneously allows this selection, and attempts to decrypt and validate the message.  An on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData addressed to the victim can re-emit it with the recipientInfos set left byte-for-byte intact, so the victim's private key still unwraps the genuine CEK (the content-encryption key), but with the inner OID rewritten to AES-256-OFB (Output Feedback Mode, an unauthenticated keystream mode) and with an attacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the real CEK, never consults the MAC field, and CMS_decrypt() returns success.  If the application under attack responds to the attacker with any indicator showing success or failure of the decryption effort, it is possible for the attacker to use this as an oracle to obtain key equivalent functionality for the CEK used for the chosen recipient of the message.  In another use case, an attacker can reduce the tag length of the chosen AEAD cipher for a given AuthEnvelopedData container to be a single byte long, allowing an attacker to brute force CMS decryption, producing an integrity bypass for applications that trust CMS_decrypt() to reject modified content.  The FIPS modules are not affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34183",
                                "url": "https://ubuntu.com/security/CVE-2026-34183",
                                "cve_description": "Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames.  Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service.  A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-35188",
                                "url": "https://ubuntu.com/security/CVE-2026-35188",
                                "cve_description": "Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path.  Impact summary: Successful exploitation allows an attacker to corrupt heap memory via a double-free, potentially leading to a Denial of Service or possibly an attacker controlled code execution or other undefined behavior.  If OCSP stapling is enabled and the TLS client connects to a malicious server, a crafted OCSP stapled response can trigger a double free in the TLS client when the stapled response is checked.  The OCSP stapling is not enabled by default. Reliable code execution through a double-free is technically complex and highly environment-dependent but the Denial of Service impact is straightforward to achieve, warranting Moderate severity.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42764",
                                "url": "https://ubuntu.com/security/CVE-2026-42764",
                                "cve_description": "Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled.  Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service.  If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token.  By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the default configuration not vulnerable to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with the SSL_new_listener() call, the address validation is disabled making the vulnerable code reachable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42765",
                                "url": "https://ubuntu.com/security/CVE-2026-42765",
                                "cve_description": "Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens.  This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verification. Both flags are disabled by default. For that reason, we have assigned Low severity to the issue.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42766",
                                "url": "https://ubuntu.com/security/CVE-2026-42766",
                                "cve_description": "Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as OPTIONAL in the ASN.1 specification and may therefore be absent in specially crafted inputs. During the password-based CMS decryption the OpenSSL CMS implementation dereferences this field without first checking whether it was present.  An attacker who supplies such a CMS message to an application performing password-based CMS decryption can trigger an application crash, leading to a Denial of Service.  Applications that process password-encrypted CMS messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42767",
                                "url": "https://ubuntu.com/security/CVE-2026-42767",
                                "cve_description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42768",
                                "url": "https://ubuntu.com/security/CVE-2026-42768",
                                "cve_description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output.  Impact summary: The Bleichenbacher-style attack allows an attacker to use the victim's vulnerable application as a way to decrypt or sign messages with the victim's private RSA key.  The attack is possible in 2 variants.  1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without providing the recipient certificate. In this case OpenSSL iterates over every KeyTransRecipientInfo (KTRI) without stopping at the first success.  An attacker who authors a message with two KTRI entries — the first one wrapping a real CEK under the victim's public key, the second with an arbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to get a valid PKCS#1 v1.5 padding if the error code of the application is available.  That is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an adaptive-chosen-ciphertext side channel from which the attacker decrypts any RSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under it.  2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with the recipient certificate, and the recipient is not found, a random key is substituted.  An attacker who authors a message and is able to compare both error code and the result of the decryption, can mount a Bleichenbacher oracle.  We are not aware of any applications that provide a remote attacker an opportunity to mount an attack described in these scenarios. We consider the existence of such application very unlikely, and for this reason this CVE has been evaluated as Low severity.  To avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the invoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described in draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit rejection was explicitly disabled.  The implicit rejection mechanism always returns a plaintext value, the symmetric key. This result is deterministic for the ciphertext and the private key.  The length of the decryption result can happen to match the length of the key of the symmetric cipher that was used for the content encryption. When a certificate is not provided, the last RecipientInfo producing a key that looks valid will be used. It may cause getting garbage content on decryption. As a proper way to deal with this a recipient certificate has to be provided to identify the particular RecipientInfo for decryption.  The FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as CMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42769",
                                "url": "https://ubuntu.com/security/CVE-2026-42769",
                                "cve_description": "Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level.  Impact Summary: The Registration Autority could replace the root CA certificate for the CMP clients with an arbitrary root CA certificate.  One of the parts of the Certificate Management Protocol (CMP), specified in RFC 9810, is Root Certification Authority (root CA) key Rollover, which is sent by the server in a message with type 'id-it-rootCaKeyUpdate'. As part of these messages, 'newWithOld' certificate, the new root CA certificate signed with the old root CA key, is provided, and verifying its signature is crucial for transferring the trust from the old CA key to the new one.  The 'id-it-rootCaKeyUpdate' messages are expected to be processed with OSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld' certificate.  A typo in the certificate chain building code led to adding an incorrect certificate ('newWithOld' instead of 'oldRoot') to the certificate chain, rendering the certificate verification process ineffectual (only the issuer name and the algorithm OIDs were verified by other parts of the verification code).  An attacker who already has credentials that satisfy the CMP message protection checks can generate a new key pair and use a crafted self-signed certificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP clients would accept as a new trust anchor.  Significant preconditions for the attack (having valid RA-level credentials) are the reason the issue was assigned Low severity.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42770",
                                "url": "https://ubuntu.com/security/CVE-2026-42770",
                                "cve_description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership.  Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts.  When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared.  A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack).  The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42771",
                                "url": "https://ubuntu.com/security/CVE-2026-42771",
                                "cve_description": "Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen.  Impact summary: This out of bounds read will not directly exfiltrate the data read to the attacker so the most likely result is a crash and a Denial of Service.  An internal helper function called from X509_VERIFY_PARAM_[set|add]_email() used a wrong length when validating the local part of an email address. This could cause the 64 octet limit on the local part of an email address to be not enforced, or cause an out of bound read and potentially a crash.  The bug is reachable via S-MIME validation with a crafted From: address supplied in an email message that can potentially cause a crash.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45445",
                                "url": "https://ubuntu.com/security/CVE-2026-45445",
                                "cve_description": "Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded.  Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality.  If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not on the plaintext or ciphertext, allowing universal forgery of arbitrary ciphertext from a single captured message.  OpenSSL provides two ways to drive a cipher: the documented streaming interface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level one-shot, EVP_Cipher(), whose documentation explicitly recommends against use by applications in favour of EVP_CipherUpdate() and EVP_CipherFinal_ex().  The OCB provider's streaming handler flushes the application-supplied IV into the OCB context before processing data; the one-shot handler did not.  Every call to EVP_Cipher() on an AES-OCB context therefore ran with the all-zero key-derived offset state left by cipher initialisation, regardless of the caller's IV.  If EVP_EncryptFinal_ex() is subsequently used to obtain the authentication tag, the deferred IV setup runs at that point and clears the running checksum that should have been accumulated over the plaintext.  The resulting tag is a function of (key, IV) only and verifies against any ciphertext produced under the same (key, IV) pair.  The OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a TLS cipher suite, and libssl does not call EVP_Cipher() in any case. Applications that drive AES-OCB through the documented streaming AEAD API (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only applications that combine the AES-OCB cipher with the EVP_Cipher() one-shot API are vulnerable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45446",
                                "url": "https://ubuntu.com/security/CVE-2026-45446",
                                "cve_description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages.  Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers.  AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not encrypted), and plaintext, and produces ciphertext plus a 16-byte tag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only if the tag is verified succesfully.  In OpenSSL's provider implementation of these ciphers, the expected tag is computed only when decryption function is invoked with non-empty data. If the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without invocation of the ciphertext update, which can happen when the received ciphertext length is zero, the tag is never recalculated and still holds its all-zeros value.  When AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty ciphertext, and all-zeros tag passes authentication under any key they do not know, single-shot. When AES-SIV is used, for mounting the attack it's necessary for the application to reuse the decryption context without resetting the key.  AES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since OpenSSL 3.2.  No protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support either AES-GCM-SIV or AES-SIV. To mount an attack, the applications must implement their own protocol and use the EVP interface. Also they must skip the ciphertext update when a message with an empty ciphertext arrives.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as these algorithms are not FIPS approved and the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45447",
                                "url": "https://ubuntu.com/security/CVE-2026-45447",
                                "cve_description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.  Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution.  When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition.  In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution.  Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Import 4.0.1",
                            "   - CVE-2026-7383 (\"Possible Heap Buffer Overflow in ASN.1 Multibyte String",
                            "     Conversion\")",
                            "   - CVE-2026-9076 (\"Out-of-Bounds Read in CMS Password-Based Decryption\")",
                            "   - CVE-2026-34180 (\"Heap Buffer Over-read in ASN.1 Content Parsing\")",
                            "   - CVE-2026-34181 (\"PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC",
                            "     Keys\")",
                            "   - CVE-2026-34182 (\"CMS AuthEnvelopedData Processing May Accept Forged",
                            "     Messages\")",
                            "   - CVE-2026-34183 (\"Unbounded Memory Growth in the QUIC PATH_CHALLENGE",
                            "     Handler\")",
                            "   - CVE-2026-35188 (\"Double-free When Checking OCSP Stapled Response\")",
                            "   - CVE-2026-42764 (\"NULL pointer dereference in QUIC server initial packet",
                            "     handling\")",
                            "   - CVE-2026-42765 (\"NULL Dereference in Certificate Verification with OCSP",
                            "     Checking\")",
                            "   - CVE-2026-42766 (\"Possible NULL Dereference in Password-Based CMS",
                            "     Decryption\")",
                            "   - CVE-2026-42767 (\"NULL Pointer Dereference in CRMF EncryptedValue",
                            "     Decryption\")",
                            "   - CVE-2026-42768 (\"Multi-RecipientInfo Bleichenbacher Oracle in",
                            "     CMS_decrypt() and PKCS7_decrypt()\")",
                            "   - CVE-2026-42769 (\"Trust-Anchor Substitution via cert/issuer Typo in CMP",
                            "     rootCaKeyUpdate\")",
                            "   - CVE-2026-42770 (\"FFC-DH Peer Validation Uses Attacker-Supplied q\")",
                            "   - CVE-2026-42771 (\"Possible Out of Bounds Read in",
                            "     X509_VERIFY_PARAM_set1_email()\")",
                            "   - CVE-2026-45445 (\"AES-OCB IV Ignored on EVP_Cipher() Path\")",
                            "   - CVE-2026-45446 (\"Incorrect Tag Processing for Empty Messages in",
                            "     AES-GCM-SIV and AES-SIV modes\")",
                            "   - CVE-2026-45447 (\"Heap Use-After-Free in OpenSSL PKCS7_verify()\")",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Sat, 13 Jun 2026 20:01:42 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-2673",
                                "url": "https://ubuntu.com/security/CVE-2026-2673",
                                "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-03-13 19:54:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28387",
                                "url": "https://ubuntu.com/security/CVE-2026-28387",
                                "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28388",
                                "url": "https://ubuntu.com/security/CVE-2026-28388",
                                "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28389",
                                "url": "https://ubuntu.com/security/CVE-2026-28389",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28390",
                                "url": "https://ubuntu.com/security/CVE-2026-28390",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31789",
                                "url": "https://ubuntu.com/security/CVE-2026-31789",
                                "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31790",
                                "url": "https://ubuntu.com/security/CVE-2026-31790",
                                "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Eric Berry ]",
                            "  * OpenSSL crashes in resolute when userspace entropy",
                            "    is enabled but fips provider is not installed (LP: #2147669)",
                            "",
                            "  [ Ravi Kant Sharma ]",
                            "  * Merge with Debian experimental (LP: #2153135). Remaining changes:",
                            "    - Use perl:native in the autopkgtest for installability on i386.",
                            "    - Symlink copyright/changelog.Debian.gz in libssl3* to libssl-dev/openssl",
                            "    - Disable LTO with which the codebase is generally incompatible",
                            "      (LP #2058017)",
                            "    - Default config reads crypto-config and /etc/ssl/openssl.cnf.d dropins",
                            "    - Don't enable or package anything FIPS (LP #2087955)",
                            "    - Match last filename for output in ecp_nistp521-ppc64.pl (LP #2137464)",
                            "    - Enable CPU jitter fluctuations",
                            "    - fips patches (debian/patches/fips):",
                            "      - crypto: Add kernel FIPS mode detection",
                            "      - crypto: Automatically use the FIPS provider...",
                            "      - apps/speed: Omit unavailable algorithms in FIPS mode",
                            "      - apps: pass -propquery arg to the libctx DRBG fetches",
                            "      - test: Ensure encoding runs with the correct context...",
                            "      - Add Ubuntu-specific defines to help FIPS certification (LP #2073991)",
                            "        + UBUNTU_OSSL_SELF_TEST_DESC_PCT_DH",
                            "        + UBUNTU_OSSL_PROV_FIPS_PARAM_UNAPPROVED_USAGE",
                            "      - Detect FIPS jitterentropy mode and load jitterentropy enabled FIPS",
                            "        provider",
                            "      - Fallback to default provider when FIPS provider is missing.",
                            "  * Refreshed patches",
                            "    - fips/apps-speed-Omit-unavailable-algorithms-in-FIPS-mode.patch",
                            "    - fips/crypto-Add-kernel-FIPS-mode-detection.patch",
                            "    - fips/crypto-add-userspace-fips-mode-detection.patch",
                            "    - fips/crypto-Automatically-use-the-FIPS-provider-when-the-kerne.patch",
                            "  * Dropped patches, merged upstream",
                            "    - CVE-2026-2673.patch",
                            "    - CVE-2026-28387.patch",
                            "    - CVE-2026-28388-1.patch",
                            "    - CVE-2026-28388-2.patch",
                            "    - CVE-2026-28389.patch",
                            "    - CVE-2026-28390.patch",
                            "    - CVE-2026-31789.patch",
                            "    - CVE-2026-31790-1.patch",
                            "    - CVE-2026-31790-2.patch",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2147669,
                            2153135
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Wed, 20 May 2026 12:14:25 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-2673",
                                "url": "https://ubuntu.com/security/CVE-2026-2673",
                                "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-03-13 19:54:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28387",
                                "url": "https://ubuntu.com/security/CVE-2026-28387",
                                "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28389",
                                "url": "https://ubuntu.com/security/CVE-2026-28389",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28390",
                                "url": "https://ubuntu.com/security/CVE-2026-28390",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31789",
                                "url": "https://ubuntu.com/security/CVE-2026-31789",
                                "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31790",
                                "url": "https://ubuntu.com/security/CVE-2026-31790",
                                "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28386",
                                "url": "https://ubuntu.com/security/CVE-2026-28386",
                                "cve_description": "Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output.  The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy.  Only x86-64 systems with AVX-512 and VAES instruction support are affected. Other architectures and systems without VAES support use different code paths that are not affected.  OpenSSL FIPS module in 3.6 version is affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28388",
                                "url": "https://ubuntu.com/security/CVE-2026-28388",
                                "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Import 4.0.0",
                            "    - CVE-2026-2673 (\"OpenSSL TLS 1.3 server may choose unexpected key agreement",
                            "      group\") (Closes: #1130650).",
                            "    - CVE-2026-28387 (\"Potential use-after-free in DANE client code\")",
                            "    - CVE-2026-28389 (\"Possible NULL dereference when processing CMS",
                            "      KeyAgreeRecipientInfo\")",
                            "    - CVE-2026-28390 (\"Possible NULL dereference when processing CMS",
                            "      KeyTransportRecipient Info\")",
                            "    - CVE-2026-31789 (\"Heap buffer overflow in hexadecimal conversion\")",
                            "    - CVE-2026-31790 (\"Incorrect failure handling in RSA KEM RSASVE",
                            "      encapsulation\")",
                            "    - CVE-2026-28386 (\"Out-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512",
                            "      Support\")",
                            "    - CVE-2026-28388 (\"NULL Pointer Dereference When Processing a Delta CRL\")",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 16 Apr 2026 20:31:23 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 4.0.0-beta1",
                            "  * Add musl targets (Closes: #1131164).",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0~beta1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 26 Mar 2026 22:34:26 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 4.0.0-alpha1 (Closes: #1126531).",
                            "  * Update Standards-Version.",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0~alpha1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Fri, 13 Mar 2026 18:16:34 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 12 Mar 2026 21:00:23 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2025-11187",
                                "url": "https://ubuntu.com/security/CVE-2025-11187",
                                "cve_description": "Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification.  Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations.  When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without validation. If the value of keylength exceeds the size of the fixed stack buffer used for the derived key (64 bytes), the key derivation will overflow the buffer. The overflow length is attacker-controlled. Also, if the salt parameter is not an OCTET STRING type this can lead to invalid or NULL pointer dereference.  Exploiting this issue requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For this reason the issue was assessed as Moderate severity.  The FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as PKCS#12 processing is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue.  OpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do not support PBMAC1 in PKCS#12.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-15467",
                                "url": "https://ubuntu.com/security/CVE-2025-15467",
                                "cve_description": "Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.  Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.  When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs.  Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.  OpenSSL 1.1.1 and 1.0.2 are not affected by this issue. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-15468",
                                "url": "https://ubuntu.com/security/CVE-2025-15468",
                                "cve_description": "Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.  Impact summary: A NULL pointer dereference leads to abnormal termination of the running process causing Denial of Service.  Some applications call SSL_CIPHER_find() from the client_hello_cb callback on the cipher ID received from the peer. If this is done with an SSL object implementing the QUIC protocol, NULL pointer dereference will happen if the examined cipher ID is unknown or unsupported.  As it is not very common to call this function in applications using the QUIC protocol and the worst outcome is Denial of Service, the issue was assessed as Low severity.  The vulnerable code was introduced in the 3.2 version with the addition of the QUIC protocol support.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the QUIC implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-15469",
                                "url": "https://ubuntu.com/security/CVE-2025-15469",
                                "cve_description": "Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error.  Impact summary: A user signing or verifying files larger than 16MB with one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire file is authenticated while trailing data beyond 16MB remains unauthenticated.  When the 'openssl dgst' command is used with algorithms that only support one-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input is buffered with a 16MB limit. If the input exceeds this limit, the tool silently truncates to the first 16MB and continues without signaling an error, contrary to what the documentation states. This creates an integrity gap where trailing bytes can be modified without detection if both signing and verification are performed using the same affected codepath.  The issue affects only the command-line tool behavior. Verifiers that process the full message using library APIs will reject the signature, so the risk primarily affects workflows that both sign and verify with the affected 'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and library users are unaffected.  The FIPS modules in 3.5 and 3.6 are not affected by this issue, as the command-line tools are outside the OpenSSL FIPS module boundary.  OpenSSL 3.5 and 3.6 are vulnerable to this issue.  OpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-66199",
                                "url": "https://ubuntu.com/security/CVE-2025-66199",
                                "cve_description": "Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.  Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work, potentially leading to service degradation or resource exhaustion (Denial of Service).  In affected configurations, the peer-supplied uncompressed certificate length from a CompressedCertificate message is used to grow a heap buffer prior to decompression. This length is not bounded by the max_cert_list setting, which otherwise constrains certificate message sizes. An attacker can exploit this to cause large per-connection allocations followed by handshake failure. No memory corruption or information disclosure occurs.  This issue only affects builds where TLS 1.3 certificate compression is compiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression algorithm (brotli, zlib, or zstd) is available, and where the compression extension is negotiated. Both clients receiving a server CompressedCertificate and servers in mutual TLS scenarios receiving a client CompressedCertificate are affected. Servers that do not request client certificates are not vulnerable to client-initiated attacks.  Users can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION to disable receiving compressed certificates.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the TLS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-68160",
                                "url": "https://ubuntu.com/security/CVE-2025-68160",
                                "cve_description": "Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.  Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application.  The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69418",
                                "url": "https://ubuntu.com/security/CVE-2025-69418",
                                "cve_description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69419",
                                "url": "https://ubuntu.com/security/CVE-2025-69419",
                                "cve_description": "Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.  Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service.  The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer.  The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer. The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69420",
                                "url": "https://ubuntu.com/security/CVE-2025-69420",
                                "cve_description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.  Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69421",
                                "url": "https://ubuntu.com/security/CVE-2025-69421",
                                "cve_description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.  Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files.  The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure.  Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-22795",
                                "url": "https://ubuntu.com/security/CVE-2026-22795",
                                "cve_description": "Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.  Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service.  A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read.  The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-22796",
                                "url": "https://ubuntu.com/security/CVE-2026-22796",
                                "cve_description": "Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.  Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Import 3.6.1",
                            "   - CVE-2025-11187 (Improper validation of PBMAC1 parameters in PKCS#12 MAC",
                            "     verification)",
                            "   - CVE-2025-15467 (Stack buffer overflow in CMS AuthEnvelopedData parsing)",
                            "   - CVE-2025-15468 (NULL dereference in SSL_CIPHER_find() function on unknown",
                            "     cipher ID)",
                            "   - CVE-2025-15469 (\"openssl dgst\" one-shot codepath silently truncates inputs",
                            "     >16MB)",
                            "   - CVE-2025-66199 (TLS 1.3 CompressedCertificate excessive memory allocation)",
                            "   - CVE-2025-68160 (Heap out-of-bounds write in BIO_f_linebuffer on short",
                            "     writes)",
                            "   - CVE-2025-69418 (Unauthenticated/unencrypted trailing bytes with low-level",
                            "     OCB function calls)",
                            "   - CVE-2025-69419 (Out of bounds write in PKCS12_get_friendlyname() UTF-8",
                            "     conversion)",
                            "   - CVE-2025-69420 (Missing ASN1_TYPE validation in TS_RESP_verify_response()",
                            "     function)",
                            "   - CVE-2025-69421 (NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex",
                            "     function)",
                            "   - CVE-2026-22795 (Missing ASN1_TYPE validation in PKCS#12 parsing)",
                            "   - CVE-2026-22796 (ASN1_TYPE Type Confusion in the",
                            "   - PKCS7_digest_from_attributes() function)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Tue, 27 Jan 2026 21:32:02 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Apply fix for upstream issue #28902",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Fri, 26 Dec 2025 17:01:03 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 3.6.0",
                            "  * Stop shipping c_rehash. It bas been long replaced by \"openssl rehash\"",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Fri, 03 Oct 2025 17:40:10 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 3.6.0-beta1",
                            "  * Drop pic & Bsymbolic patches. This shouldn't be needed anymore.",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0~~beta1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 18 Sep 2025 21:36:20 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 3.6.0-alpha1",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0~~alpha1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Sat, 06 Sep 2025 20:21:28 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "os-prober",
                "from_version": {
                    "source_package_name": "os-prober",
                    "source_package_version": "1.84ubuntu1",
                    "version": "1.84ubuntu1"
                },
                "to_version": {
                    "source_package_name": "os-prober",
                    "source_package_version": "1.85ubuntu1",
                    "version": "1.85ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2163660
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2163660). Remaining changes:",
                            "    - Ignore logger socket-errors (LP #1826294).",
                            "      This works around apparmor denials.",
                            "    - Replace newns by unshare --mount from util-linux.",
                            "      This makes os-prober run in a private mount namespace, as it was initially",
                            "      intended.",
                            "    - Mount btrfs subvolume @ when present for accessing a btrfs formatted",
                            "      rootfs.",
                            "    - Return list of Windows partitions for WINOSDATA instead of only those",
                            "      containing the bootrecord. Add Windows10 detection.",
                            "    - Fix 50mounted-tests for grub-probe recognition.",
                            "      This fixes an issue where 50mounted-tests broke if grub-probe does not",
                            "      recognize a filesystem.",
                            ""
                        ],
                        "package": "os-prober",
                        "version": "1.85ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163660
                        ],
                        "author": "Anshul Singh <anshul.singh@canonical.com>",
                        "date": "Mon, 17 Aug 2026 21:39:39 +0900"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "",
                            "  * Make sure, that the grep call for finding /boot/efi/EFI is locale-",
                            "    independent (add \"LC_ALL=C\"). Closes: #1142788.",
                            ""
                        ],
                        "package": "os-prober",
                        "version": "1.85",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Holger Wansing <hwansing@mailbox.org>",
                        "date": "Thu, 30 Jul 2026 14:26:34 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "plymouth",
                "from_version": {
                    "source_package_name": "plymouth",
                    "source_package_version": "24.004.60+git20250831.4a3c171d-0ubuntu9",
                    "version": "24.004.60+git20250831.4a3c171d-0ubuntu9"
                },
                "to_version": {
                    "source_package_name": "plymouth",
                    "source_package_version": "24.004.60+git20250831.4a3c171d-0ubuntu10",
                    "version": "24.004.60+git20250831.4a3c171d-0ubuntu10"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2144770-Fix-reload-when-happening-early.patch: Correct DEP-3 tags.",
                            "    This patch was forwarded upstream, it did not come from upstream.",
                            "  * d/local, d/source/include-binaries: Revert spinner theme.",
                            "    The spinner shipped in 26.04 was targeted to celebrate 26.04 only.",
                            ""
                        ],
                        "package": "plymouth",
                        "version": "24.004.60+git20250831.4a3c171d-0ubuntu10",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Mon, 07 Sep 2026 13:43:02 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "plymouth-theme-ubuntu-text",
                "from_version": {
                    "source_package_name": "plymouth",
                    "source_package_version": "24.004.60+git20250831.4a3c171d-0ubuntu9",
                    "version": "24.004.60+git20250831.4a3c171d-0ubuntu9"
                },
                "to_version": {
                    "source_package_name": "plymouth",
                    "source_package_version": "24.004.60+git20250831.4a3c171d-0ubuntu10",
                    "version": "24.004.60+git20250831.4a3c171d-0ubuntu10"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2144770-Fix-reload-when-happening-early.patch: Correct DEP-3 tags.",
                            "    This patch was forwarded upstream, it did not come from upstream.",
                            "  * d/local, d/source/include-binaries: Revert spinner theme.",
                            "    The spinner shipped in 26.04 was targeted to celebrate 26.04 only.",
                            ""
                        ],
                        "package": "plymouth",
                        "version": "24.004.60+git20250831.4a3c171d-0ubuntu10",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Mon, 07 Sep 2026 13:43:02 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "procps",
                "from_version": {
                    "source_package_name": "procps",
                    "source_package_version": "2:4.0.4-9ubuntu1",
                    "version": "2:4.0.4-9ubuntu1"
                },
                "to_version": {
                    "source_package_name": "procps",
                    "source_package_version": "2:4.0.6-3ubuntu1",
                    "version": "2:4.0.6-3ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153347
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable (LP: #2153347). Remaining changes:",
                            "    - debian/sysctl.d:",
                            "      + 55-console-messages.conf: stop low-level kernel messages on console.",
                            "      + 55-kernel-hardening.conf: add the kptr_restrict setting",
                            "      + 55-ipv6-privacy.conf: add a file to sysctl.d to apply the defaults",
                            "        for IPv6 privacy extensions for interfaces. (LP #176125, #841353)",
                            "      + 55-magic-sysrq.conf: Disable most magic sysrq by default, allowing",
                            "        critical sync, remount, reboot functions. (LP #194676, #1025467)",
                            "      + 55-network-security.conf: enable rp_filter.",
                            "      + 55-ptrace.conf: describe new PTRACE setting.",
                            "      + 55-zeropage.conf: safe mmap_min_addr value for graceful fall-back",
                            "        for armhf and arm64.",
                            "      + 55-qemu.conf.s390x for qemu.",
                            "      + 55-bufferbloat.conf: set default qdisc to fq_codel",
                            "      + 55-map-count.conf: Increase vm.max_map_count to 1048576",
                            "    - d/t/stack-limit: add basic autopkgtest to validate limits",
                            "    - d/tests: Add basic autopkgtest to validate sysctl-defaults (LP #1962038)",
                            "    - d/t/stack-limit: call 'pgrep systemd' instead of 'pgrep bash'",
                            "      The autopkgtest currently fails because there is no bash session, and",
                            "      pgrep returns non-zero. Use systemd because that will match for pid1.",
                            "    - d/tests: make sysctl-defaults test comprehensive",
                            "    - d/t/test_sysctl_defaults.py: skip test if sysctl key invalid",
                            "    - d/t/control: show all sysctl.d configs before test",
                            "    - d/t/control: make sysctl-defaults test Restrictions: isolation-machine",
                            "      (LP #2115346)",
                            "  * Dropped changes (applied upstream):",
                            "    - d/p/ignore_eaccess.patch: ignore EACCES when opening sysctl file (LP #1903351)",
                            "    - d/p/ignore_erofs.patch: ignore EROFS when opening sysctl file (LP #1419554)",
                            "    - d/p/0010-testsuite-ps-etime-ELAPSED-doesn-t-match-full-format.patch:",
                            "      Fix test failure (FTBFS) in testsuite/ps.test/ps_output.exp due to",
                            "      invalid regex match inside LXD containers.",
                            "    - d/p/lp2120904-openat.patch: utilize file descriptors and openat (LP #2120904)",
                            "    - d/p/lp2120904-nullpointer.patch: fix a race when 'status' is unavailable",
                            "      in /proc/<pid> resulting in NULL pointer (LP #2120904)",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153347
                        ],
                        "author": "Carter Hawthorne <carter.hawthorne@canonical.com>",
                        "date": "Thu, 13 Aug 2026 15:27:14 -0700"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Break & Replace manpages-zh Closes: #1141435",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Tue, 28 Jul 2026 21:10:17 +1000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Mattias Ellert ]",
                            "  * Fix compilation and installation on GNU/Hurd (Closes: #1138217)",
                            "",
                            "  [ Craig Small ]",
                            "  * Only include linux-sysctl-defaults on Linux systems Closes: #1129174",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Tue, 30 Jun 2026 19:23:38 +1000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            "    library and w: Don't check for sd_booted Closes: #1108549",
                            "    pgrep: Match on process ID Closes: #612146",
                            "    pgrep: Add --quiet option",
                            "    pmap: add -k option to print raw names from kernel",
                            "    ps.1: cols and collums alias width option Closes: #926361",
                            "    ps.1: Add format equivalents Closes: #925437",
                            "    slabtop: Increase column width Closes: #959375",
                            "    sysctl: Use options after --system  Closes: #978989",
                            "    w: Add terminal mode to show all terminal sessions",
                            "    w: Use process TTY as backup for user TTY Closes: #1080335",
                            "    w: Use correct return value for sd_get_sessions Closes: #1068904",
                            "    watch: Add --follow option Closes: #469156",
                            "    watch: 256 color support",
                            "    watch.1: Warn about -d permanent option Closes: #883638",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Thu, 29 Jan 2026 21:34:30 +1100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            "    library: Recover from meminfo seek using LXC Closes: #1072831",
                            "    ps.1: Update man page to standards Closes: #1081801",
                            "    snice: Minor fix for help screen Closes: #1086441",
                            "    sysctl: --all skips stat_refresh Closes: #978688",
                            "    vmstat.8: si/so are changed by --unit Closes: #1061944",
                            "    w.1: Note utmp is for non-systemd Closes: #1080333",
                            "    w.1: Update man page to standards Closes: #1077367",
                            "    w: Don't segfault with -s option",
                            "    watch.1: --chgexit only works for visible changes Closes: #729569",
                            "  * Remove ps_not_path_max patch as upstream has it",
                            "  * Remove makefile_w_link_systemd as its fixed upstream",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.5-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Thu, 19 Dec 2024 13:09:01 +1100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "publicsuffix",
                "from_version": {
                    "source_package_name": "publicsuffix",
                    "source_package_version": "20260624.0617-1",
                    "version": "20260624.0617-1"
                },
                "to_version": {
                    "source_package_name": "publicsuffix",
                    "source_package_version": "20260725.1419-1",
                    "version": "20260725.1419-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * new upstream version",
                            ""
                        ],
                        "package": "publicsuffix",
                        "version": "20260725.1419-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Florian Ernst <florian@debian.org>",
                        "date": "Sat, 08 Aug 2026 12:45:01 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-apport",
                "from_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.35.0-0ubuntu2",
                    "version": "2.35.0-0ubuntu2"
                },
                "to_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.36.0-0ubuntu1",
                    "version": "2.36.0-0ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-77113",
                        "url": "https://ubuntu.com/security/CVE-2026-77113",
                        "cve_description": "",
                        "cve_priority": "n/a",
                        "cve_public_date": ""
                    }
                ],
                "launchpad_bugs_fixed": [
                    2161697,
                    2163744,
                    2109979,
                    2156405
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-77113",
                                "url": "https://ubuntu.com/security/CVE-2026-77113",
                                "cve_description": "",
                                "cve_priority": "n/a",
                                "cve_public_date": ""
                            }
                        ],
                        "log": [
                            "",
                            "  [ Benjamin Drung ]",
                            "  * New upstream release.",
                            "    - SECURITY UPDATE: path traversal during report extraction (LP: #2161697)",
                            "      + problem_report: validate key names in ProblemReport.load",
                            "      + CVE-2026-77113",
                            "    - apport_python_hook: support dbus-broker (LP: #2163744)",
                            "    - Fix partial writes for coredumps larger than 2 GiB (LP: #2109979)",
                            "  * autopkgtest: remove unneeded dirmngr dependency",
                            "  * Drop patches applied upstream and refresh remaining patches",
                            "  * python3-apport: Tighten python3-problem-report dependency to >= 2.36",
                            "  * Let python3-problem-report break apport << 2.36 (for apport-unpack)",
                            "",
                            "  [ Kat Kuo ]",
                            "  * oem-getlogs: Remove Ubuntu Report call and get DCD directly (LP: #2156405)",
                            ""
                        ],
                        "package": "apport",
                        "version": "2.36.0-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161697,
                            2163744,
                            2109979,
                            2156405
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 16:48:31 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-certifi",
                "from_version": {
                    "source_package_name": "python-certifi",
                    "source_package_version": "2026.6.17+ds-1",
                    "version": "2026.6.17+ds-1"
                },
                "to_version": {
                    "source_package_name": "python-certifi",
                    "source_package_version": "2026.7.22+ds-1",
                    "version": "2026.7.22+ds-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Install certifi/tests/test_certify.py as non-executable.",
                            "  * Enable autopkgtest-pkg-pybuild.",
                            ""
                        ],
                        "package": "python-certifi",
                        "version": "2026.7.22+ds-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 26 Jul 2026 14:46:16 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-click",
                "from_version": {
                    "source_package_name": "python-click",
                    "source_package_version": "8.2.0+0.really.8.1.8-1build1",
                    "version": "8.2.0+0.really.8.1.8-1build1"
                },
                "to_version": {
                    "source_package_name": "python-click",
                    "source_package_version": "8.3.3-2",
                    "version": "8.3.3-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Sort help args to make them reproducible",
                            ""
                        ],
                        "package": "python-click",
                        "version": "8.3.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jochen Sprickerhof <jspricke@debian.org>",
                        "date": "Tue, 28 Jul 2026 22:03:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream version 8.3.3.",
                            "    - Add new build-dependency python3-myst-parser.",
                            "    - Refresh patches with new upstream version.",
                            ""
                        ],
                        "package": "python-click",
                        "version": "8.3.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sérgio de Almeida Cipriano Júnior <cipriano@debian.org>",
                        "date": "Sun, 19 Jul 2026 11:16:47 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Don't parameterize tests using non-Collection iterables (closes:",
                            "    #1140873).",
                            "  * Drop \"Priority: optional\", default as of dpkg-dev 1.22.13.",
                            "  * Standards-Version: 4.7.4.",
                            ""
                        ],
                        "package": "python-click",
                        "version": "8.2.0+0.really.8.1.8-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Wed, 01 Jul 2026 10:21:30 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-distupgrade",
                "from_version": {
                    "source_package_name": "ubuntu-release-upgrader",
                    "source_package_version": "1:26.10.3",
                    "version": "1:26.10.3"
                },
                "to_version": {
                    "source_package_name": "ubuntu-release-upgrader",
                    "source_package_version": "1:26.10.8",
                    "version": "1:26.10.8"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158525,
                    2166785,
                    2154822,
                    2154822
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * DistUpgradeQuirks: Add check for mysql_native_password use (LP: #2158525).",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.8",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158525
                        ],
                        "author": "Lena Voytek <lena.voytek@canonical.com>",
                        "date": "Tue, 08 Sep 2026 13:38:26 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * tests: test against recent releases",
                            "  * Use `sqv` instead of `gpgv` (LP: #2166785)",
                            "  * Run pre-build.sh to update templates and version",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.7",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166785
                        ],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 08 Sep 2026 17:18:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fixes for LP: #2154822:",
                            "    - DistUpgradeController: Fix rewriteMirrorUri to strip the country mirror",
                            "      on archs served by ports.u.c",
                            "    - test_sources_list: Disable test_apt_cacher_and_apt_bittorent on archs",
                            "      served by ports.u.c (rewriteMirrorUri now correctly causes changes that",
                            "      differ by architecture, and the test will only pass on archs served by",
                            "      archive.u.c)",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.6",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154822
                        ],
                        "author": "Dave Jones <dave.jones@canonical.com>",
                        "date": "Tue, 08 Sep 2026 12:09:21 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * DistUpgradeController: Split entries when the architecture(s) of the",
                            "    entry now reside on a different host, e.g. 26.04 where arm64 migrated",
                            "    from ports.u.c to archive.u.c (LP: #2154822)",
                            "  * DistUpgradeQuirks: minor changes to fix autopkgtest errors",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154822
                        ],
                        "author": "Dave Jones <dave.jones@canonical.com>",
                        "date": "Tue, 01 Sep 2026 20:33:49 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Florent 'Skia' Jacquet ]",
                            "  * test_pycodestyle: give a more verbose output upon failure",
                            "  * Add .launchpad.yaml to run at least some basic checks directly from git",
                            "  * Fix Stonking version number in announcements",
                            "",
                            "  [ kkuo ]",
                            "  * Remove unnecessary Ubuntu Insights consent migration logic",
                            "",
                            "  [ Oliver Reiche ]",
                            "  * DistUpgrade: fix release announcements for stonking",
                            "",
                            "  [ Alessandro Astone ]",
                            "  * Add quirk for installing dbus-broker",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Mon, 31 Aug 2026 12:01:33 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-gi",
                "from_version": {
                    "source_package_name": "pygobject",
                    "source_package_version": "3.56.2-1",
                    "version": "3.56.2-1"
                },
                "to_version": {
                    "source_package_name": "pygobject",
                    "source_package_version": "3.57.1-1",
                    "version": "3.57.1-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release (Closes: #1143867)",
                            ""
                        ],
                        "package": "pygobject",
                        "version": "3.57.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Sat, 15 Aug 2026 08:31:19 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Build with debhelper compat 14",
                            "  * Release to unstable",
                            ""
                        ],
                        "package": "pygobject",
                        "version": "3.57.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 06 Aug 2026 14:52:03 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * d/p: Drop patch applied upstream",
                            ""
                        ],
                        "package": "pygobject",
                        "version": "3.57.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Wed, 29 Jul 2026 13:03:40 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "  * d/p: Backport fix for big-endian test failure.",
                            "    This change stops trying to salvage broken GIR definitions with a",
                            "    workaround that was incorrect on big-endian architectures, and instead",
                            "    raises a python exception if that were to occur. (Closes: #1139446)",
                            ""
                        ],
                        "package": "pygobject",
                        "version": "3.56.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Wed, 29 Jul 2026 12:00:59 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * Update Standards Version to 4.7.4",
                            ""
                        ],
                        "package": "pygobject",
                        "version": "3.56.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Fri, 08 May 2026 16:58:00 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-httplib2",
                "from_version": {
                    "source_package_name": "python-httplib2",
                    "source_package_version": "0.31.2-2",
                    "version": "0.31.2-2"
                },
                "to_version": {
                    "source_package_name": "python-httplib2",
                    "source_package_version": "0.32.0-1",
                    "version": "0.32.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream release.",
                            "  * Use pytest-forked (closes: #1141010).",
                            "  * Unset pybuild's proxy environment variables; in this case, those just",
                            "    serve to confuse the test suite.",
                            ""
                        ],
                        "package": "python-httplib2",
                        "version": "0.32.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Wed, 01 Jul 2026 11:15:11 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-idna",
                "from_version": {
                    "source_package_name": "python-idna",
                    "source_package_version": "3.11-1",
                    "version": "3.11-1"
                },
                "to_version": {
                    "source_package_name": "python-idna",
                    "source_package_version": "3.18-1",
                    "version": "3.18-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * d/watch: Convert to version 5",
                            "  * New upstream version 3.18",
                            "  * d/control: Increase Standards-Version to 4.7.4",
                            ""
                        ],
                        "package": "python-idna",
                        "version": "3.18-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Carsten Schoenert <c.schoenert@t-online.de>",
                        "date": "Mon, 29 Jun 2026 14:41:21 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-jinja2",
                "from_version": {
                    "source_package_name": "jinja2",
                    "source_package_version": "3.1.6-2",
                    "version": "3.1.6-2"
                },
                "to_version": {
                    "source_package_name": "jinja2",
                    "source_package_version": "3.1.6-3",
                    "version": "3.1.6-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Test !nodoc & !nocheck profiles with Salsa CI",
                            "  * d/rules: guard call to \"make docs\" in a if-block",
                            "  * Mark python3-pallets-sphinx-themes as <!nodoc>",
                            "  * Update standards version to 4.7.4, no changes needed.",
                            "  * Use dh-sequence-* build dependencies instead of dh --with: sphinxdoc.",
                            "  * Add debian/upstream/metadata",
                            ""
                        ],
                        "package": "jinja2",
                        "version": "3.1.6-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Wed, 24 Jun 2026 10:54:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-jsonpatch",
                "from_version": {
                    "source_package_name": "python-json-patch",
                    "source_package_version": "1.32-6",
                    "version": "1.32-6"
                },
                "to_version": {
                    "source_package_name": "python-json-patch",
                    "source_package_version": "1.33-2",
                    "version": "1.33-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Uploading to unstable.",
                            ""
                        ],
                        "package": "python-json-patch",
                        "version": "1.33-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Thomas Goirand <zigo@debian.org>",
                        "date": "Thu, 26 Mar 2026 11:59:43 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "python-json-patch",
                        "version": "1.33-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Thomas Goirand <zigo@debian.org>",
                        "date": "Thu, 26 Feb 2026 13:32:02 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-lazr.restfulclient",
                "from_version": {
                    "source_package_name": "lazr.restfulclient",
                    "source_package_version": "0.14.6-3build1",
                    "version": "0.14.6-3build1"
                },
                "to_version": {
                    "source_package_name": "lazr.restfulclient",
                    "source_package_version": "4.0.0-1",
                    "version": "4.0.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * d/watch: Switch to PyPI.",
                            "  * New upstream release:",
                            "    - Replace pkg_resources namespace with a PEP 420 native namespace",
                            "      (closes: #1083460).",
                            "  * Drop \"Rules-Requires-Root: no\", default as of dpkg-dev 1.22.13.",
                            "  * Drop \"Priority: optional\", default as of dpkg-dev 1.22.13.",
                            "  * Standards-Version: 4.7.4.",
                            ""
                        ],
                        "package": "lazr.restfulclient",
                        "version": "4.0.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:16:15 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-magic",
                "from_version": {
                    "source_package_name": "python-magic",
                    "source_package_version": "2:0.4.27-5",
                    "version": "2:0.4.27-5"
                },
                "to_version": {
                    "source_package_name": "python-magic",
                    "source_package_version": "2:0.4.27-6",
                    "version": "2:0.4.27-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Mark python3-pytest build dependency as !nocheck. Closes: #1141486",
                            ""
                        ],
                        "package": "python-magic",
                        "version": "2:0.4.27-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Christoph Biedl <debian.axhn@manchmal.in-ulm.de>",
                        "date": "Sun, 05 Jul 2026 14:30:29 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-markupsafe",
                "from_version": {
                    "source_package_name": "markupsafe",
                    "source_package_version": "3.0.3-1build1",
                    "version": "3.0.3-1build1"
                },
                "to_version": {
                    "source_package_name": "markupsafe",
                    "source_package_version": "3.0.3-2",
                    "version": "3.0.3-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "  * d/copyright: Use machine-readable format",
                            ""
                        ],
                        "package": "markupsafe",
                        "version": "3.0.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Germann <bage@debian.org>",
                        "date": "Mon, 03 Aug 2026 23:47:43 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-more-itertools",
                "from_version": {
                    "source_package_name": "more-itertools",
                    "source_package_version": "10.8.0-1build1",
                    "version": "10.8.0-1build1"
                },
                "to_version": {
                    "source_package_name": "more-itertools",
                    "source_package_version": "11.1.0-2",
                    "version": "11.1.0-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/control: Add myself to Uploaders",
                            "  * debian/: Bump debhelper compat to 14",
                            ""
                        ],
                        "package": "more-itertools",
                        "version": "11.1.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Ramacher <sramacher@debian.org>",
                        "date": "Sun, 16 Aug 2026 14:06:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream release.",
                            "  * Mark python3-more-itertools as Multi-Arch: foreign (closes: #1078037).",
                            "  * Drop \"Rules-Requires-Root: no\", default as of dpkg-dev 1.22.13.",
                            "  * Drop \"Priority: optional\", default as of dpkg-dev 1.22.13.",
                            "  * Standards-Version: 4.7.4.",
                            ""
                        ],
                        "package": "more-itertools",
                        "version": "11.1.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 20 Jul 2026 11:15:39 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-netplan",
                "from_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.1-1ubuntu1",
                    "version": "1.2.1-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.2-1",
                    "version": "1.2.2-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153219,
                    2145061,
                    2147446,
                    2071747,
                    2139598,
                    2138802
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153219). Remaining changes:",
                            "    - Skip test_link_offloading to allow for a green baseline (LP 2126938)",
                            "      + d/p/lp-2126938-skip-test-link-offloading.patch",
                            "  * Dropped:",
                            "    - d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "      3.14 by handling BlockingIOError in addition to TypeError (LP 2138802)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "      execute udev rules before starting sriov apply service (LP 2139598)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "      (LP 2071747)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "      Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "      units. (LP 2145061)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "      networkd to apply dhcp labels to addresses (LP 2147446).",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "      permissions for files not managed by netplan in integration tests.",
                            "      [Included in Debian 1.2.1-1]",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153219
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Thu, 21 May 2026 16:24:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "    Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "    units. (LP: #2145061)",
                            "  * d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "    networkd to apply dhcp labels to addresses (LP: #2147446).",
                            "  * d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "    permissions for files not managed by netplan in integration tests.",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu5",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2145061,
                            2147446
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Wed, 08 Apr 2026 16:47:32 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "    (LP: #2071747)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2071747
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Fri, 20 Mar 2026 16:09:27 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "    execute udev rules before starting sriov apply service (LP: #2139598)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2139598
                        ],
                        "author": "Robert Malz <robert.malz@canonical.com>",
                        "date": "Tue, 03 Mar 2026 12:44:43 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "    3.14 by handling BlockingIOError in addition to TypeError (LP: #2138802)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2138802
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Fri, 20 Feb 2026 11:25:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip test_link_offloading to allow for a green baseline (LP: 2126938)",
                            "    - d/p/lp-2126938-skip-test-link-offloading.patch",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Lukas Märdian <slyon@ubuntu.com>",
                        "date": "Tue, 13 Jan 2026 17:58:24 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "python3-packaging",
                "from_version": {
                    "source_package_name": "python-packaging",
                    "source_package_version": "26.0-1",
                    "version": "26.0-1"
                },
                "to_version": {
                    "source_package_name": "python-packaging",
                    "source_package_version": "26.2-2",
                    "version": "26.2-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Add upstream patch for Pytest 9.1 compatibility (Closes: #1140881)",
                            "  * Salsa: test <!nocheck> profile",
                            "  * Tag test build-dependencies as <!nocheck>",
                            "  * Use dh-sequence-python3",
                            "  * Bump Standards-Version to 4.7.4, drop Priority: tag",
                            "  * Rewrite d/watch in v5 format",
                            "  * Add debian/upstream/metadata",
                            ""
                        ],
                        "package": "python-packaging",
                        "version": "26.2-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sun, 28 Jun 2026 01:15:17 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "python-packaging",
                        "version": "26.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 01 Jun 2026 12:11:04 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-pexpect",
                "from_version": {
                    "source_package_name": "pexpect",
                    "source_package_version": "4.9-4",
                    "version": "4.9-4"
                },
                "to_version": {
                    "source_package_name": "pexpect",
                    "source_package_version": "4.9-5",
                    "version": "4.9-5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Add debian/salsa-ci.yml",
                            "  * Annotate build-deps as <!nodoc> or <!nocheck>",
                            "  * Bump Standards-Version to 4.7.4, drop Priority: tag",
                            "  * Rewrite d/watch in v5 format",
                            "  * Set upstream metadata fields: Documentation.",
                            "  * Use dh-sequence-* build dependencies instead of dh --with: sphinxdoc.",
                            ""
                        ],
                        "package": "pexpect",
                        "version": "4.9-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sat, 27 Jun 2026 13:00:03 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-problem-report",
                "from_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.35.0-0ubuntu2",
                    "version": "2.35.0-0ubuntu2"
                },
                "to_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.36.0-0ubuntu1",
                    "version": "2.36.0-0ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-77113",
                        "url": "https://ubuntu.com/security/CVE-2026-77113",
                        "cve_description": "",
                        "cve_priority": "n/a",
                        "cve_public_date": ""
                    }
                ],
                "launchpad_bugs_fixed": [
                    2161697,
                    2163744,
                    2109979,
                    2156405
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-77113",
                                "url": "https://ubuntu.com/security/CVE-2026-77113",
                                "cve_description": "",
                                "cve_priority": "n/a",
                                "cve_public_date": ""
                            }
                        ],
                        "log": [
                            "",
                            "  [ Benjamin Drung ]",
                            "  * New upstream release.",
                            "    - SECURITY UPDATE: path traversal during report extraction (LP: #2161697)",
                            "      + problem_report: validate key names in ProblemReport.load",
                            "      + CVE-2026-77113",
                            "    - apport_python_hook: support dbus-broker (LP: #2163744)",
                            "    - Fix partial writes for coredumps larger than 2 GiB (LP: #2109979)",
                            "  * autopkgtest: remove unneeded dirmngr dependency",
                            "  * Drop patches applied upstream and refresh remaining patches",
                            "  * python3-apport: Tighten python3-problem-report dependency to >= 2.36",
                            "  * Let python3-problem-report break apport << 2.36 (for apport-unpack)",
                            "",
                            "  [ Kat Kuo ]",
                            "  * oem-getlogs: Remove Ubuntu Report call and get DCD directly (LP: #2156405)",
                            ""
                        ],
                        "package": "apport",
                        "version": "2.36.0-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161697,
                            2163744,
                            2109979,
                            2156405
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 16:48:31 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-pygments",
                "from_version": {
                    "source_package_name": "pygments",
                    "source_package_version": "2.19.2+dfsg-1",
                    "version": "2.19.2+dfsg-1"
                },
                "to_version": {
                    "source_package_name": "pygments",
                    "source_package_version": "2.20.0+dfsg-2",
                    "version": "2.20.0+dfsg-2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4539",
                        "url": "https://ubuntu.com/security/CVE-2026-4539",
                        "cve_description": "A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-03-22 06:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Handle None object before HTML escaping (closes: #1141791).",
                            ""
                        ],
                        "package": "pygments",
                        "version": "2.20.0+dfsg-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:09:00 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4539",
                                "url": "https://ubuntu.com/security/CVE-2026-4539",
                                "cve_description": "A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-03-22 06:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Team upload.",
                            "",
                            "  [ Colin Watson ]",
                            "  * Move dh-python, pybuild-plugin-pyproject, and python3-sphinx to",
                            "    Build-Depends.",
                            "",
                            "  [ Matheus Polkorny ]",
                            "  * New upstream version 2.20.0+dfsg",
                            "    - Fix: CVE-2026-4539 (Closes: #1132233)",
                            "  * d/control:",
                            "    - Bump Standards-Version to 4.7.4",
                            "    - Drop redundant Priority field",
                            "    - Drop redundant Rules-Requires-Root field",
                            "  * d/copyright:",
                            "    - Bump upstream copyright to 2026",
                            "    - Update Files-Excluded for new upstream version",
                            "  * d/p/tests-tolerate-missing-example-files.patch: Update patch",
                            "  * d/upstream|watch: Migrate to watch 5",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * d/salsa-ci.yml: test the <!nocheck> & <!nodoc> profiles",
                            "  * use dh-sequence-python3 & dh-sequence-sphinxdoc",
                            "  * d/rules: guard \"make doc\" in a if-block",
                            "  * rewrite d/rules with newer & shorter syntax",
                            "  * trim leftover Python2+3 hybridation",
                            ""
                        ],
                        "package": "pygments",
                        "version": "2.20.0+dfsg-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sat, 04 Jul 2026 21:31:34 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-requests",
                "from_version": {
                    "source_package_name": "requests",
                    "source_package_version": "2.32.5+dfsg-1ubuntu1",
                    "version": "2.32.5+dfsg-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "requests",
                    "source_package_version": "2.34.2-1",
                    "version": "2.34.2-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2024-47081",
                        "url": "https://ubuntu.com/security/CVE-2024-47081",
                        "cve_description": "Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.",
                        "cve_priority": "medium",
                        "cve_public_date": "2025-06-09 18:15:00 UTC"
                    },
                    {
                        "cve": "CVE-2024-47081",
                        "url": "https://ubuntu.com/security/CVE-2024-47081",
                        "cve_description": "Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.",
                        "cve_priority": "medium",
                        "cve_public_date": "2025-06-09 18:15:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2130145,
                    2085279,
                    1975541,
                    1975541
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2024-47081",
                                "url": "https://ubuntu.com/security/CVE-2024-47081",
                                "cve_description": "Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.",
                                "cve_priority": "medium",
                                "cve_public_date": "2025-06-09 18:15:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2130145). Remaining changes:",
                            "    - d/p/remove-charset-normalizer-dependency.patch: Remove charset-normalizer",
                            "      as a build dependency (LP #1975541).",
                            "    Drop changes applied in upstream:",
                            "    - debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc",
                            "      lookup instead of netloc",
                            "  * d/p/remove-charset-normalizer-dependency.patch: refresh the patch",
                            ""
                        ],
                        "package": "requests",
                        "version": "2.32.5+dfsg-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2130145
                        ],
                        "author": "Nadzeya Hutsko <nadzeya.hutsko@canonical.com>",
                        "date": "Thu, 06 Nov 2025 12:18:28 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2024-47081",
                                "url": "https://ubuntu.com/security/CVE-2024-47081",
                                "cve_description": "Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.",
                                "cve_priority": "medium",
                                "cve_public_date": "2025-06-09 18:15:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Information Leak",
                            "    - debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc",
                            "      lookup instead of netloc",
                            "    - CVE-2024-47081",
                            ""
                        ],
                        "package": "requests",
                        "version": "2.32.3+dfsg-5ubuntu2",
                        "urgency": "medium",
                        "distributions": "questing",
                        "launchpad_bugs_fixed": [],
                        "author": "Bruce Cable <bruce.cable@canonical.com>",
                        "date": "Wed, 11 Jun 2025 13:28:01 +1000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2085279). Remaining changes:",
                            "    - d/p/remove-charset-normalizer-dependency.patch: Remove charset-normalizer",
                            "      as a build dependency (LP #1975541).",
                            ""
                        ],
                        "package": "requests",
                        "version": "2.32.3+dfsg-5ubuntu1",
                        "urgency": "medium",
                        "distributions": "questing",
                        "launchpad_bugs_fixed": [
                            2085279
                        ],
                        "author": "Lena Voytek <lena.voytek@canonical.com>",
                        "date": "Thu, 22 May 2025 16:50:10 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian Unstable. Remaining changes:",
                            "    - d/p/remove-charset-normalizer-dependency.patch: Remove charset-normalizer",
                            "      as a build dependency (LP: #1975541).",
                            ""
                        ],
                        "package": "requests",
                        "version": "2.32.3+dfsg-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "plucky",
                        "launchpad_bugs_fixed": [
                            1975541
                        ],
                        "author": "Simon Quigley <tsimonq2@ubuntu.com>",
                        "date": "Tue, 18 Feb 2025 01:55:57 -0600"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/remove-charset-normalizer-dependency.patch: Remove charset-normalizer",
                            "    as a build dependency of requests (LP: #1975541)",
                            ""
                        ],
                        "package": "requests",
                        "version": "2.32.3+dfsg-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "oracular",
                        "launchpad_bugs_fixed": [
                            1975541
                        ],
                        "author": "Lena Voytek <lena.voytek@canonical.com>",
                        "date": "Wed, 26 Jun 2024 08:56:02 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "python3-urllib3",
                "from_version": {
                    "source_package_name": "python-urllib3",
                    "source_package_version": "2.6.3-2ubuntu1",
                    "version": "2.6.3-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "python-urllib3",
                    "source_package_version": "2.7.0-3",
                    "version": "2.7.0-3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-44432",
                        "url": "https://ubuntu.com/security/CVE-2026-44432",
                        "cve_description": "urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-13 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-9375",
                        "url": "https://ubuntu.com/security/CVE-2026-9375",
                        "cve_description": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-19 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Replace deprecated pyOpenSSL X509.get_subject and Context.set_passwd_cb",
                            "    methods (closes: #1142214).",
                            ""
                        ],
                        "package": "python-urllib3",
                        "version": "2.7.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Tue, 21 Jul 2026 10:09:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Salsa CI: test nocheck profile",
                            "  * Mark python3-h2 build-dep as <!nocheck>",
                            "  * Rewrite d/watch in v5 format",
                            "  * Update standards version to 4.7.4, no changes needed.",
                            "  * Set upstream metadata fields: Documentation.",
                            ""
                        ],
                        "package": "python-urllib3",
                        "version": "2.7.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sun, 12 Jul 2026 17:23:46 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-44432",
                                "url": "https://ubuntu.com/security/CVE-2026-44432",
                                "cve_description": "urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-13 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-9375",
                                "url": "https://ubuntu.com/security/CVE-2026-9375",
                                "cve_description": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-19 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream release:",
                            "    - CVE-2026-44432, CVE-2026-9375: Decompression-bomb safeguards bypassed",
                            "      in parts of the streaming API (closes: #1136654, #1140427).",
                            "    - GHSA-qccp-gfcp-xxvc: Sensitive headers forwarded across origins in",
                            "      proxied low-level redirects.",
                            "  * Don't parameterize tests using non-Collection iterables",
                            "    (Closes: #1140932).",
                            ""
                        ],
                        "package": "python-urllib3",
                        "version": "2.7.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 28 Jun 2026 17:48:21 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "rsync",
                "from_version": {
                    "source_package_name": "rsync",
                    "source_package_version": "3.4.4+ds1-1",
                    "version": "3.4.4+ds1-1"
                },
                "to_version": {
                    "source_package_name": "rsync",
                    "source_package_version": "3.4.4+ds1-1build1",
                    "version": "3.4.4+ds1-1build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "rsync",
                        "version": "3.4.4+ds1-1build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 16:14:22 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "rsyslog",
                "from_version": {
                    "source_package_name": "rsyslog",
                    "source_package_version": "8.2512.0-1ubuntu5",
                    "version": "8.2512.0-1ubuntu5"
                },
                "to_version": {
                    "source_package_name": "rsyslog",
                    "source_package_version": "8.2608.0-4ubuntu1",
                    "version": "8.2608.0-4ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-61548",
                        "url": "https://ubuntu.com/security/CVE-2026-61548",
                        "cve_description": "mmpstrucdata stack buffer overflow with oversized RFC5424 structured data",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20"
                    },
                    {
                        "cve": "CVE-2026-78002",
                        "url": "https://ubuntu.com/security/CVE-2026-78002",
                        "cve_description": "A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-27 17:20:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-19654",
                        "url": "https://ubuntu.com/security/CVE-2026-19654",
                        "cve_description": "A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-12 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-61548",
                        "url": "https://ubuntu.com/security/CVE-2026-61548",
                        "cve_description": "mmpstrucdata stack buffer overflow with oversized RFC5424 structured data",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153351,
                    2163685,
                    2163702,
                    2158686
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-61548",
                                "url": "https://ubuntu.com/security/CVE-2026-61548",
                                "cve_description": "mmpstrucdata stack buffer overflow with oversized RFC5424 structured data",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153351). Remaining changes:",
                            "    - d/00rsyslog.conf, d/rsyslog.postinst, d/rsyslog.install: add",
                            "      tmpfiles.d snippet",
                            "    - d/50-default.conf: set of default rules for syslog",
                            "    - d/rsyslog.install: install default rules",
                            "    - d/rsyslog.postrm: remove default conf file in postrm on purge,",
                            "      manage with ucf",
                            "    - d/rsyslog.postinst: adapt script to use ucf for Ubuntu's config",
                            "      files",
                            "    - d/control: add Depends for ucf",
                            "    - d/rsyslog.postinst: adapt script to use ucf for Ubuntu's config",
                            "      files",
                            "    - d/rsyslog.conf: enable $RepeatedMsgReduction to avoid bloating the",
                            "      syslog file",
                            "    - d/rsyslog.conf: enable permitnonkernelfacility for non-kernel klog",
                            "      messages",
                            "    - d/rsyslog.conf: run as syslog:syslog, set $FileOwner to syslog",
                            "    - d/usr.sbin.rsyslogd: add apparmor profile for rsyslogd",
                            "    - d/rsyslog.install: install apparmor rule",
                            "    - d/rules: use dh_apparmor to install profile before rsyslog is",
                            "      started",
                            "    - d/rsyslog.postinst: remove disabling of apparmor on upgrades",
                            "    - d/rsyslog.dirs: install /etc/apparmor.d/rsyslog.d",
                            "    - d/control: suggests apparmor (>= 2.3), Build-Depends on",
                            "      dh-apparmor",
                            "    - d/{apparmor/rsyslog-mysql, rsyslog-mysql}: add apparmor profile",
                            "      for mysql plugin",
                            "    - d/{apparmor/rsyslog-pgsql, rsyslog-pgsql}: add apparmor profile",
                            "      for pgsql plugin",
                            "    - d/{apparmor/rsyslog-gnutls, rsyslog-gnutls}: add apparmor profile",
                            "      for gnutls plugin",
                            "    - d/{apparmor/rsyslog-openssl, rsyslog-openssl}: add apparmor",
                            "      profile for openssl plugin",
                            "    - d/reload-apparmor-profile: add script to reload rsyslogd apparmor",
                            "      profile",
                            "    - d/rsyslog.install: install reload-apparmor-profile",
                            "    - d/rsyslog.service: reload apparmor profile in ExecStartPre and set",
                            "      StandardError to journal so we can see errors from the script",
                            "    - d/NEWS: add info about the apparmor changes in the Ubuntu",
                            "      packaging",
                            "    - d/rsyslog.docs, d/README.apparmor: explains how the dynamic",
                            "      component of the rsyslog apparmor profile is applied",
                            "    - d/README.apparmor.syslog.d, d/rsyslog.install: install a specific",
                            "      README file in the apparmor include directory for rsyslog",
                            "    - d/rules: fix LDFLAGS to avoid segfault on receipt of first message",
                            "    - d/rules: drop --enable-mmnormalize & --enable-pmnormalize",
                            "    - d/rsyslog.install: remove mmnormalize",
                            "    - d/rsyslog.postinst: create syslog uesr and add it to adm group",
                            "    - d/rsyslog.postinst: adapt privileges for /var/log",
                            "    - d/rsyslog.postinst: fix ownership of /var/spool/rsyslog",
                            "    - d/control: add depends for adduser",
                            "    - d/dmesg.service, d/rsyslog.install: provide /var/log/dmesg.log as",
                            "      non log-rotated log for boot-time kernel messages",
                            "    - d/clean: delete some files left over by the test suite",
                            "    - d/t/utils: common test functions",
                            "    - d/t/apparmor-include-mechanism: test for the rsyslog.d include",
                            "      mechanism for apparmor",
                            "    - d/t/simple-logger: simple logger test",
                            "    - d/t/simple-mysql: test with a MySQL server",
                            "    - d/t/simple-pgsql: test with a PostgreSQL server",
                            "    - d/t/logcheck: fix timing of test",
                            "    - d/rsyslog.logcheck.ignore.server: amend list of expected messages",
                            "      to fix armhf autopkgtest (LP #2028935)",
                            "    - d/rsyslog.service: adjust sandboxing; add CAP_MAC_ADMIN,",
                            "      CAP_SETUID, CAP_SETGID",
                            "    - d/usr.sbin.rsyslogd: add rule to allow reading systemd sessions",
                            "      (LP #2056768)",
                            "    - d/usr.sbin.rsyslogd: add rule to allow imjournal module to work",
                            "      (LP 2073628)",
                            "    - d/usr.sbin.rsyslogd: add rule to allow access to disable_ipv6",
                            "      inside /proc (LP 2061726)",
                            "    - d/t/logcheck: only consider current boot when checking the journal",
                            "      (LP #2100765)",
                            "    - d/usr.sbin.rsyslogd: allow reading of systemd-journal's dev-log",
                            "      unix socket (LP #2123821)",
                            "    - d/t/control: add isolation-container and skip armhf for test broken",
                            "      by to mysql-server being unavailable on that arch.",
                            "    - d/control, d/p/gnusort-in-tests.patch: Fix ftbfs with tests on",
                            "      armhf by reverting to gnusort on tests with large data for its",
                            "      memory usage. (LP #2137562)",
                            "      [Refreshed the patch]",
                            "    - d/rsyslog.install: usr-merge dmesg.service (LP #2139209)",
                            "    - Update rsyslog apparmor profile to cope with log sockets in",
                            "      chroot directories (LP #2138647):",
                            "      + d/usr.sbin.rsyslogd: add attach_disconnected flag to profile",
                            "      + d/t/{control,haproxy-logging}: new test to confirm the fix",
                            "  * Dropped:",
                            "    - d/p/fix-curl-ftbfs.patch: fix FTBFS with newer curl headers",
                            "      (LP #2143157)",
                            "      [Fixed upstream in 8.2602.0]",
                            "    - SECURITY UPDATE: mmpstrucdata stack buffer overflow with oversized",
                            "      RFC5424 structured data",
                            "      + debian/patches/CVE-2026-61548.patch: remove fixed-size buffer in",
                            "        plugins/mmpstrucdata/mmpstrucdata.c.",
                            "      + CVE-2026-61548",
                            "        [Fixed upstream in 8.2606.0]",
                            "    - SECURITY UPDATE: imptcp regex-framing remote denial of service",
                            "      + debian/patches/imptcp-security.patch: Fix logic in",
                            "        plugins/imptcp/imptcp.c.",
                            "      + CVE number pending",
                            "        [Fixed upstream]",
                            "  * Added:",
                            "    - d/p/format-attribute-ftbfs.patch: add printf format attribute to",
                            "      fix an FTBFS (LP: #2163685)",
                            "    - d/p/openssl4-ftbfs.patch: fix openssl4 FTBFS (LP: #2163702)",
                            "    - d/p/imdtls-dtlsv1-listen-openssl4.patch: fix imdtls with OpenSSL 4.0",
                            "",
                            "  [ Nick Rosbrook ]",
                            "",
                            "  * Fix for /var/log ownership conflict with the systemd package",
                            "    (LP: #2158686):",
                            "    - d/rsyslog.tmpfiles.conf: use ACL instead of fighting for ownership of",
                            "      /var/log",
                            "    - d/ryslog.postinst: do not call systemd-tmpfiles directly",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2608.0-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153351,
                            2163685,
                            2163702,
                            2158686
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Thu, 03 Sep 2026 15:19:49 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-78002",
                                "url": "https://ubuntu.com/security/CVE-2026-78002",
                                "cve_description": "A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-27 17:20:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * rainerscript: Avoid heap buffer overflow in replace() function.",
                            "    Patch cherry-picked from upstream Git.",
                            "    (CVE-2026-78002, Closes: #1145980)",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2608.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Sun, 30 Aug 2026 01:58:01 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix debian/patches/Skip-imfile-logrotate-async.sh.patch to apply correctly",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2608.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Wed, 26 Aug 2026 20:56:22 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip imfile-logrotate-async.sh (again)",
                            "    This test appears to be flaky and fails rather often on",
                            "    reproducible-builds.org and reproduce.d.n.",
                            "    See https://github.com/rsyslog/rsyslog/issues/6293",
                            "    (Closes: #1145527)",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2608.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Wed, 26 Aug 2026 18:44:06 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-19654",
                                "url": "https://ubuntu.com/security/CVE-2026-19654",
                                "cve_description": "A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-12 21:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream version 8.2608.0",
                            "    - imptcp: reject invalid regex-framing recovery transitions",
                            "      (CVE-2026-19654, Closes: #1144616)",
                            "  * Rebase patches.",
                            "    Drop patches that have been merged upstream.",
                            "  * Enable support for Kubernetes-native log input.",
                            "    Ship the new imkubernetes input module within rsyslog-kubernetes.",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2608.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Wed, 19 Aug 2026 20:30:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2606.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Wed, 08 Jul 2026 10:38:12 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add Build-Depends on gdb.",
                            "    This hopefully provides better diagnosis if one of the tests crashes.",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2606.0-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Thu, 02 Jul 2026 22:37:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * config: keep empty include globs silent",
                            "  * testbench: add daemon termination oracle",
                            "  * Use check_LTLIBRARIES to generate liboverride_* test libraries",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2606.0-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Mon, 29 Jun 2026 18:56:48 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 8.2606.0",
                            "  * Drop patches that have been merged upstream",
                            "  * Fix doc version for sphinx-build (again)",
                            "  * Enable YAML support as recommended by upstream",
                            "  * Update debhelper-compat to 14",
                            "  * Re-run previously skipped tests.",
                            "    They are hopefully less flaky now. And if not, we want to see the",
                            "    results.",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2606.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Thu, 25 Jun 2026 13:32:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix debian/patches/Skip-imfile-logrotate-async.sh.patch to apply correctly",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2604.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Wed, 06 May 2026 18:01:09 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert \"Run dh_auto_test with --no-parallel\"",
                            "  * Revert \"Skip imudp_ratelimit_name and ratelimit_name test\"",
                            "  * ratelimit: preserve severity sentinel on unsigned char architectures",
                            "  * queue: quarantine runtime disk corruption safely",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2604.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Wed, 06 May 2026 13:47:21 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip imudp_ratelimit_name and ratelimit_name test.",
                            "    Those tests fail on s390x/riscv64/ppc64el.",
                            "    But they are seemingly not regressions, so skip them for now.",
                            "    (Closes: #1134851)",
                            "  * Bump Standards-Version to 4.7.4",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2604.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Tue, 05 May 2026 20:35:11 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 8.2604.0",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2604.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Wed, 22 Apr 2026 18:36:03 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Michael Biebl ]",
                            "  * New upstream version 8.2602.0",
                            "  * Fix doc version for sphinx-build",
                            "  * Disable (new) impstats-push support.",
                            "    Otherwise this would result in the main rsyslog package getting a",
                            "    dependency on libcurl, libsnappy and libprotobuf-c which seems a bit",
                            "    excessive. An alternative might be, to split off the impstats module",
                            "    into a separate package.",
                            "  * imfile: preserve symlink cleanup notifications with deferred destroy.",
                            "    Patch cherry-picked from upstream Git.",
                            "    https://github.com/rsyslog/rsyslog/issues/6576",
                            "",
                            "  [ Dennis van Dok ]",
                            "  * Include README.Debian section on drop privilege specifics",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2602.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Wed, 25 Mar 2026 15:58:59 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Bump Standards-Version to 4.7.3.",
                            "    Drop Priority and Rules-Requires-Root field.",
                            "  * Add explicit Build-Depends on openssl.",
                            "    It is required by the test suite, so mark it as <!nocheck>.",
                            "    (Closes: #1124951)",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2512.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Wed, 07 Jan 2026 20:32:16 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Helmut Grohne ]",
                            "  * Fix FTCBFS: Demote documentation dependencies to B-D-I.",
                            "    Add an explicit Build-Depends on python3-docutils for generating the man",
                            "    pages. (Closes: #1123696)",
                            "",
                            "  [ Josselin Mouette ]",
                            "  * Enable HTTP output plugin and ship it as rsyslog-http (Closes: #1121114)",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2512.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Biebl <biebl@debian.org>",
                        "date": "Sat, 20 Dec 2025 23:31:28 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-61548",
                                "url": "https://ubuntu.com/security/CVE-2026-61548",
                                "cve_description": "mmpstrucdata stack buffer overflow with oversized RFC5424 structured data",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: imptcp regex-framing remote denial of service",
                            "    - debian/patches/imptcp-security.patch: Fix logic in",
                            "      plugins/imptcp/imptcp.c.",
                            "    - CVE number pending",
                            "  * SECURITY UPDATE: mmpstrucdata stack buffer overflow with oversized",
                            "    RFC5424 structured data",
                            "    - debian/patches/CVE-2026-61548.patch: remove fixed-size buffer in",
                            "      plugins/mmpstrucdata/mmpstrucdata.c.",
                            "    - CVE-2026-61548",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2512.0-1ubuntu6",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Mon, 20 Jul 2026 12:25:41 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "rust-coreutils",
                "from_version": {
                    "source_package_name": "rust-coreutils",
                    "source_package_version": "0.8.0-0ubuntu4",
                    "version": "0.8.0-0ubuntu4"
                },
                "to_version": {
                    "source_package_name": "rust-coreutils",
                    "source_package_version": "0.10.0-1ubuntu2",
                    "version": "0.10.0-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2165041,
                    2163175,
                    2134860,
                    2159679,
                    2132368,
                    2137580,
                    2142900,
                    2150342,
                    2157011,
                    2157342,
                    2116290,
                    2158691,
                    2160614,
                    2153168,
                    2154338,
                    2154042,
                    2152801,
                    2146819,
                    2146818,
                    2155763,
                    2115782
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/cp-fix-symlink-target-permissions.patch: Fix an issue where cp",
                            "    would alter the permissions of the source file, such as stripping the",
                            "    setuid bit (LP: #2165041)",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.10.0-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165041
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Wed, 26 Aug 2026 16:29:49 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon Johnsson ]",
                            "  * Merge with Debian unstable. Remaining changes: (LP: #2163175)",
                            "    - Install libstdbuf.so: Modify d/rules to export LIBSTDBUF_DIR as to not",
                            "      skip stdbuf, fix libstdbuf.so permissions, and install it in",
                            "      rust-coreutils.install.",
                            "    - Install hardlinks: Rename rust-coreutils.links to",
                            "      rust-coreutils.hardlinks.",
                            "    - Enable feat_systemd_logind: This allows commands such as who and pinky",
                            "      to work correctly. Introduces libsystemd-dev as a dependency.",
                            "    - Remove Build-Depends on lld: Debian added it as the preferred linker,",
                            "      but some partial architectures like i386 may be missing it.",
                            "    - d/rules: Fix vendored sources field creation. Debian does not have",
                            "      access to dh-cargo-vendored-sources so it uses a script instead.",
                            "      Change it to use dh-cargo-vendored-sources on Ubuntu instead.",
                            "    - d/rules: Skip failing tests.",
                            "    - Add patches:",
                            "      + build-stty",
                            "      + dd-ensure-full-writes",
                            "      + require-utility-to-be-invoked-at-matching-path",
                            "      + Tweak-release-build-profile",
                            "      + rust-vendor/glibc-2.42",
                            "      + rustix-use-libc-backend",
                            "    - Remove upstream patches:",
                            "      + fix-ppc64el-baudrate.diff: Launchpad's builders instead fails on",
                            "        ppc64le for this patch, the original source code is correct.",
                            "    - Update vendored rust crates",
                            "    - debian/control: Update XS-Vendored-Sources-Rust field",
                            "  * Drop changes:",
                            "    - Remove patches fixed upstream:",
                            "      + cp-respect-composite-flag",
                            "      + fix-cp-parents",
                            "      + fix-incomplete-locale-bundles",
                            "      + fix-locale-path: Debian adopted this patch.",
                            "  * New changes:",
                            "    - debian/patches/remove-workspace-members.patch: Remove workspace member",
                            "      array to prevent dh-cargo bypassing workspace-exclude.patch. Otherwise",
                            "      vendored dependencies would still think that they're part of the",
                            "      workspace.",
                            "  * Fixes:",
                            "    - File ownership changes when a file is mv'ed by root to a different file",
                            "      system (LP: #2134860)",
                            "    - Failing to build images: mv resolv.conf.tmp",
                            "      /build/chroot/etc/resolv.conf mv: File exists (os error 17)",
                            "      (LP: #2159679)",
                            "    - unaligned plus in \"ls -l\" output (LP: #2132368)",
                            "    - git-buildpackage ftbfs on resolute-proposed due to rust coreutils",
                            "      (LP: #2137580)",
                            "    - env: signal flags do not understand RTMIN+n notation (LP: #2142900)",
                            "    - date: width prefix in %N format specifier is ignored",
                            "      ( %3N, %6N always output full 9 nanosecond digits) (LP: #2150342)",
                            "    - changes in behaviour of cp in coreutils-from-uutils break test case in",
                            "      util-linux (LP: #2157011)",
                            "    - systemd: TEST-45-TIMEDATE is flaky with rust coreutils (LP: #2157342)",
                            "",
                            "  [ Varun Varma ]",
                            "  * debian/patches/df-statfs-fallback.patch: Add a fallback to statfs if the",
                            "    mount path could not be found normally (LP: #2116290).",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.10.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163175,
                            2134860,
                            2159679,
                            2132368,
                            2137580,
                            2142900,
                            2150342,
                            2157011,
                            2157342,
                            2116290
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Tue, 11 Aug 2026 18:06:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Rework the source package to match the layout used by Ubuntu, so that",
                            "    merging Debian into Ubuntu no longer means undoing our repack:",
                            "    - Drop debian/repack.sh: the orig tarball is now the pristine GitHub tag.",
                            "    - d/watch: new, fetching the upstream tag plus the translations from",
                            "      uutils/coreutils-l10n as an l10n component tarball (unpacked in l10n/).",
                            "      Written in the version=4 syntax because devscripts in Debian does not",
                            "      support the newer \"Version: 5\" templates yet.",
                            "    - The vendored crates move out of the orig tarball into",
                            "      debian/rust-vendor/, generated by the new \"debian/rules vendor\" target",
                            "      with cargo-vendor-filterer (tier 2, *-*-linux-gnu* only). Vendor-only",
                            "      patches now have their own quilt series, debian/patches/rust-vendor/,",
                            "      applied by dh_quilt_patch; Build-Depends on quilt accordingly.",
                            "    - d/control: add the XS-Vendored-Sources-Rust field.",
                            "    - d/README.source: document the whole workflow.",
                            "  * debian/patches:",
                            "    - Drop use-vendor.diff, handled by \"cargo prepare-debian\" now.",
                            "    - Drop disable-utmp-classic.diff: utmp-classic is an OpenBSD-only target",
                            "      dependency, so it is never built on Linux; only its (unused) vendored",
                            "      copy remains. Ubuntu dropped the patch for the same reason.",
                            "    - Replace fix-locale-path.diff by Ubuntu's fix-locale-path.patch and add",
                            "      their use-l10n-translations-in-makefile.patch, the translations being",
                            "      installed from l10n/ instead of src/uu/*/locales/.",
                            "    - New workspace-exclude.patch, to keep debian/rust-vendor out of the",
                            "      cargo workspace.",
                            "    - Rebase the remaining patches on 0.10.0 and refresh the whole series",
                            "      with standard -p1 headers.",
                            "  * Ship debian/tldr.zip (English pages only): the pristine tarball does not",
                            "    carry the tldr archive that improve-man.diff turns into the EXAMPLES",
                            "    section of the manpages, and the build has no network access.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.10.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Thu, 06 Aug 2026 00:20:00 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Use the debian/changelog date (via SOURCE_DATE_EPOCH) for the",
                            "    generated manpage date instead of the current build date, so the",
                            "    package builds reproducibly. New patch reproducible-man-date.diff.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Thu, 04 Jun 2026 11:12:51 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon Johnsson ]",
                            "  * Remove lld as dependency as it is not available on i386:",
                            "    - d/control: Remove Build-Depends lld",
                            "    - d/rules: Change RUSTFLAGS to omit lld",
                            "  * debian/patches:",
                            "    - cp-respect-composite-flag: Cherry-pick fix from upstream for issue",
                            "      where the -a flag is not considered recursive due to flag stripping",
                            "      (LP: #2158691)",
                            "",
                            "  [ Varun Varma ]",
                            "  * debian/patches:",
                            "    - rustix-use-libc-backend: Switch rustix backend to libc to solve",
                            "      the error where tools that rely on LD_PRELOAD have altered",
                            "      behaviour with the default rustix backend (LP: #2160614).",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158691,
                            2160614
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Tue, 14 Jul 2026 17:15:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable. Remaining changes: (LP: #2153168)",
                            "    - Install libstdbuf.so",
                            "    - Install hardlinks",
                            "    - Refresh upstream patches",
                            "    - Use direct GitHub tarball instead of debian/repack.sh",
                            "    - d/rules:",
                            "      + Add vendoring targets",
                            "      + Build verbosely",
                            "      + Skip failing tests",
                            "    - d/watch: add watch file",
                            "    - d/patches:",
                            "      + Tweak-release-build-profile.patch",
                            "      + workspace-exclude.patch",
                            "      + build-stty.patch",
                            "      + require-utility-to-be-invoked-at-matching-path.patch",
                            "      + glibc-2.42.patch",
                            "      + dd-ensure-full-writes.patch",
                            "      + use-l10n-translations-in-makefile.patch",
                            "      + fix-locale-path.patch",
                            "      + fix-incomplete-locale-bundles.patch",
                            "    - d/control: update XS-Vendored-Sources-Rust field",
                            "    - vendor: update vendored deps",
                            "    - l10n/: update translations",
                            "  * Fixes:",
                            "    - xattrs break ls formatting (LP: #2154338)",
                            "    - ls: files are not sorted in alphabetical order when using",
                            "      --group-directories-first or if LC_ALL is unset (LP: #2154042)",
                            "  * Drop changes:",
                            "    - d/p/tee-fix-input-with-sleep.patch: The underlying issue was fixed",
                            "      upstream, so drop the patch.",
                            "  * New changes:",
                            "    - Enable feat_systemd_logind to fix who not showing output",
                            "      (LP: #2152801, LP: #2146819, LP: #2146818)",
                            "      + d/control: Add libsystemd-dev as a dependency.",
                            "      + d/rules: Link systemd and add feat_systemd_logind to CARGOFLAGS.",
                            "    - d/p/fix-cp-parents.patch: Cherry-pick fix from upstream for cp --parents",
                            "      bug resulting in build failures (LP: #2155763)",
                            "    - Remove unnecessary upstream patches:",
                            "      + disable-utmp-classic.diff",
                            "      + fix-locale-path.diff: Locale handling is different on Ubuntu, using",
                            "        l10n (see the new fix-locale-path.patch).",
                            "      + fix-man.diff: Uncommented in the upstream series.",
                            "      + fix-ppc64el-baudrate.diff: Launchpad's builders instead fails on",
                            "        ppc64le for this patch, the original source code is correct.",
                            "      + use-vendor.diff: Vendor handling is different on Ubuntu.",
                            "    - Remove docs/tldr.zip from Debian upstream",
                            "    - Delete locales shipped in Debian upstream under src/",
                            "    - Move vendored dependencies to debian/",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153168,
                            2154338,
                            2154042,
                            2152801,
                            2146819,
                            2146818,
                            2155763
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Thu, 04 Jun 2026 15:54:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix the i386 (32-bit) FTBFS (OOM): the test build did fat LTO +",
                            "    codegen-units=1 + full debuginfo on the giant all-utils crate and ran out",
                            "    of the ~3GB address space. Set CARGO_PROFILE_RELEASE_LTO=thin,",
                            "    CODEGEN_UNITS=16 and DEBUG=1 via env on all 32-bit arches so every cargo",
                            "    invocation honours them, replacing the sed hacks that missed the test step.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Sun, 31 May 2026 10:04:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Sat, 30 May 2026 17:07:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix the s390x FTBFS (150min buildd inactivity timeout). The previous",
                            "    sed only disabled LTO around dh_auto_install, so the default build and",
                            "    the test build still did fat LTO + codegen-units=1 + full debuginfo on",
                            "    the giant all-utils crate, which is what actually timed out. Now set",
                            "    CARGO_PROFILE_RELEASE_LTO=false, CODEGEN_UNITS=16 and DEBUG=1 via env so",
                            "    every cargo invocation honours them.",
                            "  * Skip the (non-gating) test suite on s390x: the release test build was",
                            "    the step hitting the timeout (killed at \"Compiling unindent\").",
                            "  * Use lld as the linker on every architecture when it is available, not",
                            "    just on s390x: ld.lld is detected at build time (via command -v) and",
                            "    -fuse-ld=lld is added when present, falling back to the default linker",
                            "    otherwise. lld links the multicall binary much faster than GNU ld.",
                            "    Build-Depend on lld on all architectures (it ships from the same",
                            "    llvm-toolchain source as the already-required libclang-dev).",
                            "  * Log the linker on every architecture: emit the -Wl,-v banner on every",
                            "    link and print rustc -vV / ld.lld / ld at configure time, so every build",
                            "    log records which linker ran. Previously the ld.lld check lived in",
                            "    dh_auto_install (never reached when the build timed out) and only on s390x.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Thu, 28 May 2026 08:08:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Disable LTO on s390x: thin LTO + lld in 0.8.0-4 still timed out on",
                            "    the buildd, so turn LTO off entirely on s390x.",
                            "  * Print ld.lld version and ask the linker to log itself (-Wl,-v) so",
                            "    the build log shows which linker was actually invoked.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Wed, 27 May 2026 23:11:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Use lld as the linker on s390x: thin LTO alone in 0.8.0-3 did not",
                            "    unblock the buildd timeout, so switch the final link to ld.lld.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Wed, 27 May 2026 08:04:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Use thin LTO on s390x to avoid linker timeouts on the buildd",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Wed, 27 May 2026 08:04:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * try to unbreak the ppc64 build",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Sun, 17 May 2026 14:58:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release (Closes: #1134876)",
                            "  * Improve the manpage (LP: #2115782)",
                            "  * Add manpage symlink for coreutils binary (no-manual-page)",
                            "  * Extend disable-utmp-classic.diff to cover the new",
                            "    [target.'cfg(target_os = \"openbsd\")'.dependencies] block in",
                            "    src/uucore/Cargo.toml introduced upstream in 0.8.0 (fixes FTBFS).",
                            "  * Disable fix-man.diff: it converts .ftl bullet markers from `-` to `*`",
                            "    and rewrites top-level `key = value` lines as markdown bullets, which",
                            "    is invalid Fluent syntax. uudoc loads each utility's locale via",
                            "    setup_localization_or_exit and was aborting manpage generation with",
                            "    a Localization parse error. Patch kept in debian/patches/ but",
                            "    commented out in series until it can be rewritten Fluent-cleanly.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2115782
                        ],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Wed, 06 May 2026 13:08:52 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * Move to https://salsa.debian.org/rust-team/coreutils",
                            "  * Improve the manpages example display",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.7.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Mon, 09 Mar 2026 06:59:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * Vendor dependencies. Too hard to maintain in Debian",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.6.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Tue, 17 Feb 2026 13:48:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "",
                            "  [ Jeremy Bícha]",
                            "  * remove unused Build-Depends: librust-unix-socket-dev",
                            "",
                            "  [ Peter Michael Green ]",
                            "  * Add patch for nix 0.30",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.0.30-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Peter Michael Green <plugwash@debian.org>",
                        "date": "Tue, 30 Sep 2025 12:45:34 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Bump the notify dependency to v8",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.0.30-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "NoisyCoil <noisycoil@debian.org>",
                        "date": "Wed, 24 Sep 2025 19:38:04 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Also ship with b3sum (Closes: #1107092)",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.0.30-3~exp1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Mon, 02 Jun 2025 20:43:15 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "strace",
                "from_version": {
                    "source_package_name": "strace",
                    "source_package_version": "6.19+ds-0ubuntu5",
                    "version": "6.19+ds-0ubuntu5"
                },
                "to_version": {
                    "source_package_name": "strace",
                    "source_package_version": "7.0+ds-1ubuntu1",
                    "version": "7.0+ds-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158786
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2158786). Remaining changes:",
                            "    - d/p/lp2142588-fix-date-formatting.patch: resolve ftbfs (LP #2142588)",
                            "    - d/p/ioctl-fix-ftbfs-c23.patch: resolve ftbfs (LP #2142890)",
                            "    - d/control: add new libncurses-dev dependency for termcap checks (LP #2142281)",
                            "    - d/rules, d/control: use GNU rm when clearing test artifacts on",
                            "      32-bit architectures to workaround the rust-coreutils bug (LP #2148301)",
                            "  * New Changes:",
                            "    - d/p/io-uring-linux-7.1.patch: fix FTBFS with Linux 7.1 headers.",
                            "  * Drop Changes:",
                            "    - Drop the s390x gcc-multilib Build-Depends delta.",
                            "    - Drop the color output patch.",
                            "    - Drop the upstream strace 6.19 import.",
                            "    - Drop the non-vDSO syscall filtering patch.",
                            "    - Drop the Linux 7.0-rc3 header, decoder, and test patches.",
                            ""
                        ],
                        "package": "strace",
                        "version": "7.0+ds-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158786
                        ],
                        "author": "Zineb Zaadoud <zineb.zaadoud@canonical.com>",
                        "date": "Thu, 13 Aug 2026 14:34:51 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream OpenPGP signing key",
                            "  * New upstream version 7.0+ds. (Closes: #1131592)",
                            "  * Drop 1000-*-vDSO.patch which applied by upstream",
                            "  * d/control: Standards-Version: 4.7.4 (routine-update)",
                            "  * d/control: drop redundanty Priority field",
                            "  * Add d/strace64.lintian-overrides and dh_lintian to override ",
                            "    expected biarch binary",
                            ""
                        ],
                        "package": "strace",
                        "version": "7.0+ds-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bo YU <vimer@debian.org>",
                        "date": "Fri, 05 Jun 2026 11:18:44 +0800"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Making non-fatal tests on armhf due to the issue upstream known.",
                            "    (Closes: #1125942)",
                            "  * Drop gcc-multilib build-dependency on s390x. (Closes: #1125246)",
                            "    Thanks to Aurelien Jarno <aurel32@debian.org>",
                            ""
                        ],
                        "package": "strace",
                        "version": "6.18+ds-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bo YU <vimer@debian.org>",
                        "date": "Sun, 25 Jan 2026 16:39:48 +0800"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * switch to debian-watch 5",
                            "  * New upstream version 6.18. (Closes: #1122484)",
                            ""
                        ],
                        "package": "strace",
                        "version": "6.18+ds-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bo YU <vimer@debian.org>",
                        "date": "Wed, 24 Dec 2025 12:39:14 +0800"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "sudo",
                "from_version": {
                    "source_package_name": "sudo",
                    "source_package_version": "1.9.17p2-7ubuntu1",
                    "version": "1.9.17p2-7ubuntu1"
                },
                "to_version": {
                    "source_package_name": "sudo",
                    "source_package_version": "1.9.17p2-7ubuntu3",
                    "version": "1.9.17p2-7ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2156801,
                    2161810
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/04-getroot-sssd: adjust slapd apparmor for autopkgtests",
                            "    (LP: #2156801)",
                            "  * d/p/openssl4-ftbfs-fix.patch: fix build with OpenSSL4 (LP: #2161810)",
                            "  * d/t/03-1126085-sudoersd: make sure we are using sudo.ws for this",
                            "    test, since this is the package shipping the sudo.ws implementation",
                            ""
                        ],
                        "package": "sudo",
                        "version": "1.9.17p2-7ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2156801,
                            2161810
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 18 Aug 2026 15:35:45 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "sudo",
                        "version": "1.9.17p2-7ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 11:21:47 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "sudo-rs",
                "from_version": {
                    "source_package_name": "rust-sudo-rs",
                    "source_package_version": "0.2.13-0ubuntu1",
                    "version": "0.2.13-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "rust-sudo-rs",
                    "source_package_version": "0.2.14-1ubuntu2",
                    "version": "0.2.14-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2159633,
                    2156983,
                    2153817,
                    2158541,
                    2152220,
                    2146860
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/04-getroot-sssd: Fix test by restarting slapd with systemd",
                            "    and add some more robustness",
                            ""
                        ],
                        "package": "rust-sudo-rs",
                        "version": "0.2.14-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Grayson Wolf <grayson.wolf@canonical.com>",
                        "date": "Mon, 13 Jul 2026 10:42:31 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2159633). Remaining changes:",
                            "    - drop unnecessary upstream patches:",
                            "      + auto/auto-remove-features",
                            "      + disable-test-timeout",
                            "    - d/rules:",
                            "      + add vendoring targets",
                            "      + set setuid bit after dh_fixperms",
                            "      + change DEB_CARGO_INSTALL_PREFIX",
                            "      + set features and skip tests in dh_auto_test",
                            "      + set SUDO_RS_VERSION",
                            "    - Add autopkgtest and centralize cargo build features",
                            "    - Remove librust-sudo-rs-dev",
                            "    - debian/control:",
                            "      + add Depends sudo-common",
                            "      + add Recommends apport",
                            "      + add Recommends libapparmor1",
                            "      + remove vendored librust Build-Depends",
                            "      + update XS-Vendored-Sources-Rust field",
                            "    - debian/README.source: add vendoring instructions",
                            "    - debian/copyright: update information",
                            "    - rust-vendor: update vendored dependencies",
                            "    - Skip pandoc on i386",
                            "    - Add and modify sudo.ws tests",
                            "    - Add sudo alternatives",
                            "    - Add apport package hook",
                            "    - Add cargo-auditable metadata",
                            "  * Fixes:",
                            "    - Remove unnecessary python dependency: Replace Depends python3:any with",
                            "      Recommends apport as that better aligns with the apport hook intent",
                            "      (LP: #2156983)",
                            "    - PAM_TTY is wrongly computed by sudo-rs (LP: #2153817)",
                            "    - sudo-rs fails with \"I'm sorry\" message in systems with large groups",
                            "      (LP: #2158541)",
                            "    - [security] sudo-rs ≤ 0.2.13: silent drop of argument restrictions on",
                            "      \\<newline> line continuation (LPE) (LP: #2152220)",
                            "    - command permanently stop (LP: #2146860)",
                            "  * New Changes:",
                            "    - Use debian/rust-vendor for vendoring as this allows changing the",
                            "      versions of vendored dependencies without bumping the upstream version.",
                            "  * Drop Changes:",
                            "    - debian/patches:",
                            "      + fix-toggle-pwfeedback-tab: Fixed upstream.",
                            "    - wrap-and-sort debian/ files: Dropped as it created unnecessary delta",
                            "      with Debian.",
                            ""
                        ],
                        "package": "rust-sudo-rs",
                        "version": "0.2.14-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159633,
                            2156983,
                            2153817,
                            2158541,
                            2152220,
                            2146860
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Wed, 08 Jul 2026 11:50:23 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Package sudo-rs 0.2.14 from crates.io using debcargo 2.8.3",
                            "  * Notable upstream changes:",
                            "    - timestamp files created with sudo-rs <= 0.2.10 are invalidated",
                            "    - `Defaults pwfeedback` is now on by default, TAB will turn off visual",
                            "    feedback during password prompts",
                            "    - `su` will allow changing to an account that has no password set, making",
                            "    su-rs consistent with util-linux and FreeBSD `su`",
                            ""
                        ],
                        "package": "rust-sudo-rs",
                        "version": "0.2.14-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Fabian Grünbichler <debian@fabian.gruenbichler.email>",
                        "date": "Sun, 05 Jul 2026 20:24:59 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/tests: Add test suit from sudo.ws and change expected outputs",
                            "    to match sudo-rs output formats.",
                            ""
                        ],
                        "package": "rust-sudo-rs",
                        "version": "0.2.13-0ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Varun Varma <varun.varma@canonical.com>",
                        "date": "Wed, 01 Apr 2026 09:56:32 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "systemd",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "systemd-cryptsetup",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "systemd-resolved",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "systemd-sysv",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "tcpdump",
                "from_version": {
                    "source_package_name": "tcpdump",
                    "source_package_version": "4.99.6-2",
                    "version": "4.99.6-2"
                },
                "to_version": {
                    "source_package_name": "tcpdump",
                    "source_package_version": "4.99.6-2build1",
                    "version": "4.99.6-2build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "tcpdump",
                        "version": "4.99.6-2build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 16:31:09 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "thin-provisioning-tools",
                "from_version": {
                    "source_package_name": "thin-provisioning-tools",
                    "source_package_version": "1.1.0-4ubuntu2",
                    "version": "1.1.0-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "thin-provisioning-tools",
                    "source_package_version": "1.1.0-5.1ubuntu1",
                    "version": "1.1.0-5.1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153258
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153258). Remaining changes:",
                            "    - initramfs-hook: Combine calls to manual_add_modules (LP #2065180)",
                            "    - Vendorize rust dependencies (LP #2091303):",
                            "      + d/rules: allow builds with vendorized rust dependencies",
                            "      + d/p/debian-changes: do not patch Cargo.toml. There is need since",
                            "        we are now using vendored dependencies",
                            "      + d/control:",
                            "        - add XS-Vendored-Sources-Rust field",
                            "        - set X-Cargo-Built-Using field. This is currently redundant",
                            "          with Static-Built-Using. Let's set both for now to make sure",
                            "          we cover cases where one may be consuming one or another until",
                            "          we have an agreement on which should be set",
                            "      + vendor: add vendorized rust dependencies",
                            "      + d/p/vendor-remove-unused-deps: remove unused rust dependencies",
                            "  * New changes:",
                            "    - d/control: remove rust B-D since they are vendored, add missing",
                            "      B-D caused by these removals.",
                            "      (part of \"Vendorize rust dependencies\")",
                            "    - d/README.source.md: add instructions on how to update vendor deps",
                            "      (part of \"Vendorize rust dependencies\")",
                            "  * Dropped changes:",
                            "    - fix i386 builds due to rust libraries missing in Ubuntu",
                            "      [No needed since we drop all Rust BD-Ds in a new change, also no need",
                            "       to exclude i386 for other B-Ds]",
                            ""
                        ],
                        "package": "thin-provisioning-tools",
                        "version": "1.1.0-5.1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153258
                        ],
                        "author": "Hector Cao <hector.cao@canonical.com>",
                        "date": "Tue, 04 Aug 2026 18:43:06 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Non-maintainer upload.",
                            "  * Patch for roaring 0.11. (Closes: #1134124)",
                            ""
                        ],
                        "package": "thin-provisioning-tools",
                        "version": "1.1.0-5.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Adrian Bunk <bunk@debian.org>",
                        "date": "Mon, 15 Jun 2026 15:09:07 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update rust dependencies, again. (closes: #1117378)",
                            ""
                        ],
                        "package": "thin-provisioning-tools",
                        "version": "1.1.0-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Blank <waldi@debian.org>",
                        "date": "Sun, 19 Oct 2025 14:15:27 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "tmux",
                "from_version": {
                    "source_package_name": "tmux",
                    "source_package_version": "3.6b-1",
                    "version": "3.6b-1"
                },
                "to_version": {
                    "source_package_name": "tmux",
                    "source_package_version": "3.7b-1",
                    "version": "3.7b-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Sébastien Delafond ]",
                            "  * New upstream version 3.7b",
                            ""
                        ],
                        "package": "tmux",
                        "version": "3.7b-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastien Delafond <seb@debian.org>",
                        "date": "Sat, 04 Jul 2026 05:54:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Sébastien Delafond ]",
                            "  * New upstream version 3.7",
                            ""
                        ],
                        "package": "tmux",
                        "version": "3.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastien Delafond <seb@debian.org>",
                        "date": "Sat, 27 Jun 2026 07:32:15 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "tnftp",
                "from_version": {
                    "source_package_name": "tnftp",
                    "source_package_version": "20260211-2",
                    "version": "20260211-2"
                },
                "to_version": {
                    "source_package_name": "tnftp",
                    "source_package_version": "20260211-2build1",
                    "version": "20260211-2build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "tnftp",
                        "version": "20260211-2build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 16:32:26 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-kernel-accessories",
                "from_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.574",
                    "version": "1.574"
                },
                "to_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.575",
                    "version": "1.575"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Kat Kuo ]",
                            "  * Refreshed dependencies",
                            "  * Removed ubuntu-report from desktop-minimal-recommends, desktop-",
                            "    raspi-recommends, desktop-recommends",
                            ""
                        ],
                        "package": "ubuntu-meta",
                        "version": "1.575",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Didier Roche-Tolomelli <didrocks@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:23:44 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-keyring",
                "from_version": {
                    "source_package_name": "ubuntu-keyring",
                    "source_package_version": "2023.11.28.1build1",
                    "version": "2023.11.28.1build1"
                },
                "to_version": {
                    "source_package_name": "ubuntu-keyring",
                    "source_package_version": "2026.08.18",
                    "version": "2026.08.18"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2163397
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop ubuntu-keyring-udeb",
                            "  * Remove obsolete postinst scripts",
                            "  * Remove cdimage fragment and add ubuntu-cdimage-keyring.gpg",
                            "  * Rename GnuPG to OpenPGP",
                            "  * Remove transitional ubuntu-cloudimage-keyring",
                            "  * ubuntu-archive-keyring: Remove the cdimage key",
                            "  * Update keys with new self-signatures (LP: #2163397)",
                            "    - ubuntu-cloudimage-keyring",
                            "    - ubuntu-dbgsym-keyring",
                            "  * Regenerate fragments with `sq`",
                            ""
                        ],
                        "package": "ubuntu-keyring",
                        "version": "2026.08.18",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163397
                        ],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 23:33:48 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-minimal",
                "from_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.574",
                    "version": "1.574"
                },
                "to_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.575",
                    "version": "1.575"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Kat Kuo ]",
                            "  * Refreshed dependencies",
                            "  * Removed ubuntu-report from desktop-minimal-recommends, desktop-",
                            "    raspi-recommends, desktop-recommends",
                            ""
                        ],
                        "package": "ubuntu-meta",
                        "version": "1.575",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Didier Roche-Tolomelli <didrocks@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:23:44 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-release-upgrader-core",
                "from_version": {
                    "source_package_name": "ubuntu-release-upgrader",
                    "source_package_version": "1:26.10.3",
                    "version": "1:26.10.3"
                },
                "to_version": {
                    "source_package_name": "ubuntu-release-upgrader",
                    "source_package_version": "1:26.10.8",
                    "version": "1:26.10.8"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158525,
                    2166785,
                    2154822,
                    2154822
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * DistUpgradeQuirks: Add check for mysql_native_password use (LP: #2158525).",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.8",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158525
                        ],
                        "author": "Lena Voytek <lena.voytek@canonical.com>",
                        "date": "Tue, 08 Sep 2026 13:38:26 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * tests: test against recent releases",
                            "  * Use `sqv` instead of `gpgv` (LP: #2166785)",
                            "  * Run pre-build.sh to update templates and version",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.7",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166785
                        ],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 08 Sep 2026 17:18:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fixes for LP: #2154822:",
                            "    - DistUpgradeController: Fix rewriteMirrorUri to strip the country mirror",
                            "      on archs served by ports.u.c",
                            "    - test_sources_list: Disable test_apt_cacher_and_apt_bittorent on archs",
                            "      served by ports.u.c (rewriteMirrorUri now correctly causes changes that",
                            "      differ by architecture, and the test will only pass on archs served by",
                            "      archive.u.c)",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.6",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154822
                        ],
                        "author": "Dave Jones <dave.jones@canonical.com>",
                        "date": "Tue, 08 Sep 2026 12:09:21 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * DistUpgradeController: Split entries when the architecture(s) of the",
                            "    entry now reside on a different host, e.g. 26.04 where arm64 migrated",
                            "    from ports.u.c to archive.u.c (LP: #2154822)",
                            "  * DistUpgradeQuirks: minor changes to fix autopkgtest errors",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154822
                        ],
                        "author": "Dave Jones <dave.jones@canonical.com>",
                        "date": "Tue, 01 Sep 2026 20:33:49 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Florent 'Skia' Jacquet ]",
                            "  * test_pycodestyle: give a more verbose output upon failure",
                            "  * Add .launchpad.yaml to run at least some basic checks directly from git",
                            "  * Fix Stonking version number in announcements",
                            "",
                            "  [ kkuo ]",
                            "  * Remove unnecessary Ubuntu Insights consent migration logic",
                            "",
                            "  [ Oliver Reiche ]",
                            "  * DistUpgrade: fix release announcements for stonking",
                            "",
                            "  [ Alessandro Astone ]",
                            "  * Add quirk for installing dbus-broker",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Mon, 31 Aug 2026 12:01:33 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-server",
                "from_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.574",
                    "version": "1.574"
                },
                "to_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.575",
                    "version": "1.575"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Kat Kuo ]",
                            "  * Refreshed dependencies",
                            "  * Removed ubuntu-report from desktop-minimal-recommends, desktop-",
                            "    raspi-recommends, desktop-recommends",
                            ""
                        ],
                        "package": "ubuntu-meta",
                        "version": "1.575",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Didier Roche-Tolomelli <didrocks@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:23:44 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-standard",
                "from_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.574",
                    "version": "1.574"
                },
                "to_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.575",
                    "version": "1.575"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Kat Kuo ]",
                            "  * Refreshed dependencies",
                            "  * Removed ubuntu-report from desktop-minimal-recommends, desktop-",
                            "    raspi-recommends, desktop-recommends",
                            ""
                        ],
                        "package": "ubuntu-meta",
                        "version": "1.575",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Didier Roche-Tolomelli <didrocks@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:23:44 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "udev",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "udisks2",
                "from_version": {
                    "source_package_name": "udisks2",
                    "source_package_version": "2.11.1-2ubuntu1",
                    "version": "2.11.1-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "udisks2",
                    "source_package_version": "2.11.2-1ubuntu1",
                    "version": "2.11.2-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-7867",
                        "url": "https://ubuntu.com/security/CVE-2026-7867",
                        "cve_description": "A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-06 22:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable. Remaining changes:",
                            "  * d/p/nvme-disk-size.patch:",
                            "    - use upstream candidate fix for getting the size of nvme drives",
                            "      note: the upstream patch was merged as PR 1457 with different content.",
                            "      It should be syncable when 2.11.90 branch is released",
                            ""
                        ],
                        "package": "udisks2",
                        "version": "2.11.2-1ubuntu1",
                        "urgency": "low",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Gianfranco Costamagna <locutusofborg@debian.org>",
                        "date": "Mon, 24 Aug 2026 09:50:19 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-7867",
                                "url": "https://ubuntu.com/security/CVE-2026-7867",
                                "cve_description": "A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-06 22:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream version 2.11.2.",
                            "    - Fixes local privilege escalation via 'as-user' mount spoofing",
                            "      (CVE-2026-7867)",
                            ""
                        ],
                        "package": "udisks2",
                        "version": "2.11.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alberto Garcia <berto@igalia.com>",
                        "date": "Thu, 06 Aug 2026 17:41:56 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "update-notifier-common",
                "from_version": {
                    "source_package_name": "update-notifier",
                    "source_package_version": "3.210",
                    "version": "3.210"
                },
                "to_version": {
                    "source_package_name": "update-notifier",
                    "source_package_version": "3.212",
                    "version": "3.212"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1957863
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * data/notify-reboot-required: Drop legacy Canonical Livepatch reboot-",
                            "    marker suppression.",
                            ""
                        ],
                        "package": "update-notifier",
                        "version": "3.212",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Zara Grigoryan <zara.grigoryan@canonical.com>",
                        "date": "Tue, 01 Sep 2026 06:37:14 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * data/update-motd-fsck-at-reboot: Fix script errors (LP: #1957863)",
                            "  * tests: Ensure local HTTP fixture requests bypass the testbed's APT",
                            "    proxy",
                            ""
                        ],
                        "package": "update-notifier",
                        "version": "3.211",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1957863
                        ],
                        "author": "Varun Varma <varun.varma@canonical.com>",
                        "date": "Tue, 11 Aug 2026 17:30:58 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "wget",
                "from_version": {
                    "source_package_name": "wget",
                    "source_package_version": "1.25.0-2ubuntu4",
                    "version": "1.25.0-2ubuntu4"
                },
                "to_version": {
                    "source_package_name": "wget",
                    "source_package_version": "1.25.0-2ubuntu6",
                    "version": "1.25.0-2ubuntu6"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-58469",
                        "url": "https://ubuntu.com/security/CVE-2026-58469",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58470",
                        "url": "https://ubuntu.com/security/CVE-2026-58470",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58471",
                        "url": "https://ubuntu.com/security/CVE-2026-58471",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58472",
                        "url": "https://ubuntu.com/security/CVE-2026-58472",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58469",
                                "url": "https://ubuntu.com/security/CVE-2026-58469",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58470",
                                "url": "https://ubuntu.com/security/CVE-2026-58470",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58471",
                                "url": "https://ubuntu.com/security/CVE-2026-58471",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58472",
                                "url": "https://ubuntu.com/security/CVE-2026-58472",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Buffer overflow in metalink.",
                            "    - debian/patches/CVE-2026-58469.patch: Fix buffer overflow in",
                            "      src/metalink.c",
                            "    - CVE-2026-58469",
                            "  * SECURITY UPDATE: Integer overflow in http",
                            "    - debian/patches/CVE-2026-58470.patch: Fix integer overflow in src/http.c",
                            "    - CVE-2026-58470",
                            "  * SECURITY UPDATE: Buffer overflow in convert_fname.",
                            "    - debian/patches/CVE-2026-58471.patch: Fix buffer overflow in src/url.c",
                            "    - CVE-2026-58471",
                            "  * SECURITY UPDATE: Integer and buffer overflow in html_quote_string.",
                            "    - debian/patches/CVE-2026-58472.patch: Fix integer+buffer overflow in",
                            "      src/convert.c",
                            "    - CVE-2026-58472",
                            ""
                        ],
                        "package": "wget",
                        "version": "1.25.0-2ubuntu6",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Fri, 10 Jul 2026 17:22:16 -0600"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "wireless-regdb",
                "from_version": {
                    "source_package_name": "wireless-regdb",
                    "source_package_version": "2026.02.04-0ubuntu1",
                    "version": "2026.02.04-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "wireless-regdb",
                    "source_package_version": "2026.05.30-0ubuntu1",
                    "version": "2026.05.30-0ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2163172
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 2026.05.30 (LP: #2163172)",
                            "    - debian/control: Exchange python3-m2crypto build dependency for",
                            "      python3-cryptography",
                            ""
                        ],
                        "package": "wireless-regdb",
                        "version": "2026.05.30-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163172
                        ],
                        "author": "Jacob Martin <jacob.martin@canonical.com>",
                        "date": "Mon, 10 Aug 2026 10:02:11 -0500"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "added": {
        "deb": [
            {
                "name": "libproc2-1:ppc64el",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "procps",
                    "source_package_version": "2:4.0.6-3ubuntu1",
                    "version": "2:4.0.6-3ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153347
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable (LP: #2153347). Remaining changes:",
                            "    - debian/sysctl.d:",
                            "      + 55-console-messages.conf: stop low-level kernel messages on console.",
                            "      + 55-kernel-hardening.conf: add the kptr_restrict setting",
                            "      + 55-ipv6-privacy.conf: add a file to sysctl.d to apply the defaults",
                            "        for IPv6 privacy extensions for interfaces. (LP #176125, #841353)",
                            "      + 55-magic-sysrq.conf: Disable most magic sysrq by default, allowing",
                            "        critical sync, remount, reboot functions. (LP #194676, #1025467)",
                            "      + 55-network-security.conf: enable rp_filter.",
                            "      + 55-ptrace.conf: describe new PTRACE setting.",
                            "      + 55-zeropage.conf: safe mmap_min_addr value for graceful fall-back",
                            "        for armhf and arm64.",
                            "      + 55-qemu.conf.s390x for qemu.",
                            "      + 55-bufferbloat.conf: set default qdisc to fq_codel",
                            "      + 55-map-count.conf: Increase vm.max_map_count to 1048576",
                            "    - d/t/stack-limit: add basic autopkgtest to validate limits",
                            "    - d/tests: Add basic autopkgtest to validate sysctl-defaults (LP #1962038)",
                            "    - d/t/stack-limit: call 'pgrep systemd' instead of 'pgrep bash'",
                            "      The autopkgtest currently fails because there is no bash session, and",
                            "      pgrep returns non-zero. Use systemd because that will match for pid1.",
                            "    - d/tests: make sysctl-defaults test comprehensive",
                            "    - d/t/test_sysctl_defaults.py: skip test if sysctl key invalid",
                            "    - d/t/control: show all sysctl.d configs before test",
                            "    - d/t/control: make sysctl-defaults test Restrictions: isolation-machine",
                            "      (LP #2115346)",
                            "  * Dropped changes (applied upstream):",
                            "    - d/p/ignore_eaccess.patch: ignore EACCES when opening sysctl file (LP #1903351)",
                            "    - d/p/ignore_erofs.patch: ignore EROFS when opening sysctl file (LP #1419554)",
                            "    - d/p/0010-testsuite-ps-etime-ELAPSED-doesn-t-match-full-format.patch:",
                            "      Fix test failure (FTBFS) in testsuite/ps.test/ps_output.exp due to",
                            "      invalid regex match inside LXD containers.",
                            "    - d/p/lp2120904-openat.patch: utilize file descriptors and openat (LP #2120904)",
                            "    - d/p/lp2120904-nullpointer.patch: fix a race when 'status' is unavailable",
                            "      in /proc/<pid> resulting in NULL pointer (LP #2120904)",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153347
                        ],
                        "author": "Carter Hawthorne <carter.hawthorne@canonical.com>",
                        "date": "Thu, 13 Aug 2026 15:27:14 -0700"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Break & Replace manpages-zh Closes: #1141435",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Tue, 28 Jul 2026 21:10:17 +1000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Mattias Ellert ]",
                            "  * Fix compilation and installation on GNU/Hurd (Closes: #1138217)",
                            "",
                            "  [ Craig Small ]",
                            "  * Only include linux-sysctl-defaults on Linux systems Closes: #1129174",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Tue, 30 Jun 2026 19:23:38 +1000"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libssl4:ppc64el",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "openssl",
                    "source_package_version": "4.0.1-1ubuntu4",
                    "version": "4.0.1-1ubuntu4"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2163146,
                    2158026,
                    2158026
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/default-configuration-read-dropins-and-crypto-config.patch:",
                            "    partially restore patch, needed by src:crypto-policies",
                            "    (LP: #2163146)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163146
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 12 Aug 2026 15:20:38 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert \"Add Depends on libjitterentropy3-dev, zlib1g-dev, and libzstd-dev.",
                            "    (LP: #2158026)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158026
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Mon, 10 Aug 2026 11:49:51 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add Depends on libjitterentropy3-dev, zlib1g-dev, and libzstd-dev.",
                            "    libcrypto.pc declares these as static private dependencies",
                            "    (Libs.private) but libssl-dev did not pull them in, breaking static",
                            "    linking against libcrypto. (LP: #2158026)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158026
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Mon, 03 Aug 2026 16:49:15 +0200"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libtss2-esys-3.0.2-0t64:ppc64el",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "tpm2-tss",
                    "source_package_version": "4.1.3-7ubuntu1",
                    "version": "4.1.3-7ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2154861
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Added patches for OpenSSL4 compatibility (LP: #2154861)",
                            "    - d/p/fix-for-openssl4-compat.patch",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154861
                        ],
                        "author": "Alan Moore <alan.moore@canonical.com>",
                        "date": "Wed, 5 Aug 2026 13:51:08 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:07:29 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Downgrade dependency from lib packages to tpm-udev to recommends",
                            "    (Closes: #1141826)",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mario Limonciello <superm1@debian.org>",
                        "date": "Mon, 13 Jul 2026 23:55:55 -0500"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libtss2-mu-4.0.1-0t64:ppc64el",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "tpm2-tss",
                    "source_package_version": "4.1.3-7ubuntu1",
                    "version": "4.1.3-7ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2154861
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Added patches for OpenSSL4 compatibility (LP: #2154861)",
                            "    - d/p/fix-for-openssl4-compat.patch",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154861
                        ],
                        "author": "Alan Moore <alan.moore@canonical.com>",
                        "date": "Wed, 5 Aug 2026 13:51:08 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:07:29 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Downgrade dependency from lib packages to tpm-udev to recommends",
                            "    (Closes: #1141826)",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mario Limonciello <superm1@debian.org>",
                        "date": "Mon, 13 Jul 2026 23:55:55 -0500"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libtss2-rc0t64:ppc64el",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "tpm2-tss",
                    "source_package_version": "4.1.3-7ubuntu1",
                    "version": "4.1.3-7ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2154861
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Added patches for OpenSSL4 compatibility (LP: #2154861)",
                            "    - d/p/fix-for-openssl4-compat.patch",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154861
                        ],
                        "author": "Alan Moore <alan.moore@canonical.com>",
                        "date": "Wed, 5 Aug 2026 13:51:08 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:07:29 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Downgrade dependency from lib packages to tpm-udev to recommends",
                            "    (Closes: #1141826)",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mario Limonciello <superm1@debian.org>",
                        "date": "Mon, 13 Jul 2026 23:55:55 -0500"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libtss2-sys1t64:ppc64el",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "tpm2-tss",
                    "source_package_version": "4.1.3-7ubuntu1",
                    "version": "4.1.3-7ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2154861
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Added patches for OpenSSL4 compatibility (LP: #2154861)",
                            "    - d/p/fix-for-openssl4-compat.patch",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154861
                        ],
                        "author": "Alan Moore <alan.moore@canonical.com>",
                        "date": "Wed, 5 Aug 2026 13:51:08 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:07:29 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Downgrade dependency from lib packages to tpm-udev to recommends",
                            "    (Closes: #1141826)",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mario Limonciello <superm1@debian.org>",
                        "date": "Mon, 13 Jul 2026 23:55:55 -0500"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libtss2-tcti-cmd0t64:ppc64el",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "tpm2-tss",
                    "source_package_version": "4.1.3-7ubuntu1",
                    "version": "4.1.3-7ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2154861
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Added patches for OpenSSL4 compatibility (LP: #2154861)",
                            "    - d/p/fix-for-openssl4-compat.patch",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154861
                        ],
                        "author": "Alan Moore <alan.moore@canonical.com>",
                        "date": "Wed, 5 Aug 2026 13:51:08 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:07:29 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Downgrade dependency from lib packages to tpm-udev to recommends",
                            "    (Closes: #1141826)",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mario Limonciello <superm1@debian.org>",
                        "date": "Mon, 13 Jul 2026 23:55:55 -0500"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libtss2-tcti-device0t64:ppc64el",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "tpm2-tss",
                    "source_package_version": "4.1.3-7ubuntu1",
                    "version": "4.1.3-7ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2154861
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Added patches for OpenSSL4 compatibility (LP: #2154861)",
                            "    - d/p/fix-for-openssl4-compat.patch",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154861
                        ],
                        "author": "Alan Moore <alan.moore@canonical.com>",
                        "date": "Wed, 5 Aug 2026 13:51:08 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:07:29 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Downgrade dependency from lib packages to tpm-udev to recommends",
                            "    (Closes: #1141826)",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mario Limonciello <superm1@debian.org>",
                        "date": "Mon, 13 Jul 2026 23:55:55 -0500"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libtss2-tcti-mssim0t64:ppc64el",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "tpm2-tss",
                    "source_package_version": "4.1.3-7ubuntu1",
                    "version": "4.1.3-7ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2154861
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Added patches for OpenSSL4 compatibility (LP: #2154861)",
                            "    - d/p/fix-for-openssl4-compat.patch",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154861
                        ],
                        "author": "Alan Moore <alan.moore@canonical.com>",
                        "date": "Wed, 5 Aug 2026 13:51:08 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:07:29 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Downgrade dependency from lib packages to tpm-udev to recommends",
                            "    (Closes: #1141826)",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mario Limonciello <superm1@debian.org>",
                        "date": "Mon, 13 Jul 2026 23:55:55 -0500"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libtss2-tcti-swtpm0t64:ppc64el",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "tpm2-tss",
                    "source_package_version": "4.1.3-7ubuntu1",
                    "version": "4.1.3-7ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2154861
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Added patches for OpenSSL4 compatibility (LP: #2154861)",
                            "    - d/p/fix-for-openssl4-compat.patch",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154861
                        ],
                        "author": "Alan Moore <alan.moore@canonical.com>",
                        "date": "Wed, 5 Aug 2026 13:51:08 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:07:29 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Downgrade dependency from lib packages to tpm-udev to recommends",
                            "    (Closes: #1141826)",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mario Limonciello <superm1@debian.org>",
                        "date": "Mon, 13 Jul 2026 23:55:55 -0500"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-headers-7.2.0-5",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-47337",
                        "url": "https://ubuntu.com/security/CVE-2026-47337",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47334",
                        "url": "https://ubuntu.com/security/CVE-2026-47334",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47333",
                        "url": "https://ubuntu.com/security/CVE-2026-47333",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47332",
                        "url": "https://ubuntu.com/security/CVE-2026-47332",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47330",
                        "url": "https://ubuntu.com/security/CVE-2026-47330",
                        "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47329",
                        "url": "https://ubuntu.com/security/CVE-2026-47329",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47327",
                        "url": "https://ubuntu.com/security/CVE-2026-47327",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47328",
                        "url": "https://ubuntu.com/security/CVE-2026-47328",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47326",
                        "url": "https://ubuntu.com/security/CVE-2026-47326",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163667,
                    2163401,
                    2147533,
                    1990064,
                    2144679,
                    2142956,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2160302,
                    2161304,
                    2160497,
                    1786013,
                    2159617,
                    1786013,
                    2156849,
                    2155837,
                    2146517,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2148809,
                    2151747,
                    2151747,
                    2151747,
                    1990064,
                    2144679,
                    2142956,
                    2139664,
                    2142956,
                    2141298,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2154256,
                    1786013,
                    2154174,
                    2152714,
                    2148866,
                    2149808,
                    2148718
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.2.0-5.5 -proposed tracker (LP: #2163667)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163667
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 16:59:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-4.4 -proposed tracker (LP: #2163401)",
                            "",
                            "  * AA: disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED (LP: #2147533)",
                            "    - [Config] disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.1.0 [60/61]: apparmor: skb: add the ability to use",
                            "      interface in network mediation.",
                            "    - SAUCE: apparmor5.1.0 [61/61]: apparmor: skb: switch to using sk_ctx crit",
                            "      section",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.1.0 [59/61]: apparmor: skb: fix",
                            "      apparmor_secmark_check() when !inet and secmark defined.",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.1.0 [1/61]: apparmor-next: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.1.0 [2/61]: apparmor-next: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.1.0 [3/61]: apparmor-next: apparmor: Initial support",
                            "      for compressed policies",
                            "    - SAUCE: apparmor5.1.0 [4/61]: apparmor-next: apparmor: fix alternate",
                            "      loaders ability to load compressed policy",
                            "    - SAUCE: apparmor5.1.0 [5/61]: apparmor-next: apparmor: replace",
                            "      decompress_zstd() prototype with its entity",
                            "    - SAUCE: apparmor5.1.0 [6/61]: apparmor-next: apparmor: leverage",
                            "      audit_log_n_untrustedstring() when possible",
                            "    - SAUCE: apparmor5.1.0 [7/61]: apparmor-next: apparmor: switch website",
                            "      link to https",
                            "    - SAUCE: apparmor5.1.0 [8/61]: apparmor-next: apparmor: compressed_data",
                            "      not described in aa_get_data_from_compressed",
                            "    - SAUCE: apparmor5.1.0 [9/61]: apparmor-next: apparmor: Fix build failure",
                            "      when ZSTD_DECOMPRESS is not enabled",
                            "    - SAUCE: apparmor5.1.0 [10/61]: apparmor-next: apparmor: fix implicit",
                            "      declaration of function 'decompress_zstd'",
                            "    - SAUCE: apparmor5.1.0 [11/61]: apparmor-next: apparmor: Fix warning:",
                            "      'decompress_zstd' defined but not used",
                            "    - SAUCE: apparmor5.1.0 [12/61]: apparmor-next: apparmor: use",
                            "      SEND_SIG_NOINFO instead of NULL in aa_audit()",
                            "    - SAUCE: apparmor5.1.0 [13/61]: apparmor-next: apparmor: fix cred UAF",
                            "      caused by begin_current_label_crit_section()",
                            "    - SAUCE: apparmor5.1.0 [14/61]: apparmor-next: apparmor: optimize",
                            "      current_label_crit_section() with needput",
                            "    - SAUCE: apparmor5.1.0 [15/61]: apparmor-next: apparmor: fix integer",
                            "      overflow in verify_tags() bounds check",
                            "    - SAUCE: apparmor5.1.0 [16/61]: apparmor-next: apparmor: fix out-of-bounds",
                            "      write when null terminating a label vec",
                            "    - SAUCE: apparmor5.1.0 [17/61]: apparmor-next: apparmor: fix error",
                            "      handling for copy_from_user in policy_update",
                            "    - SAUCE: apparmor5.1.0 [18/61]: apparmor-next: apparmor: make",
                            "      MEDIATES_AF_UNIX its own fn",
                            "    - SAUCE: apparmor5.1.0 [19/61]: apparmor-next: apparmor: refactor network",
                            "      sock mediation in preparation for inet mediation",
                            "    - SAUCE: apparmor5.1.0 [20/61]: apparmor-next: apparmor: push inet",
                            "      mediation into profile callbacks, and improve auditing",
                            "    - SAUCE: apparmor5.1.0 [21/61]: apparmor-next: apparmor: refactor network",
                            "      socket mediation to support compatibility",
                            "    - SAUCE: apparmor5.1.0 [22/61]: apparmor-next: apparmor: move netfilter",
                            "      functions next to the LSM network operations",
                            "    - SAUCE: apparmor5.1.0 [23/61]: apparmor-next: apparmor: move",
                            "      sock_rcv_skb() next to inet_conn_request",
                            "    - SAUCE: apparmor5.1.0 [24/61]: apparmor-next: apparmor: reserve mediation",
                            "      class for packet mediation",
                            "    - SAUCE: apparmor5.1.0 [25/61]: apparmor-next: apparmor: fix unconfined",
                            "      user namespace restriction forced stack",
                            "    - SAUCE: apparmor5.1.0 [26/61]: apparmor-next: apparmor: refactor xattr",
                            "      attachment, to take the file path",
                            "    - SAUCE: apparmor5.1.0 [27/61]: apparmor-next: apparmor: fix race",
                            "      condition in label replacement",
                            "    - SAUCE: apparmor5.1.0 [28/61]: apparmor-next: apparmor: make table entry",
                            "      count last enum for static tables",
                            "    - SAUCE: apparmor5.1.0 [29/61]: apparmor-next: apparmor: fix error debug",
                            "      output in fn_label_build",
                            "    - SAUCE: apparmor5.1.0 [30/61]: apparmor-next: apparmor: mark static",
                            "      tables and structs as read only",
                            "    - SAUCE: apparmor5.1.0 [31/61]: apparmor-next: apparmor: add audit mode to",
                            "      provide a mechanism to silence complain messages",
                            "    - SAUCE: apparmor5.1.0 [32/61]: apparmor-next: apparmor: fix auditing of",
                            "      mount binary data",
                            "    - SAUCE: apparmor5.1.0 [33/61]: apparmor-next: apparmor: refactory mount",
                            "      to use check_perms",
                            "    - SAUCE: apparmor5.1.0 [34/61]: apparmor-next: apparmor: drop use of",
                            "      _confined variant for iteration",
                            "    - SAUCE: apparmor5.1.0 [35/61]: apparmor-next: apparmor: constify aa_perms",
                            "      parameters that are read-only",
                            "    - SAUCE: apparmor5.1.0 [36/61]: apparmor-next: apparmor: constify",
                            "      aa_profile parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [37/61]: apparmor-next: apparmor: constify aa_dfa",
                            "      parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [38/61]: apparmor-next: apparmor: constify aa_label",
                            "      parameters on read-only query helpers",
                            "    - SAUCE: apparmor5.1.0 [39/61]: apparmor-next-next: apparmor: setup slab",
                            "      cache for audit data",
                            "    - SAUCE: apparmor5.1.0 [40/61]: apparmor-next-next: apparmor: add the",
                            "      ability for profiles to have a learning cache",
                            "    - SAUCE: apparmor5.1.0 [41/61]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.1.0 [42/61]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.1.0 [43/61]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.1.0 [44/61]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.1.0 [45/61]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.1.0 [46/61]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [47/61]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [48/61]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.1.0 [50/61]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.1.0 [51/61]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.1.0 [52/61]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.1.0 [53/61]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.1.0 [54/61]: apparmor: mqueue: prevent",
                            "      profile->disconnected double free in aa_free_profile",
                            "    - SAUCE: apparmor5.1.0 [55/61]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.1.0 [58/61]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.1.0 [56/61]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.1.0 [57/61]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.1.0 [49/61]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Drop DEP-8 tests from kernel packages (LP: #2160302)",
                            "    - [Packaging] Drop DEP-8 tests from kernel source",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] updateconfigs after rebase to v7.2-rc6",
                            "    - [Config] Enable SECURITY_APPARMOR_COMPRESSED_POLICY",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163401,
                            2147533,
                            1990064,
                            2144679,
                            2142956,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602,
                            2160302
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:46:26 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-2.2 -proposed tracker (LP: #2161304)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Changes.md: dropping reboot=pci quirks for sandy bridge hw",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161304
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:29:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-1.1 -proposed tracker (LP: #2160497)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160497,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:07:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-0.0 -proposed tracker (LP: #2159617)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] update annotations scripts",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.2-rc1 rebase",
                            "    - [Config] updateconfigs after v7.2-rc1 rebase",
                            "    - SAUCE: thunderbolt: fixup move of pci_device out of tb_nhi",
                            "    - [Packaging] integrate SBOM generation into the build",
                            "    - SAUCE: fixup s/strncpy/strscpy/ in compat_uts_machine= kernel command",
                            "      line override",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: media: venus: core: guard SC8280XP/SM8350 resources behind !IRIS",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159617,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47337",
                                "url": "https://ubuntu.com/security/CVE-2026-47337",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47334",
                                "url": "https://ubuntu.com/security/CVE-2026-47334",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47333",
                                "url": "https://ubuntu.com/security/CVE-2026-47333",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47332",
                                "url": "https://ubuntu.com/security/CVE-2026-47332",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47330",
                                "url": "https://ubuntu.com/security/CVE-2026-47330",
                                "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47329",
                                "url": "https://ubuntu.com/security/CVE-2026-47329",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47327",
                                "url": "https://ubuntu.com/security/CVE-2026-47327",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47328",
                                "url": "https://ubuntu.com/security/CVE-2026-47328",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47326",
                                "url": "https://ubuntu.com/security/CVE-2026-47326",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-5.5 -proposed tracker (LP: #2156849)",
                            "",
                            "  * MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260",
                            "    renders upside-down (LP: #2155837)",
                            "    - SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14",
                            "      Premium PA14260",
                            "",
                            "  * ov08x40 module mounted upside down on a certain DELL platforms",
                            "    (LP: #2146517)",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for new Dell XPS laptops with",
                            "      upside down sensors",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for Dell 14 laptops with upside",
                            "      down sensors",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747)",
                            "    - SAUCE: apparmor: pass big_resp to handler",
                            "    - SAUCE: apparmor: remove redundant kref_init for listener->count",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47337",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47334",
                            "    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47333",
                            "    - SAUCE: apparmor: fix dfa unpacking size of the notification filter",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47332",
                            "    - SAUCE: apparmor: fix size check against type instead of pointer",
                            "",
                            "  * apparmor: LLVM/clang build failure due to uninitialized variable in",
                            "    notify.c (LP: #2148809) // CVE-2026-47330",
                            "    - SAUCE: apparmor: initialize variable used in uninitialized context",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47329",
                            "    - SAUCE: apparmor: fix name validation bypass on notification",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47327 //",
                            "    CVE-2026-47328",
                            "    - SAUCE: apparmor: fix glob memory leak after kstrdup",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47326",
                            "    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.0.0 [57/57]: apparmor: add the ability to use interface",
                            "      in network mediation.",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [29/57]: apparmor: fix fine grained inet mediation",
                            "      sock_file_perm",
                            "    - SAUCE: apparmor5.0.0 [32/57]: apparmor-next 7.1: apparmor: enable",
                            "      differential encoding",
                            "    - SAUCE: apparmor5.0.0 [33/57]: apparmor-next 7.1: apparmor: propagate",
                            "      -ENOMEM correctly in unpack_table",
                            "    - SAUCE: apparmor5.0.0 [36/57]: apparmor-next 7.1: apparmor: use",
                            "      __label_make_stale in __aa_proxy_redirect",
                            "    - SAUCE: apparmor5.0.0 [37/57]: apparmor-next 7.1: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.0.0 [39/57]: apparmor-next 7.1: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1: apparmor: fix",
                            "      rawdata_f_data implicit flex array",
                            "    - SAUCE: apparmor5.0.0 [42/57]: apparmor-next 7.1: apparmor: free rawdata",
                            "      as soon as possible",
                            "    - SAUCE: apparmor5.0.0 [43/57]: apparmor-next 7.1: apparmor: Initial",
                            "      support for compressed policies",
                            "    - SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1: apparmor: fix potential",
                            "      UAF in aa_replace_profiles",
                            "    - SAUCE: apparmor5.0.0 [45/57]: apparmor-next 7.1: apparmor: hide unused",
                            "      get_loaddata_common_ref() function",
                            "    - SAUCE: apparmor5.0.0 [47/57]: apparmor: fix packed tag on v5 header",
                            "      struct",
                            "    - SAUCE: apparmor5.0.0 [48/57]: apparmor: add temporal caching to audit",
                            "      responses.",
                            "    - SAUCE: apparmor5.0.0 [49/57]: apparmor: change fn_label_build() call to",
                            "      not return NULL",
                            "    - SAUCE: apparmor5.0.0 [50/57]: apparmor: make fn_label_build() capable of",
                            "      handling not supported",
                            "    - SAUCE: apparmor5.0.0 [51/57]: apparmor: move netfilter functions next to",
                            "      the LSM network operations",
                            "    - SAUCE: apparmor5.0.0 [52/57]: apparmor: move sock_rvc_skb() next to",
                            "      inet_conn_request",
                            "    - SAUCE: apparmor5.0.0 [53/57]: apparmor: fix af_unix local addr mediation",
                            "      binding",
                            "    - SAUCE: apparmor5.0.0 [54/57]: cleanups of apparmor af_unix mediation",
                            "    - SAUCE: apparmor5.0.0 [55/57]: apparmor: fix apparmor_secmark_check()",
                            "      when !inet and secmark defined.",
                            "    - SAUCE: apparmor5.0.0 [56/57]: apparmor: fix auditing of non-mediation",
                            "      falures",
                            "",
                            "  * snap service cannot change apparmor hat (LP: #2139664) // Jellyfin Desktop",
                            "    Flatpak doesn't work with the current AppArmor profile (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1: apparmor: grab ns lock",
                            "      and refresh when looking up changehat child profiles",
                            "",
                            "  * AppArmor blocks write(2) to network sockets with Linux 6.19 (LP: #2141298)",
                            "    - SAUCE: apparmor5.0.0 [28/57]: apparmor: fix aa_label_sk_perm to check",
                            "      for RULE_MEDIATES_NET",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.0.0 [1/57]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.0.0 [2/57]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.0.0 [3/57]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.0.0 [4/57]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.0.0 [5/57]: Revert \"apparmor: gate make fine grained",
                            "      unix mediation behind v9 abi\"",
                            "    - SAUCE: apparmor5.0.0 [6/57]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.0.0 [7/57]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [8/57]: apparmor: lift compatibility check out of",
                            "      profile_af_perm",
                            "    - SAUCE: apparmor5.0.0 [9/57]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [10/57]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.0.0 [12/57]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.0.0 [13/57]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.0.0 [14/57]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.0.0 [15/57]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.0.0 [16/57]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.0.0 [19/57]: apparmor: prompt: setup slab cache for",
                            "      audit data",
                            "    - SAUCE: apparmor5.0.0 [20/57]: apparmor: prompt: add the ability for",
                            "      profiles to have a learning cache",
                            "    - SAUCE: apparmor5.0.0 [21/57]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "    - SAUCE: apparmor5.0.0 [22/57]: apparmor: prompt: pass prompt boolean",
                            "      through into path_name as well",
                            "    - SAUCE: apparmor5.0.0 [23/57]: apparmor: check for supported version in",
                            "      notification messages.",
                            "    - SAUCE: apparmor5.0.0 [24/57]: apparmor: refactor building notice so it",
                            "      is easier to extend",
                            "    - SAUCE: apparmor5.0.0 [25/57]: apparmor: switch from ENOTSUPP to",
                            "      EPROTONOSUPPORT",
                            "    - SAUCE: apparmor5.0.0 [26/57]: apparmor: add support for meta data tags",
                            "    - SAUCE: apparmor5.0.0 [27/57]: apparmor: prevent profile->disconnected",
                            "      double free in aa_free_profile",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.0.0 [17/57]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.0.0 [18/57]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.0.0 [11/57]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] enable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "    - [Packaging] Fix cross-builds",
                            "    - [Config] updateconfigs after v7.1 rebase",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2156849,
                            2155837,
                            2146517,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2148809,
                            2151747,
                            2151747,
                            2151747,
                            1990064,
                            2144679,
                            2142956,
                            2139664,
                            2142956,
                            2141298,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:38:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-1.1 -proposed tracker (LP: #2154256)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "",
                            "  * resolute ubuntu_kernel_selftests:seccomp_build test compilation issue",
                            "    (LP: #2154174)",
                            "    - SAUCE: selftests/seccomp fix compilation issue for amd64",
                            "",
                            "  * Kernel 6.19-rc8 does not include GPIB driver (LP: #2152714)",
                            "    - [Config] Enable CONFIG_GPIB for amd64",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.1-rc4 rebase",
                            "    - [packaging] Install gdb scripts again",
                            "    - [Config] updateconfigs after v7.1-rc5 rebase",
                            "    - [Packaging] templates: Use a for-loop for run-parts",
                            "    - [Packaging] Remove dead debian.master/rules.d/x32.mk",
                            "    - [Packaging] Remove orphaned debian/v4l2loopback-modules.ignore",
                            "    - [Packaging] Remove orphaned debian/zfs-modules.ignore",
                            "    - [Packaging] Remove deprecated linux-doc transitional stub",
                            "    - [Packaging] Remove dead comment referencing gcc-4.7 in control.stub.in",
                            "    - [Packaging] Remove dead comment in ppc64el.mk",
                            "    - [Packaging] Remove stale legacy code",
                            "    - [Packaging] rules: Drop an obsolete check for do_zstd_ko",
                            "    - [Config] toolchain version update",
                            "    - [Packaging] update Ubuntu.md",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154256,
                            1786013,
                            2154174,
                            2152714
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:08:55 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 09:59:13 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * resolute/linux: 7.0.0-15.15 -proposed tracker (LP: #2148866)",
                            "",
                            "  * Qualcomm X1E: Speaker overdrive causes hardware protection shutdown",
                            "    (LP: #2149808)",
                            "    - SAUCE: ASoC: qcom: x1e80100: limit speaker volumes",
                            "",
                            "  * intel-ipu7 / intel-ipu7-isys modules are shipped unsigned in latest",
                            "    Resolute kernels, breaking Secure Boot systems  (LP: #2148718)",
                            "    - [packaging] add intel-ipu7 to signature inclusion list",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2148866,
                            2149808,
                            2148718
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:02:19 +0200"
                    }
                ],
                "notes": "linux-headers-7.2.0-5 version '7.2.0-5.5' (source package linux version '7.2.0-5.5') was added. linux-headers-7.2.0-5 version '7.2.0-5.5' has the same source package name, linux, as removed package linux-headers-7.0.0-14. As such we can use the source package version of the removed package, '7.0.0-14.14', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-headers-7.2.0-5-generic",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-47337",
                        "url": "https://ubuntu.com/security/CVE-2026-47337",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47334",
                        "url": "https://ubuntu.com/security/CVE-2026-47334",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47333",
                        "url": "https://ubuntu.com/security/CVE-2026-47333",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47332",
                        "url": "https://ubuntu.com/security/CVE-2026-47332",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47330",
                        "url": "https://ubuntu.com/security/CVE-2026-47330",
                        "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47329",
                        "url": "https://ubuntu.com/security/CVE-2026-47329",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47327",
                        "url": "https://ubuntu.com/security/CVE-2026-47327",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47328",
                        "url": "https://ubuntu.com/security/CVE-2026-47328",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47326",
                        "url": "https://ubuntu.com/security/CVE-2026-47326",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163667,
                    2163401,
                    2147533,
                    1990064,
                    2144679,
                    2142956,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2160302,
                    2161304,
                    2160497,
                    1786013,
                    2159617,
                    1786013,
                    2156849,
                    2155837,
                    2146517,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2148809,
                    2151747,
                    2151747,
                    2151747,
                    1990064,
                    2144679,
                    2142956,
                    2139664,
                    2142956,
                    2141298,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2154256,
                    1786013,
                    2154174,
                    2152714,
                    2148866,
                    2149808,
                    2148718
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.2.0-5.5 -proposed tracker (LP: #2163667)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163667
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 16:59:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-4.4 -proposed tracker (LP: #2163401)",
                            "",
                            "  * AA: disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED (LP: #2147533)",
                            "    - [Config] disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.1.0 [60/61]: apparmor: skb: add the ability to use",
                            "      interface in network mediation.",
                            "    - SAUCE: apparmor5.1.0 [61/61]: apparmor: skb: switch to using sk_ctx crit",
                            "      section",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.1.0 [59/61]: apparmor: skb: fix",
                            "      apparmor_secmark_check() when !inet and secmark defined.",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.1.0 [1/61]: apparmor-next: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.1.0 [2/61]: apparmor-next: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.1.0 [3/61]: apparmor-next: apparmor: Initial support",
                            "      for compressed policies",
                            "    - SAUCE: apparmor5.1.0 [4/61]: apparmor-next: apparmor: fix alternate",
                            "      loaders ability to load compressed policy",
                            "    - SAUCE: apparmor5.1.0 [5/61]: apparmor-next: apparmor: replace",
                            "      decompress_zstd() prototype with its entity",
                            "    - SAUCE: apparmor5.1.0 [6/61]: apparmor-next: apparmor: leverage",
                            "      audit_log_n_untrustedstring() when possible",
                            "    - SAUCE: apparmor5.1.0 [7/61]: apparmor-next: apparmor: switch website",
                            "      link to https",
                            "    - SAUCE: apparmor5.1.0 [8/61]: apparmor-next: apparmor: compressed_data",
                            "      not described in aa_get_data_from_compressed",
                            "    - SAUCE: apparmor5.1.0 [9/61]: apparmor-next: apparmor: Fix build failure",
                            "      when ZSTD_DECOMPRESS is not enabled",
                            "    - SAUCE: apparmor5.1.0 [10/61]: apparmor-next: apparmor: fix implicit",
                            "      declaration of function 'decompress_zstd'",
                            "    - SAUCE: apparmor5.1.0 [11/61]: apparmor-next: apparmor: Fix warning:",
                            "      'decompress_zstd' defined but not used",
                            "    - SAUCE: apparmor5.1.0 [12/61]: apparmor-next: apparmor: use",
                            "      SEND_SIG_NOINFO instead of NULL in aa_audit()",
                            "    - SAUCE: apparmor5.1.0 [13/61]: apparmor-next: apparmor: fix cred UAF",
                            "      caused by begin_current_label_crit_section()",
                            "    - SAUCE: apparmor5.1.0 [14/61]: apparmor-next: apparmor: optimize",
                            "      current_label_crit_section() with needput",
                            "    - SAUCE: apparmor5.1.0 [15/61]: apparmor-next: apparmor: fix integer",
                            "      overflow in verify_tags() bounds check",
                            "    - SAUCE: apparmor5.1.0 [16/61]: apparmor-next: apparmor: fix out-of-bounds",
                            "      write when null terminating a label vec",
                            "    - SAUCE: apparmor5.1.0 [17/61]: apparmor-next: apparmor: fix error",
                            "      handling for copy_from_user in policy_update",
                            "    - SAUCE: apparmor5.1.0 [18/61]: apparmor-next: apparmor: make",
                            "      MEDIATES_AF_UNIX its own fn",
                            "    - SAUCE: apparmor5.1.0 [19/61]: apparmor-next: apparmor: refactor network",
                            "      sock mediation in preparation for inet mediation",
                            "    - SAUCE: apparmor5.1.0 [20/61]: apparmor-next: apparmor: push inet",
                            "      mediation into profile callbacks, and improve auditing",
                            "    - SAUCE: apparmor5.1.0 [21/61]: apparmor-next: apparmor: refactor network",
                            "      socket mediation to support compatibility",
                            "    - SAUCE: apparmor5.1.0 [22/61]: apparmor-next: apparmor: move netfilter",
                            "      functions next to the LSM network operations",
                            "    - SAUCE: apparmor5.1.0 [23/61]: apparmor-next: apparmor: move",
                            "      sock_rcv_skb() next to inet_conn_request",
                            "    - SAUCE: apparmor5.1.0 [24/61]: apparmor-next: apparmor: reserve mediation",
                            "      class for packet mediation",
                            "    - SAUCE: apparmor5.1.0 [25/61]: apparmor-next: apparmor: fix unconfined",
                            "      user namespace restriction forced stack",
                            "    - SAUCE: apparmor5.1.0 [26/61]: apparmor-next: apparmor: refactor xattr",
                            "      attachment, to take the file path",
                            "    - SAUCE: apparmor5.1.0 [27/61]: apparmor-next: apparmor: fix race",
                            "      condition in label replacement",
                            "    - SAUCE: apparmor5.1.0 [28/61]: apparmor-next: apparmor: make table entry",
                            "      count last enum for static tables",
                            "    - SAUCE: apparmor5.1.0 [29/61]: apparmor-next: apparmor: fix error debug",
                            "      output in fn_label_build",
                            "    - SAUCE: apparmor5.1.0 [30/61]: apparmor-next: apparmor: mark static",
                            "      tables and structs as read only",
                            "    - SAUCE: apparmor5.1.0 [31/61]: apparmor-next: apparmor: add audit mode to",
                            "      provide a mechanism to silence complain messages",
                            "    - SAUCE: apparmor5.1.0 [32/61]: apparmor-next: apparmor: fix auditing of",
                            "      mount binary data",
                            "    - SAUCE: apparmor5.1.0 [33/61]: apparmor-next: apparmor: refactory mount",
                            "      to use check_perms",
                            "    - SAUCE: apparmor5.1.0 [34/61]: apparmor-next: apparmor: drop use of",
                            "      _confined variant for iteration",
                            "    - SAUCE: apparmor5.1.0 [35/61]: apparmor-next: apparmor: constify aa_perms",
                            "      parameters that are read-only",
                            "    - SAUCE: apparmor5.1.0 [36/61]: apparmor-next: apparmor: constify",
                            "      aa_profile parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [37/61]: apparmor-next: apparmor: constify aa_dfa",
                            "      parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [38/61]: apparmor-next: apparmor: constify aa_label",
                            "      parameters on read-only query helpers",
                            "    - SAUCE: apparmor5.1.0 [39/61]: apparmor-next-next: apparmor: setup slab",
                            "      cache for audit data",
                            "    - SAUCE: apparmor5.1.0 [40/61]: apparmor-next-next: apparmor: add the",
                            "      ability for profiles to have a learning cache",
                            "    - SAUCE: apparmor5.1.0 [41/61]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.1.0 [42/61]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.1.0 [43/61]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.1.0 [44/61]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.1.0 [45/61]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.1.0 [46/61]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [47/61]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [48/61]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.1.0 [50/61]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.1.0 [51/61]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.1.0 [52/61]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.1.0 [53/61]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.1.0 [54/61]: apparmor: mqueue: prevent",
                            "      profile->disconnected double free in aa_free_profile",
                            "    - SAUCE: apparmor5.1.0 [55/61]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.1.0 [58/61]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.1.0 [56/61]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.1.0 [57/61]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.1.0 [49/61]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Drop DEP-8 tests from kernel packages (LP: #2160302)",
                            "    - [Packaging] Drop DEP-8 tests from kernel source",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] updateconfigs after rebase to v7.2-rc6",
                            "    - [Config] Enable SECURITY_APPARMOR_COMPRESSED_POLICY",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163401,
                            2147533,
                            1990064,
                            2144679,
                            2142956,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602,
                            2160302
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:46:26 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-2.2 -proposed tracker (LP: #2161304)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Changes.md: dropping reboot=pci quirks for sandy bridge hw",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161304
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:29:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-1.1 -proposed tracker (LP: #2160497)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160497,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:07:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-0.0 -proposed tracker (LP: #2159617)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] update annotations scripts",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.2-rc1 rebase",
                            "    - [Config] updateconfigs after v7.2-rc1 rebase",
                            "    - SAUCE: thunderbolt: fixup move of pci_device out of tb_nhi",
                            "    - [Packaging] integrate SBOM generation into the build",
                            "    - SAUCE: fixup s/strncpy/strscpy/ in compat_uts_machine= kernel command",
                            "      line override",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: media: venus: core: guard SC8280XP/SM8350 resources behind !IRIS",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159617,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47337",
                                "url": "https://ubuntu.com/security/CVE-2026-47337",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47334",
                                "url": "https://ubuntu.com/security/CVE-2026-47334",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47333",
                                "url": "https://ubuntu.com/security/CVE-2026-47333",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47332",
                                "url": "https://ubuntu.com/security/CVE-2026-47332",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47330",
                                "url": "https://ubuntu.com/security/CVE-2026-47330",
                                "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47329",
                                "url": "https://ubuntu.com/security/CVE-2026-47329",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47327",
                                "url": "https://ubuntu.com/security/CVE-2026-47327",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47328",
                                "url": "https://ubuntu.com/security/CVE-2026-47328",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47326",
                                "url": "https://ubuntu.com/security/CVE-2026-47326",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-5.5 -proposed tracker (LP: #2156849)",
                            "",
                            "  * MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260",
                            "    renders upside-down (LP: #2155837)",
                            "    - SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14",
                            "      Premium PA14260",
                            "",
                            "  * ov08x40 module mounted upside down on a certain DELL platforms",
                            "    (LP: #2146517)",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for new Dell XPS laptops with",
                            "      upside down sensors",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for Dell 14 laptops with upside",
                            "      down sensors",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747)",
                            "    - SAUCE: apparmor: pass big_resp to handler",
                            "    - SAUCE: apparmor: remove redundant kref_init for listener->count",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47337",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47334",
                            "    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47333",
                            "    - SAUCE: apparmor: fix dfa unpacking size of the notification filter",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47332",
                            "    - SAUCE: apparmor: fix size check against type instead of pointer",
                            "",
                            "  * apparmor: LLVM/clang build failure due to uninitialized variable in",
                            "    notify.c (LP: #2148809) // CVE-2026-47330",
                            "    - SAUCE: apparmor: initialize variable used in uninitialized context",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47329",
                            "    - SAUCE: apparmor: fix name validation bypass on notification",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47327 //",
                            "    CVE-2026-47328",
                            "    - SAUCE: apparmor: fix glob memory leak after kstrdup",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47326",
                            "    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.0.0 [57/57]: apparmor: add the ability to use interface",
                            "      in network mediation.",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [29/57]: apparmor: fix fine grained inet mediation",
                            "      sock_file_perm",
                            "    - SAUCE: apparmor5.0.0 [32/57]: apparmor-next 7.1: apparmor: enable",
                            "      differential encoding",
                            "    - SAUCE: apparmor5.0.0 [33/57]: apparmor-next 7.1: apparmor: propagate",
                            "      -ENOMEM correctly in unpack_table",
                            "    - SAUCE: apparmor5.0.0 [36/57]: apparmor-next 7.1: apparmor: use",
                            "      __label_make_stale in __aa_proxy_redirect",
                            "    - SAUCE: apparmor5.0.0 [37/57]: apparmor-next 7.1: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.0.0 [39/57]: apparmor-next 7.1: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1: apparmor: fix",
                            "      rawdata_f_data implicit flex array",
                            "    - SAUCE: apparmor5.0.0 [42/57]: apparmor-next 7.1: apparmor: free rawdata",
                            "      as soon as possible",
                            "    - SAUCE: apparmor5.0.0 [43/57]: apparmor-next 7.1: apparmor: Initial",
                            "      support for compressed policies",
                            "    - SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1: apparmor: fix potential",
                            "      UAF in aa_replace_profiles",
                            "    - SAUCE: apparmor5.0.0 [45/57]: apparmor-next 7.1: apparmor: hide unused",
                            "      get_loaddata_common_ref() function",
                            "    - SAUCE: apparmor5.0.0 [47/57]: apparmor: fix packed tag on v5 header",
                            "      struct",
                            "    - SAUCE: apparmor5.0.0 [48/57]: apparmor: add temporal caching to audit",
                            "      responses.",
                            "    - SAUCE: apparmor5.0.0 [49/57]: apparmor: change fn_label_build() call to",
                            "      not return NULL",
                            "    - SAUCE: apparmor5.0.0 [50/57]: apparmor: make fn_label_build() capable of",
                            "      handling not supported",
                            "    - SAUCE: apparmor5.0.0 [51/57]: apparmor: move netfilter functions next to",
                            "      the LSM network operations",
                            "    - SAUCE: apparmor5.0.0 [52/57]: apparmor: move sock_rvc_skb() next to",
                            "      inet_conn_request",
                            "    - SAUCE: apparmor5.0.0 [53/57]: apparmor: fix af_unix local addr mediation",
                            "      binding",
                            "    - SAUCE: apparmor5.0.0 [54/57]: cleanups of apparmor af_unix mediation",
                            "    - SAUCE: apparmor5.0.0 [55/57]: apparmor: fix apparmor_secmark_check()",
                            "      when !inet and secmark defined.",
                            "    - SAUCE: apparmor5.0.0 [56/57]: apparmor: fix auditing of non-mediation",
                            "      falures",
                            "",
                            "  * snap service cannot change apparmor hat (LP: #2139664) // Jellyfin Desktop",
                            "    Flatpak doesn't work with the current AppArmor profile (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1: apparmor: grab ns lock",
                            "      and refresh when looking up changehat child profiles",
                            "",
                            "  * AppArmor blocks write(2) to network sockets with Linux 6.19 (LP: #2141298)",
                            "    - SAUCE: apparmor5.0.0 [28/57]: apparmor: fix aa_label_sk_perm to check",
                            "      for RULE_MEDIATES_NET",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.0.0 [1/57]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.0.0 [2/57]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.0.0 [3/57]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.0.0 [4/57]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.0.0 [5/57]: Revert \"apparmor: gate make fine grained",
                            "      unix mediation behind v9 abi\"",
                            "    - SAUCE: apparmor5.0.0 [6/57]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.0.0 [7/57]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [8/57]: apparmor: lift compatibility check out of",
                            "      profile_af_perm",
                            "    - SAUCE: apparmor5.0.0 [9/57]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [10/57]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.0.0 [12/57]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.0.0 [13/57]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.0.0 [14/57]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.0.0 [15/57]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.0.0 [16/57]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.0.0 [19/57]: apparmor: prompt: setup slab cache for",
                            "      audit data",
                            "    - SAUCE: apparmor5.0.0 [20/57]: apparmor: prompt: add the ability for",
                            "      profiles to have a learning cache",
                            "    - SAUCE: apparmor5.0.0 [21/57]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "    - SAUCE: apparmor5.0.0 [22/57]: apparmor: prompt: pass prompt boolean",
                            "      through into path_name as well",
                            "    - SAUCE: apparmor5.0.0 [23/57]: apparmor: check for supported version in",
                            "      notification messages.",
                            "    - SAUCE: apparmor5.0.0 [24/57]: apparmor: refactor building notice so it",
                            "      is easier to extend",
                            "    - SAUCE: apparmor5.0.0 [25/57]: apparmor: switch from ENOTSUPP to",
                            "      EPROTONOSUPPORT",
                            "    - SAUCE: apparmor5.0.0 [26/57]: apparmor: add support for meta data tags",
                            "    - SAUCE: apparmor5.0.0 [27/57]: apparmor: prevent profile->disconnected",
                            "      double free in aa_free_profile",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.0.0 [17/57]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.0.0 [18/57]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.0.0 [11/57]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] enable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "    - [Packaging] Fix cross-builds",
                            "    - [Config] updateconfigs after v7.1 rebase",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2156849,
                            2155837,
                            2146517,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2148809,
                            2151747,
                            2151747,
                            2151747,
                            1990064,
                            2144679,
                            2142956,
                            2139664,
                            2142956,
                            2141298,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:38:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-1.1 -proposed tracker (LP: #2154256)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "",
                            "  * resolute ubuntu_kernel_selftests:seccomp_build test compilation issue",
                            "    (LP: #2154174)",
                            "    - SAUCE: selftests/seccomp fix compilation issue for amd64",
                            "",
                            "  * Kernel 6.19-rc8 does not include GPIB driver (LP: #2152714)",
                            "    - [Config] Enable CONFIG_GPIB for amd64",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.1-rc4 rebase",
                            "    - [packaging] Install gdb scripts again",
                            "    - [Config] updateconfigs after v7.1-rc5 rebase",
                            "    - [Packaging] templates: Use a for-loop for run-parts",
                            "    - [Packaging] Remove dead debian.master/rules.d/x32.mk",
                            "    - [Packaging] Remove orphaned debian/v4l2loopback-modules.ignore",
                            "    - [Packaging] Remove orphaned debian/zfs-modules.ignore",
                            "    - [Packaging] Remove deprecated linux-doc transitional stub",
                            "    - [Packaging] Remove dead comment referencing gcc-4.7 in control.stub.in",
                            "    - [Packaging] Remove dead comment in ppc64el.mk",
                            "    - [Packaging] Remove stale legacy code",
                            "    - [Packaging] rules: Drop an obsolete check for do_zstd_ko",
                            "    - [Config] toolchain version update",
                            "    - [Packaging] update Ubuntu.md",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154256,
                            1786013,
                            2154174,
                            2152714
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:08:55 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 09:59:13 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * resolute/linux: 7.0.0-15.15 -proposed tracker (LP: #2148866)",
                            "",
                            "  * Qualcomm X1E: Speaker overdrive causes hardware protection shutdown",
                            "    (LP: #2149808)",
                            "    - SAUCE: ASoC: qcom: x1e80100: limit speaker volumes",
                            "",
                            "  * intel-ipu7 / intel-ipu7-isys modules are shipped unsigned in latest",
                            "    Resolute kernels, breaking Secure Boot systems  (LP: #2148718)",
                            "    - [packaging] add intel-ipu7 to signature inclusion list",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2148866,
                            2149808,
                            2148718
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:02:19 +0200"
                    }
                ],
                "notes": "linux-headers-7.2.0-5-generic version '7.2.0-5.5' (source package linux version '7.2.0-5.5') was added. linux-headers-7.2.0-5-generic version '7.2.0-5.5' has the same source package name, linux, as removed package linux-headers-7.0.0-14. As such we can use the source package version of the removed package, '7.0.0-14.14', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-image-7.2.0-5-generic",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-47337",
                        "url": "https://ubuntu.com/security/CVE-2026-47337",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47334",
                        "url": "https://ubuntu.com/security/CVE-2026-47334",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47333",
                        "url": "https://ubuntu.com/security/CVE-2026-47333",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47332",
                        "url": "https://ubuntu.com/security/CVE-2026-47332",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47330",
                        "url": "https://ubuntu.com/security/CVE-2026-47330",
                        "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47329",
                        "url": "https://ubuntu.com/security/CVE-2026-47329",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47327",
                        "url": "https://ubuntu.com/security/CVE-2026-47327",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47328",
                        "url": "https://ubuntu.com/security/CVE-2026-47328",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47326",
                        "url": "https://ubuntu.com/security/CVE-2026-47326",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163667,
                    2163401,
                    2147533,
                    1990064,
                    2144679,
                    2142956,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2160302,
                    2161304,
                    2160497,
                    1786013,
                    2159617,
                    1786013,
                    2156849,
                    2155837,
                    2146517,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2148809,
                    2151747,
                    2151747,
                    2151747,
                    1990064,
                    2144679,
                    2142956,
                    2139664,
                    2142956,
                    2141298,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2154256,
                    1786013,
                    2154174,
                    2152714,
                    2148866,
                    2149808,
                    2148718
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.2.0-5.5 -proposed tracker (LP: #2163667)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163667
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 16:59:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-4.4 -proposed tracker (LP: #2163401)",
                            "",
                            "  * AA: disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED (LP: #2147533)",
                            "    - [Config] disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.1.0 [60/61]: apparmor: skb: add the ability to use",
                            "      interface in network mediation.",
                            "    - SAUCE: apparmor5.1.0 [61/61]: apparmor: skb: switch to using sk_ctx crit",
                            "      section",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.1.0 [59/61]: apparmor: skb: fix",
                            "      apparmor_secmark_check() when !inet and secmark defined.",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.1.0 [1/61]: apparmor-next: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.1.0 [2/61]: apparmor-next: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.1.0 [3/61]: apparmor-next: apparmor: Initial support",
                            "      for compressed policies",
                            "    - SAUCE: apparmor5.1.0 [4/61]: apparmor-next: apparmor: fix alternate",
                            "      loaders ability to load compressed policy",
                            "    - SAUCE: apparmor5.1.0 [5/61]: apparmor-next: apparmor: replace",
                            "      decompress_zstd() prototype with its entity",
                            "    - SAUCE: apparmor5.1.0 [6/61]: apparmor-next: apparmor: leverage",
                            "      audit_log_n_untrustedstring() when possible",
                            "    - SAUCE: apparmor5.1.0 [7/61]: apparmor-next: apparmor: switch website",
                            "      link to https",
                            "    - SAUCE: apparmor5.1.0 [8/61]: apparmor-next: apparmor: compressed_data",
                            "      not described in aa_get_data_from_compressed",
                            "    - SAUCE: apparmor5.1.0 [9/61]: apparmor-next: apparmor: Fix build failure",
                            "      when ZSTD_DECOMPRESS is not enabled",
                            "    - SAUCE: apparmor5.1.0 [10/61]: apparmor-next: apparmor: fix implicit",
                            "      declaration of function 'decompress_zstd'",
                            "    - SAUCE: apparmor5.1.0 [11/61]: apparmor-next: apparmor: Fix warning:",
                            "      'decompress_zstd' defined but not used",
                            "    - SAUCE: apparmor5.1.0 [12/61]: apparmor-next: apparmor: use",
                            "      SEND_SIG_NOINFO instead of NULL in aa_audit()",
                            "    - SAUCE: apparmor5.1.0 [13/61]: apparmor-next: apparmor: fix cred UAF",
                            "      caused by begin_current_label_crit_section()",
                            "    - SAUCE: apparmor5.1.0 [14/61]: apparmor-next: apparmor: optimize",
                            "      current_label_crit_section() with needput",
                            "    - SAUCE: apparmor5.1.0 [15/61]: apparmor-next: apparmor: fix integer",
                            "      overflow in verify_tags() bounds check",
                            "    - SAUCE: apparmor5.1.0 [16/61]: apparmor-next: apparmor: fix out-of-bounds",
                            "      write when null terminating a label vec",
                            "    - SAUCE: apparmor5.1.0 [17/61]: apparmor-next: apparmor: fix error",
                            "      handling for copy_from_user in policy_update",
                            "    - SAUCE: apparmor5.1.0 [18/61]: apparmor-next: apparmor: make",
                            "      MEDIATES_AF_UNIX its own fn",
                            "    - SAUCE: apparmor5.1.0 [19/61]: apparmor-next: apparmor: refactor network",
                            "      sock mediation in preparation for inet mediation",
                            "    - SAUCE: apparmor5.1.0 [20/61]: apparmor-next: apparmor: push inet",
                            "      mediation into profile callbacks, and improve auditing",
                            "    - SAUCE: apparmor5.1.0 [21/61]: apparmor-next: apparmor: refactor network",
                            "      socket mediation to support compatibility",
                            "    - SAUCE: apparmor5.1.0 [22/61]: apparmor-next: apparmor: move netfilter",
                            "      functions next to the LSM network operations",
                            "    - SAUCE: apparmor5.1.0 [23/61]: apparmor-next: apparmor: move",
                            "      sock_rcv_skb() next to inet_conn_request",
                            "    - SAUCE: apparmor5.1.0 [24/61]: apparmor-next: apparmor: reserve mediation",
                            "      class for packet mediation",
                            "    - SAUCE: apparmor5.1.0 [25/61]: apparmor-next: apparmor: fix unconfined",
                            "      user namespace restriction forced stack",
                            "    - SAUCE: apparmor5.1.0 [26/61]: apparmor-next: apparmor: refactor xattr",
                            "      attachment, to take the file path",
                            "    - SAUCE: apparmor5.1.0 [27/61]: apparmor-next: apparmor: fix race",
                            "      condition in label replacement",
                            "    - SAUCE: apparmor5.1.0 [28/61]: apparmor-next: apparmor: make table entry",
                            "      count last enum for static tables",
                            "    - SAUCE: apparmor5.1.0 [29/61]: apparmor-next: apparmor: fix error debug",
                            "      output in fn_label_build",
                            "    - SAUCE: apparmor5.1.0 [30/61]: apparmor-next: apparmor: mark static",
                            "      tables and structs as read only",
                            "    - SAUCE: apparmor5.1.0 [31/61]: apparmor-next: apparmor: add audit mode to",
                            "      provide a mechanism to silence complain messages",
                            "    - SAUCE: apparmor5.1.0 [32/61]: apparmor-next: apparmor: fix auditing of",
                            "      mount binary data",
                            "    - SAUCE: apparmor5.1.0 [33/61]: apparmor-next: apparmor: refactory mount",
                            "      to use check_perms",
                            "    - SAUCE: apparmor5.1.0 [34/61]: apparmor-next: apparmor: drop use of",
                            "      _confined variant for iteration",
                            "    - SAUCE: apparmor5.1.0 [35/61]: apparmor-next: apparmor: constify aa_perms",
                            "      parameters that are read-only",
                            "    - SAUCE: apparmor5.1.0 [36/61]: apparmor-next: apparmor: constify",
                            "      aa_profile parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [37/61]: apparmor-next: apparmor: constify aa_dfa",
                            "      parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [38/61]: apparmor-next: apparmor: constify aa_label",
                            "      parameters on read-only query helpers",
                            "    - SAUCE: apparmor5.1.0 [39/61]: apparmor-next-next: apparmor: setup slab",
                            "      cache for audit data",
                            "    - SAUCE: apparmor5.1.0 [40/61]: apparmor-next-next: apparmor: add the",
                            "      ability for profiles to have a learning cache",
                            "    - SAUCE: apparmor5.1.0 [41/61]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.1.0 [42/61]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.1.0 [43/61]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.1.0 [44/61]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.1.0 [45/61]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.1.0 [46/61]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [47/61]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [48/61]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.1.0 [50/61]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.1.0 [51/61]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.1.0 [52/61]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.1.0 [53/61]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.1.0 [54/61]: apparmor: mqueue: prevent",
                            "      profile->disconnected double free in aa_free_profile",
                            "    - SAUCE: apparmor5.1.0 [55/61]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.1.0 [58/61]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.1.0 [56/61]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.1.0 [57/61]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.1.0 [49/61]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Drop DEP-8 tests from kernel packages (LP: #2160302)",
                            "    - [Packaging] Drop DEP-8 tests from kernel source",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] updateconfigs after rebase to v7.2-rc6",
                            "    - [Config] Enable SECURITY_APPARMOR_COMPRESSED_POLICY",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163401,
                            2147533,
                            1990064,
                            2144679,
                            2142956,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602,
                            2160302
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:46:26 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-2.2 -proposed tracker (LP: #2161304)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Changes.md: dropping reboot=pci quirks for sandy bridge hw",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161304
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:29:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-1.1 -proposed tracker (LP: #2160497)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160497,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:07:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-0.0 -proposed tracker (LP: #2159617)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] update annotations scripts",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.2-rc1 rebase",
                            "    - [Config] updateconfigs after v7.2-rc1 rebase",
                            "    - SAUCE: thunderbolt: fixup move of pci_device out of tb_nhi",
                            "    - [Packaging] integrate SBOM generation into the build",
                            "    - SAUCE: fixup s/strncpy/strscpy/ in compat_uts_machine= kernel command",
                            "      line override",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: media: venus: core: guard SC8280XP/SM8350 resources behind !IRIS",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159617,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47337",
                                "url": "https://ubuntu.com/security/CVE-2026-47337",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47334",
                                "url": "https://ubuntu.com/security/CVE-2026-47334",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47333",
                                "url": "https://ubuntu.com/security/CVE-2026-47333",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47332",
                                "url": "https://ubuntu.com/security/CVE-2026-47332",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47330",
                                "url": "https://ubuntu.com/security/CVE-2026-47330",
                                "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47329",
                                "url": "https://ubuntu.com/security/CVE-2026-47329",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47327",
                                "url": "https://ubuntu.com/security/CVE-2026-47327",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47328",
                                "url": "https://ubuntu.com/security/CVE-2026-47328",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47326",
                                "url": "https://ubuntu.com/security/CVE-2026-47326",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-5.5 -proposed tracker (LP: #2156849)",
                            "",
                            "  * MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260",
                            "    renders upside-down (LP: #2155837)",
                            "    - SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14",
                            "      Premium PA14260",
                            "",
                            "  * ov08x40 module mounted upside down on a certain DELL platforms",
                            "    (LP: #2146517)",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for new Dell XPS laptops with",
                            "      upside down sensors",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for Dell 14 laptops with upside",
                            "      down sensors",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747)",
                            "    - SAUCE: apparmor: pass big_resp to handler",
                            "    - SAUCE: apparmor: remove redundant kref_init for listener->count",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47337",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47334",
                            "    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47333",
                            "    - SAUCE: apparmor: fix dfa unpacking size of the notification filter",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47332",
                            "    - SAUCE: apparmor: fix size check against type instead of pointer",
                            "",
                            "  * apparmor: LLVM/clang build failure due to uninitialized variable in",
                            "    notify.c (LP: #2148809) // CVE-2026-47330",
                            "    - SAUCE: apparmor: initialize variable used in uninitialized context",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47329",
                            "    - SAUCE: apparmor: fix name validation bypass on notification",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47327 //",
                            "    CVE-2026-47328",
                            "    - SAUCE: apparmor: fix glob memory leak after kstrdup",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47326",
                            "    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.0.0 [57/57]: apparmor: add the ability to use interface",
                            "      in network mediation.",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [29/57]: apparmor: fix fine grained inet mediation",
                            "      sock_file_perm",
                            "    - SAUCE: apparmor5.0.0 [32/57]: apparmor-next 7.1: apparmor: enable",
                            "      differential encoding",
                            "    - SAUCE: apparmor5.0.0 [33/57]: apparmor-next 7.1: apparmor: propagate",
                            "      -ENOMEM correctly in unpack_table",
                            "    - SAUCE: apparmor5.0.0 [36/57]: apparmor-next 7.1: apparmor: use",
                            "      __label_make_stale in __aa_proxy_redirect",
                            "    - SAUCE: apparmor5.0.0 [37/57]: apparmor-next 7.1: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.0.0 [39/57]: apparmor-next 7.1: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1: apparmor: fix",
                            "      rawdata_f_data implicit flex array",
                            "    - SAUCE: apparmor5.0.0 [42/57]: apparmor-next 7.1: apparmor: free rawdata",
                            "      as soon as possible",
                            "    - SAUCE: apparmor5.0.0 [43/57]: apparmor-next 7.1: apparmor: Initial",
                            "      support for compressed policies",
                            "    - SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1: apparmor: fix potential",
                            "      UAF in aa_replace_profiles",
                            "    - SAUCE: apparmor5.0.0 [45/57]: apparmor-next 7.1: apparmor: hide unused",
                            "      get_loaddata_common_ref() function",
                            "    - SAUCE: apparmor5.0.0 [47/57]: apparmor: fix packed tag on v5 header",
                            "      struct",
                            "    - SAUCE: apparmor5.0.0 [48/57]: apparmor: add temporal caching to audit",
                            "      responses.",
                            "    - SAUCE: apparmor5.0.0 [49/57]: apparmor: change fn_label_build() call to",
                            "      not return NULL",
                            "    - SAUCE: apparmor5.0.0 [50/57]: apparmor: make fn_label_build() capable of",
                            "      handling not supported",
                            "    - SAUCE: apparmor5.0.0 [51/57]: apparmor: move netfilter functions next to",
                            "      the LSM network operations",
                            "    - SAUCE: apparmor5.0.0 [52/57]: apparmor: move sock_rvc_skb() next to",
                            "      inet_conn_request",
                            "    - SAUCE: apparmor5.0.0 [53/57]: apparmor: fix af_unix local addr mediation",
                            "      binding",
                            "    - SAUCE: apparmor5.0.0 [54/57]: cleanups of apparmor af_unix mediation",
                            "    - SAUCE: apparmor5.0.0 [55/57]: apparmor: fix apparmor_secmark_check()",
                            "      when !inet and secmark defined.",
                            "    - SAUCE: apparmor5.0.0 [56/57]: apparmor: fix auditing of non-mediation",
                            "      falures",
                            "",
                            "  * snap service cannot change apparmor hat (LP: #2139664) // Jellyfin Desktop",
                            "    Flatpak doesn't work with the current AppArmor profile (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1: apparmor: grab ns lock",
                            "      and refresh when looking up changehat child profiles",
                            "",
                            "  * AppArmor blocks write(2) to network sockets with Linux 6.19 (LP: #2141298)",
                            "    - SAUCE: apparmor5.0.0 [28/57]: apparmor: fix aa_label_sk_perm to check",
                            "      for RULE_MEDIATES_NET",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.0.0 [1/57]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.0.0 [2/57]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.0.0 [3/57]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.0.0 [4/57]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.0.0 [5/57]: Revert \"apparmor: gate make fine grained",
                            "      unix mediation behind v9 abi\"",
                            "    - SAUCE: apparmor5.0.0 [6/57]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.0.0 [7/57]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [8/57]: apparmor: lift compatibility check out of",
                            "      profile_af_perm",
                            "    - SAUCE: apparmor5.0.0 [9/57]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [10/57]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.0.0 [12/57]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.0.0 [13/57]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.0.0 [14/57]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.0.0 [15/57]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.0.0 [16/57]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.0.0 [19/57]: apparmor: prompt: setup slab cache for",
                            "      audit data",
                            "    - SAUCE: apparmor5.0.0 [20/57]: apparmor: prompt: add the ability for",
                            "      profiles to have a learning cache",
                            "    - SAUCE: apparmor5.0.0 [21/57]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "    - SAUCE: apparmor5.0.0 [22/57]: apparmor: prompt: pass prompt boolean",
                            "      through into path_name as well",
                            "    - SAUCE: apparmor5.0.0 [23/57]: apparmor: check for supported version in",
                            "      notification messages.",
                            "    - SAUCE: apparmor5.0.0 [24/57]: apparmor: refactor building notice so it",
                            "      is easier to extend",
                            "    - SAUCE: apparmor5.0.0 [25/57]: apparmor: switch from ENOTSUPP to",
                            "      EPROTONOSUPPORT",
                            "    - SAUCE: apparmor5.0.0 [26/57]: apparmor: add support for meta data tags",
                            "    - SAUCE: apparmor5.0.0 [27/57]: apparmor: prevent profile->disconnected",
                            "      double free in aa_free_profile",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.0.0 [17/57]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.0.0 [18/57]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.0.0 [11/57]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] enable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "    - [Packaging] Fix cross-builds",
                            "    - [Config] updateconfigs after v7.1 rebase",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2156849,
                            2155837,
                            2146517,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2148809,
                            2151747,
                            2151747,
                            2151747,
                            1990064,
                            2144679,
                            2142956,
                            2139664,
                            2142956,
                            2141298,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:38:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-1.1 -proposed tracker (LP: #2154256)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "",
                            "  * resolute ubuntu_kernel_selftests:seccomp_build test compilation issue",
                            "    (LP: #2154174)",
                            "    - SAUCE: selftests/seccomp fix compilation issue for amd64",
                            "",
                            "  * Kernel 6.19-rc8 does not include GPIB driver (LP: #2152714)",
                            "    - [Config] Enable CONFIG_GPIB for amd64",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.1-rc4 rebase",
                            "    - [packaging] Install gdb scripts again",
                            "    - [Config] updateconfigs after v7.1-rc5 rebase",
                            "    - [Packaging] templates: Use a for-loop for run-parts",
                            "    - [Packaging] Remove dead debian.master/rules.d/x32.mk",
                            "    - [Packaging] Remove orphaned debian/v4l2loopback-modules.ignore",
                            "    - [Packaging] Remove orphaned debian/zfs-modules.ignore",
                            "    - [Packaging] Remove deprecated linux-doc transitional stub",
                            "    - [Packaging] Remove dead comment referencing gcc-4.7 in control.stub.in",
                            "    - [Packaging] Remove dead comment in ppc64el.mk",
                            "    - [Packaging] Remove stale legacy code",
                            "    - [Packaging] rules: Drop an obsolete check for do_zstd_ko",
                            "    - [Config] toolchain version update",
                            "    - [Packaging] update Ubuntu.md",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154256,
                            1786013,
                            2154174,
                            2152714
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:08:55 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 09:59:13 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * resolute/linux: 7.0.0-15.15 -proposed tracker (LP: #2148866)",
                            "",
                            "  * Qualcomm X1E: Speaker overdrive causes hardware protection shutdown",
                            "    (LP: #2149808)",
                            "    - SAUCE: ASoC: qcom: x1e80100: limit speaker volumes",
                            "",
                            "  * intel-ipu7 / intel-ipu7-isys modules are shipped unsigned in latest",
                            "    Resolute kernels, breaking Secure Boot systems  (LP: #2148718)",
                            "    - [packaging] add intel-ipu7 to signature inclusion list",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2148866,
                            2149808,
                            2148718
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:02:19 +0200"
                    }
                ],
                "notes": "linux-image-7.2.0-5-generic version '7.2.0-5.5' (source package linux version '7.2.0-5.5') was added. linux-image-7.2.0-5-generic version '7.2.0-5.5' has the same source package name, linux, as removed package linux-headers-7.0.0-14. As such we can use the source package version of the removed package, '7.0.0-14.14', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-main-modules-zfs-7.2.0-5-generic",
                "from_version": {
                    "source_package_name": "linux-main-signed",
                    "source_package_version": "7.0.0-14.14+3",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux-main-signed",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1786013,
                    1786013,
                    1786013,
                    1786013
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "",
                            "  * Miscellaneous upstream changes",
                            "    - Revert \"lmm: Add synthetic dependency for LMM package, to stop early",
                            "      promotion\"",
                            ""
                        ],
                        "package": "linux-main-signed",
                        "version": "7.0.0-14.14+3",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 14 Apr 2026 13:38:00 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/dkms-versions -- update from kernel-versions",
                            "      (main/d2026.04.13)",
                            ""
                        ],
                        "package": "linux-main-signed",
                        "version": "7.0.0-14.14+2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 14 Apr 2026 09:23:27 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/dkms-versions -- update from kernel-versions",
                            "      (main/d2026.04.13)",
                            ""
                        ],
                        "package": "linux-main-signed",
                        "version": "7.0.0-14.14+1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Mon, 13 Apr 2026 20:03:08 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.0.0-14.14",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            "",
                            "  * Miscellaneous upstream changes",
                            "    - Cleanup d/package.config from LRM config options",
                            "    - lmm: cleanup and add copyright notice",
                            "    - lmm: Fix an issue for the in-series copy phase",
                            "    - lmm: Make off_series the default mechanism",
                            "    - lmm: Allow skipping specific DKMS for specific flavours at build time",
                            "    - lmm: move final artifacts from /ubuntu to /kernel",
                            "    - lmm: Fix DKMS build for chroot environments",
                            "    - lmm: Add synthetic dependency for LMM package, to stop early promotion",
                            ""
                        ],
                        "package": "linux-main-signed",
                        "version": "7.0.0-14.14",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Apr 2026 11:36:59 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.0.0-13.13",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            "    - [Packaging] debian/dkms-versions -- update from kernel-versions",
                            "      (main/d2026.04.07)",
                            ""
                        ],
                        "package": "linux-main-signed",
                        "version": "7.0.0-13.13",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 08 Apr 2026 06:59:33 +0200"
                    }
                ],
                "notes": "linux-main-modules-zfs-7.2.0-5-generic version '7.2.0-5.5' (source package linux-main-signed version '7.2.0-5.5') was added. linux-main-modules-zfs-7.2.0-5-generic version '7.2.0-5.5' has the same source package name, linux-main-signed, as removed package linux-main-modules-zfs-7.0.0-14-generic. As such we can use the source package version of the removed package, '7.0.0-14.14+3', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-modules-7.2.0-5-generic",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-47337",
                        "url": "https://ubuntu.com/security/CVE-2026-47337",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47334",
                        "url": "https://ubuntu.com/security/CVE-2026-47334",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47333",
                        "url": "https://ubuntu.com/security/CVE-2026-47333",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47332",
                        "url": "https://ubuntu.com/security/CVE-2026-47332",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47330",
                        "url": "https://ubuntu.com/security/CVE-2026-47330",
                        "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47329",
                        "url": "https://ubuntu.com/security/CVE-2026-47329",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47327",
                        "url": "https://ubuntu.com/security/CVE-2026-47327",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47328",
                        "url": "https://ubuntu.com/security/CVE-2026-47328",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47326",
                        "url": "https://ubuntu.com/security/CVE-2026-47326",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163667,
                    2163401,
                    2147533,
                    1990064,
                    2144679,
                    2142956,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2160302,
                    2161304,
                    2160497,
                    1786013,
                    2159617,
                    1786013,
                    2156849,
                    2155837,
                    2146517,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2148809,
                    2151747,
                    2151747,
                    2151747,
                    1990064,
                    2144679,
                    2142956,
                    2139664,
                    2142956,
                    2141298,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2154256,
                    1786013,
                    2154174,
                    2152714,
                    2148866,
                    2149808,
                    2148718
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.2.0-5.5 -proposed tracker (LP: #2163667)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163667
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 16:59:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-4.4 -proposed tracker (LP: #2163401)",
                            "",
                            "  * AA: disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED (LP: #2147533)",
                            "    - [Config] disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.1.0 [60/61]: apparmor: skb: add the ability to use",
                            "      interface in network mediation.",
                            "    - SAUCE: apparmor5.1.0 [61/61]: apparmor: skb: switch to using sk_ctx crit",
                            "      section",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.1.0 [59/61]: apparmor: skb: fix",
                            "      apparmor_secmark_check() when !inet and secmark defined.",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.1.0 [1/61]: apparmor-next: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.1.0 [2/61]: apparmor-next: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.1.0 [3/61]: apparmor-next: apparmor: Initial support",
                            "      for compressed policies",
                            "    - SAUCE: apparmor5.1.0 [4/61]: apparmor-next: apparmor: fix alternate",
                            "      loaders ability to load compressed policy",
                            "    - SAUCE: apparmor5.1.0 [5/61]: apparmor-next: apparmor: replace",
                            "      decompress_zstd() prototype with its entity",
                            "    - SAUCE: apparmor5.1.0 [6/61]: apparmor-next: apparmor: leverage",
                            "      audit_log_n_untrustedstring() when possible",
                            "    - SAUCE: apparmor5.1.0 [7/61]: apparmor-next: apparmor: switch website",
                            "      link to https",
                            "    - SAUCE: apparmor5.1.0 [8/61]: apparmor-next: apparmor: compressed_data",
                            "      not described in aa_get_data_from_compressed",
                            "    - SAUCE: apparmor5.1.0 [9/61]: apparmor-next: apparmor: Fix build failure",
                            "      when ZSTD_DECOMPRESS is not enabled",
                            "    - SAUCE: apparmor5.1.0 [10/61]: apparmor-next: apparmor: fix implicit",
                            "      declaration of function 'decompress_zstd'",
                            "    - SAUCE: apparmor5.1.0 [11/61]: apparmor-next: apparmor: Fix warning:",
                            "      'decompress_zstd' defined but not used",
                            "    - SAUCE: apparmor5.1.0 [12/61]: apparmor-next: apparmor: use",
                            "      SEND_SIG_NOINFO instead of NULL in aa_audit()",
                            "    - SAUCE: apparmor5.1.0 [13/61]: apparmor-next: apparmor: fix cred UAF",
                            "      caused by begin_current_label_crit_section()",
                            "    - SAUCE: apparmor5.1.0 [14/61]: apparmor-next: apparmor: optimize",
                            "      current_label_crit_section() with needput",
                            "    - SAUCE: apparmor5.1.0 [15/61]: apparmor-next: apparmor: fix integer",
                            "      overflow in verify_tags() bounds check",
                            "    - SAUCE: apparmor5.1.0 [16/61]: apparmor-next: apparmor: fix out-of-bounds",
                            "      write when null terminating a label vec",
                            "    - SAUCE: apparmor5.1.0 [17/61]: apparmor-next: apparmor: fix error",
                            "      handling for copy_from_user in policy_update",
                            "    - SAUCE: apparmor5.1.0 [18/61]: apparmor-next: apparmor: make",
                            "      MEDIATES_AF_UNIX its own fn",
                            "    - SAUCE: apparmor5.1.0 [19/61]: apparmor-next: apparmor: refactor network",
                            "      sock mediation in preparation for inet mediation",
                            "    - SAUCE: apparmor5.1.0 [20/61]: apparmor-next: apparmor: push inet",
                            "      mediation into profile callbacks, and improve auditing",
                            "    - SAUCE: apparmor5.1.0 [21/61]: apparmor-next: apparmor: refactor network",
                            "      socket mediation to support compatibility",
                            "    - SAUCE: apparmor5.1.0 [22/61]: apparmor-next: apparmor: move netfilter",
                            "      functions next to the LSM network operations",
                            "    - SAUCE: apparmor5.1.0 [23/61]: apparmor-next: apparmor: move",
                            "      sock_rcv_skb() next to inet_conn_request",
                            "    - SAUCE: apparmor5.1.0 [24/61]: apparmor-next: apparmor: reserve mediation",
                            "      class for packet mediation",
                            "    - SAUCE: apparmor5.1.0 [25/61]: apparmor-next: apparmor: fix unconfined",
                            "      user namespace restriction forced stack",
                            "    - SAUCE: apparmor5.1.0 [26/61]: apparmor-next: apparmor: refactor xattr",
                            "      attachment, to take the file path",
                            "    - SAUCE: apparmor5.1.0 [27/61]: apparmor-next: apparmor: fix race",
                            "      condition in label replacement",
                            "    - SAUCE: apparmor5.1.0 [28/61]: apparmor-next: apparmor: make table entry",
                            "      count last enum for static tables",
                            "    - SAUCE: apparmor5.1.0 [29/61]: apparmor-next: apparmor: fix error debug",
                            "      output in fn_label_build",
                            "    - SAUCE: apparmor5.1.0 [30/61]: apparmor-next: apparmor: mark static",
                            "      tables and structs as read only",
                            "    - SAUCE: apparmor5.1.0 [31/61]: apparmor-next: apparmor: add audit mode to",
                            "      provide a mechanism to silence complain messages",
                            "    - SAUCE: apparmor5.1.0 [32/61]: apparmor-next: apparmor: fix auditing of",
                            "      mount binary data",
                            "    - SAUCE: apparmor5.1.0 [33/61]: apparmor-next: apparmor: refactory mount",
                            "      to use check_perms",
                            "    - SAUCE: apparmor5.1.0 [34/61]: apparmor-next: apparmor: drop use of",
                            "      _confined variant for iteration",
                            "    - SAUCE: apparmor5.1.0 [35/61]: apparmor-next: apparmor: constify aa_perms",
                            "      parameters that are read-only",
                            "    - SAUCE: apparmor5.1.0 [36/61]: apparmor-next: apparmor: constify",
                            "      aa_profile parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [37/61]: apparmor-next: apparmor: constify aa_dfa",
                            "      parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [38/61]: apparmor-next: apparmor: constify aa_label",
                            "      parameters on read-only query helpers",
                            "    - SAUCE: apparmor5.1.0 [39/61]: apparmor-next-next: apparmor: setup slab",
                            "      cache for audit data",
                            "    - SAUCE: apparmor5.1.0 [40/61]: apparmor-next-next: apparmor: add the",
                            "      ability for profiles to have a learning cache",
                            "    - SAUCE: apparmor5.1.0 [41/61]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.1.0 [42/61]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.1.0 [43/61]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.1.0 [44/61]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.1.0 [45/61]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.1.0 [46/61]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [47/61]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [48/61]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.1.0 [50/61]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.1.0 [51/61]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.1.0 [52/61]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.1.0 [53/61]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.1.0 [54/61]: apparmor: mqueue: prevent",
                            "      profile->disconnected double free in aa_free_profile",
                            "    - SAUCE: apparmor5.1.0 [55/61]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.1.0 [58/61]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.1.0 [56/61]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.1.0 [57/61]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.1.0 [49/61]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Drop DEP-8 tests from kernel packages (LP: #2160302)",
                            "    - [Packaging] Drop DEP-8 tests from kernel source",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] updateconfigs after rebase to v7.2-rc6",
                            "    - [Config] Enable SECURITY_APPARMOR_COMPRESSED_POLICY",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163401,
                            2147533,
                            1990064,
                            2144679,
                            2142956,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602,
                            2160302
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:46:26 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-2.2 -proposed tracker (LP: #2161304)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Changes.md: dropping reboot=pci quirks for sandy bridge hw",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161304
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:29:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-1.1 -proposed tracker (LP: #2160497)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160497,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:07:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-0.0 -proposed tracker (LP: #2159617)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] update annotations scripts",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.2-rc1 rebase",
                            "    - [Config] updateconfigs after v7.2-rc1 rebase",
                            "    - SAUCE: thunderbolt: fixup move of pci_device out of tb_nhi",
                            "    - [Packaging] integrate SBOM generation into the build",
                            "    - SAUCE: fixup s/strncpy/strscpy/ in compat_uts_machine= kernel command",
                            "      line override",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: media: venus: core: guard SC8280XP/SM8350 resources behind !IRIS",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159617,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47337",
                                "url": "https://ubuntu.com/security/CVE-2026-47337",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47334",
                                "url": "https://ubuntu.com/security/CVE-2026-47334",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47333",
                                "url": "https://ubuntu.com/security/CVE-2026-47333",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47332",
                                "url": "https://ubuntu.com/security/CVE-2026-47332",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47330",
                                "url": "https://ubuntu.com/security/CVE-2026-47330",
                                "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47329",
                                "url": "https://ubuntu.com/security/CVE-2026-47329",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47327",
                                "url": "https://ubuntu.com/security/CVE-2026-47327",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47328",
                                "url": "https://ubuntu.com/security/CVE-2026-47328",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47326",
                                "url": "https://ubuntu.com/security/CVE-2026-47326",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-5.5 -proposed tracker (LP: #2156849)",
                            "",
                            "  * MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260",
                            "    renders upside-down (LP: #2155837)",
                            "    - SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14",
                            "      Premium PA14260",
                            "",
                            "  * ov08x40 module mounted upside down on a certain DELL platforms",
                            "    (LP: #2146517)",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for new Dell XPS laptops with",
                            "      upside down sensors",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for Dell 14 laptops with upside",
                            "      down sensors",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747)",
                            "    - SAUCE: apparmor: pass big_resp to handler",
                            "    - SAUCE: apparmor: remove redundant kref_init for listener->count",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47337",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47334",
                            "    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47333",
                            "    - SAUCE: apparmor: fix dfa unpacking size of the notification filter",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47332",
                            "    - SAUCE: apparmor: fix size check against type instead of pointer",
                            "",
                            "  * apparmor: LLVM/clang build failure due to uninitialized variable in",
                            "    notify.c (LP: #2148809) // CVE-2026-47330",
                            "    - SAUCE: apparmor: initialize variable used in uninitialized context",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47329",
                            "    - SAUCE: apparmor: fix name validation bypass on notification",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47327 //",
                            "    CVE-2026-47328",
                            "    - SAUCE: apparmor: fix glob memory leak after kstrdup",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47326",
                            "    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.0.0 [57/57]: apparmor: add the ability to use interface",
                            "      in network mediation.",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [29/57]: apparmor: fix fine grained inet mediation",
                            "      sock_file_perm",
                            "    - SAUCE: apparmor5.0.0 [32/57]: apparmor-next 7.1: apparmor: enable",
                            "      differential encoding",
                            "    - SAUCE: apparmor5.0.0 [33/57]: apparmor-next 7.1: apparmor: propagate",
                            "      -ENOMEM correctly in unpack_table",
                            "    - SAUCE: apparmor5.0.0 [36/57]: apparmor-next 7.1: apparmor: use",
                            "      __label_make_stale in __aa_proxy_redirect",
                            "    - SAUCE: apparmor5.0.0 [37/57]: apparmor-next 7.1: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.0.0 [39/57]: apparmor-next 7.1: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1: apparmor: fix",
                            "      rawdata_f_data implicit flex array",
                            "    - SAUCE: apparmor5.0.0 [42/57]: apparmor-next 7.1: apparmor: free rawdata",
                            "      as soon as possible",
                            "    - SAUCE: apparmor5.0.0 [43/57]: apparmor-next 7.1: apparmor: Initial",
                            "      support for compressed policies",
                            "    - SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1: apparmor: fix potential",
                            "      UAF in aa_replace_profiles",
                            "    - SAUCE: apparmor5.0.0 [45/57]: apparmor-next 7.1: apparmor: hide unused",
                            "      get_loaddata_common_ref() function",
                            "    - SAUCE: apparmor5.0.0 [47/57]: apparmor: fix packed tag on v5 header",
                            "      struct",
                            "    - SAUCE: apparmor5.0.0 [48/57]: apparmor: add temporal caching to audit",
                            "      responses.",
                            "    - SAUCE: apparmor5.0.0 [49/57]: apparmor: change fn_label_build() call to",
                            "      not return NULL",
                            "    - SAUCE: apparmor5.0.0 [50/57]: apparmor: make fn_label_build() capable of",
                            "      handling not supported",
                            "    - SAUCE: apparmor5.0.0 [51/57]: apparmor: move netfilter functions next to",
                            "      the LSM network operations",
                            "    - SAUCE: apparmor5.0.0 [52/57]: apparmor: move sock_rvc_skb() next to",
                            "      inet_conn_request",
                            "    - SAUCE: apparmor5.0.0 [53/57]: apparmor: fix af_unix local addr mediation",
                            "      binding",
                            "    - SAUCE: apparmor5.0.0 [54/57]: cleanups of apparmor af_unix mediation",
                            "    - SAUCE: apparmor5.0.0 [55/57]: apparmor: fix apparmor_secmark_check()",
                            "      when !inet and secmark defined.",
                            "    - SAUCE: apparmor5.0.0 [56/57]: apparmor: fix auditing of non-mediation",
                            "      falures",
                            "",
                            "  * snap service cannot change apparmor hat (LP: #2139664) // Jellyfin Desktop",
                            "    Flatpak doesn't work with the current AppArmor profile (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1: apparmor: grab ns lock",
                            "      and refresh when looking up changehat child profiles",
                            "",
                            "  * AppArmor blocks write(2) to network sockets with Linux 6.19 (LP: #2141298)",
                            "    - SAUCE: apparmor5.0.0 [28/57]: apparmor: fix aa_label_sk_perm to check",
                            "      for RULE_MEDIATES_NET",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.0.0 [1/57]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.0.0 [2/57]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.0.0 [3/57]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.0.0 [4/57]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.0.0 [5/57]: Revert \"apparmor: gate make fine grained",
                            "      unix mediation behind v9 abi\"",
                            "    - SAUCE: apparmor5.0.0 [6/57]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.0.0 [7/57]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [8/57]: apparmor: lift compatibility check out of",
                            "      profile_af_perm",
                            "    - SAUCE: apparmor5.0.0 [9/57]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [10/57]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.0.0 [12/57]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.0.0 [13/57]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.0.0 [14/57]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.0.0 [15/57]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.0.0 [16/57]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.0.0 [19/57]: apparmor: prompt: setup slab cache for",
                            "      audit data",
                            "    - SAUCE: apparmor5.0.0 [20/57]: apparmor: prompt: add the ability for",
                            "      profiles to have a learning cache",
                            "    - SAUCE: apparmor5.0.0 [21/57]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "    - SAUCE: apparmor5.0.0 [22/57]: apparmor: prompt: pass prompt boolean",
                            "      through into path_name as well",
                            "    - SAUCE: apparmor5.0.0 [23/57]: apparmor: check for supported version in",
                            "      notification messages.",
                            "    - SAUCE: apparmor5.0.0 [24/57]: apparmor: refactor building notice so it",
                            "      is easier to extend",
                            "    - SAUCE: apparmor5.0.0 [25/57]: apparmor: switch from ENOTSUPP to",
                            "      EPROTONOSUPPORT",
                            "    - SAUCE: apparmor5.0.0 [26/57]: apparmor: add support for meta data tags",
                            "    - SAUCE: apparmor5.0.0 [27/57]: apparmor: prevent profile->disconnected",
                            "      double free in aa_free_profile",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.0.0 [17/57]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.0.0 [18/57]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.0.0 [11/57]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] enable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "    - [Packaging] Fix cross-builds",
                            "    - [Config] updateconfigs after v7.1 rebase",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2156849,
                            2155837,
                            2146517,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2148809,
                            2151747,
                            2151747,
                            2151747,
                            1990064,
                            2144679,
                            2142956,
                            2139664,
                            2142956,
                            2141298,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:38:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-1.1 -proposed tracker (LP: #2154256)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "",
                            "  * resolute ubuntu_kernel_selftests:seccomp_build test compilation issue",
                            "    (LP: #2154174)",
                            "    - SAUCE: selftests/seccomp fix compilation issue for amd64",
                            "",
                            "  * Kernel 6.19-rc8 does not include GPIB driver (LP: #2152714)",
                            "    - [Config] Enable CONFIG_GPIB for amd64",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.1-rc4 rebase",
                            "    - [packaging] Install gdb scripts again",
                            "    - [Config] updateconfigs after v7.1-rc5 rebase",
                            "    - [Packaging] templates: Use a for-loop for run-parts",
                            "    - [Packaging] Remove dead debian.master/rules.d/x32.mk",
                            "    - [Packaging] Remove orphaned debian/v4l2loopback-modules.ignore",
                            "    - [Packaging] Remove orphaned debian/zfs-modules.ignore",
                            "    - [Packaging] Remove deprecated linux-doc transitional stub",
                            "    - [Packaging] Remove dead comment referencing gcc-4.7 in control.stub.in",
                            "    - [Packaging] Remove dead comment in ppc64el.mk",
                            "    - [Packaging] Remove stale legacy code",
                            "    - [Packaging] rules: Drop an obsolete check for do_zstd_ko",
                            "    - [Config] toolchain version update",
                            "    - [Packaging] update Ubuntu.md",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154256,
                            1786013,
                            2154174,
                            2152714
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:08:55 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 09:59:13 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * resolute/linux: 7.0.0-15.15 -proposed tracker (LP: #2148866)",
                            "",
                            "  * Qualcomm X1E: Speaker overdrive causes hardware protection shutdown",
                            "    (LP: #2149808)",
                            "    - SAUCE: ASoC: qcom: x1e80100: limit speaker volumes",
                            "",
                            "  * intel-ipu7 / intel-ipu7-isys modules are shipped unsigned in latest",
                            "    Resolute kernels, breaking Secure Boot systems  (LP: #2148718)",
                            "    - [packaging] add intel-ipu7 to signature inclusion list",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2148866,
                            2149808,
                            2148718
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:02:19 +0200"
                    }
                ],
                "notes": "linux-modules-7.2.0-5-generic version '7.2.0-5.5' (source package linux version '7.2.0-5.5') was added. linux-modules-7.2.0-5-generic version '7.2.0-5.5' has the same source package name, linux, as removed package linux-headers-7.0.0-14. As such we can use the source package version of the removed package, '7.0.0-14.14', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-tools-7.2.0-5",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-47337",
                        "url": "https://ubuntu.com/security/CVE-2026-47337",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47334",
                        "url": "https://ubuntu.com/security/CVE-2026-47334",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47333",
                        "url": "https://ubuntu.com/security/CVE-2026-47333",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47332",
                        "url": "https://ubuntu.com/security/CVE-2026-47332",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47330",
                        "url": "https://ubuntu.com/security/CVE-2026-47330",
                        "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47329",
                        "url": "https://ubuntu.com/security/CVE-2026-47329",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47327",
                        "url": "https://ubuntu.com/security/CVE-2026-47327",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47328",
                        "url": "https://ubuntu.com/security/CVE-2026-47328",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47326",
                        "url": "https://ubuntu.com/security/CVE-2026-47326",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163667,
                    2163401,
                    2147533,
                    1990064,
                    2144679,
                    2142956,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2160302,
                    2161304,
                    2160497,
                    1786013,
                    2159617,
                    1786013,
                    2156849,
                    2155837,
                    2146517,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2148809,
                    2151747,
                    2151747,
                    2151747,
                    1990064,
                    2144679,
                    2142956,
                    2139664,
                    2142956,
                    2141298,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2154256,
                    1786013,
                    2154174,
                    2152714,
                    2148866,
                    2149808,
                    2148718
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.2.0-5.5 -proposed tracker (LP: #2163667)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163667
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 16:59:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-4.4 -proposed tracker (LP: #2163401)",
                            "",
                            "  * AA: disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED (LP: #2147533)",
                            "    - [Config] disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.1.0 [60/61]: apparmor: skb: add the ability to use",
                            "      interface in network mediation.",
                            "    - SAUCE: apparmor5.1.0 [61/61]: apparmor: skb: switch to using sk_ctx crit",
                            "      section",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.1.0 [59/61]: apparmor: skb: fix",
                            "      apparmor_secmark_check() when !inet and secmark defined.",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.1.0 [1/61]: apparmor-next: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.1.0 [2/61]: apparmor-next: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.1.0 [3/61]: apparmor-next: apparmor: Initial support",
                            "      for compressed policies",
                            "    - SAUCE: apparmor5.1.0 [4/61]: apparmor-next: apparmor: fix alternate",
                            "      loaders ability to load compressed policy",
                            "    - SAUCE: apparmor5.1.0 [5/61]: apparmor-next: apparmor: replace",
                            "      decompress_zstd() prototype with its entity",
                            "    - SAUCE: apparmor5.1.0 [6/61]: apparmor-next: apparmor: leverage",
                            "      audit_log_n_untrustedstring() when possible",
                            "    - SAUCE: apparmor5.1.0 [7/61]: apparmor-next: apparmor: switch website",
                            "      link to https",
                            "    - SAUCE: apparmor5.1.0 [8/61]: apparmor-next: apparmor: compressed_data",
                            "      not described in aa_get_data_from_compressed",
                            "    - SAUCE: apparmor5.1.0 [9/61]: apparmor-next: apparmor: Fix build failure",
                            "      when ZSTD_DECOMPRESS is not enabled",
                            "    - SAUCE: apparmor5.1.0 [10/61]: apparmor-next: apparmor: fix implicit",
                            "      declaration of function 'decompress_zstd'",
                            "    - SAUCE: apparmor5.1.0 [11/61]: apparmor-next: apparmor: Fix warning:",
                            "      'decompress_zstd' defined but not used",
                            "    - SAUCE: apparmor5.1.0 [12/61]: apparmor-next: apparmor: use",
                            "      SEND_SIG_NOINFO instead of NULL in aa_audit()",
                            "    - SAUCE: apparmor5.1.0 [13/61]: apparmor-next: apparmor: fix cred UAF",
                            "      caused by begin_current_label_crit_section()",
                            "    - SAUCE: apparmor5.1.0 [14/61]: apparmor-next: apparmor: optimize",
                            "      current_label_crit_section() with needput",
                            "    - SAUCE: apparmor5.1.0 [15/61]: apparmor-next: apparmor: fix integer",
                            "      overflow in verify_tags() bounds check",
                            "    - SAUCE: apparmor5.1.0 [16/61]: apparmor-next: apparmor: fix out-of-bounds",
                            "      write when null terminating a label vec",
                            "    - SAUCE: apparmor5.1.0 [17/61]: apparmor-next: apparmor: fix error",
                            "      handling for copy_from_user in policy_update",
                            "    - SAUCE: apparmor5.1.0 [18/61]: apparmor-next: apparmor: make",
                            "      MEDIATES_AF_UNIX its own fn",
                            "    - SAUCE: apparmor5.1.0 [19/61]: apparmor-next: apparmor: refactor network",
                            "      sock mediation in preparation for inet mediation",
                            "    - SAUCE: apparmor5.1.0 [20/61]: apparmor-next: apparmor: push inet",
                            "      mediation into profile callbacks, and improve auditing",
                            "    - SAUCE: apparmor5.1.0 [21/61]: apparmor-next: apparmor: refactor network",
                            "      socket mediation to support compatibility",
                            "    - SAUCE: apparmor5.1.0 [22/61]: apparmor-next: apparmor: move netfilter",
                            "      functions next to the LSM network operations",
                            "    - SAUCE: apparmor5.1.0 [23/61]: apparmor-next: apparmor: move",
                            "      sock_rcv_skb() next to inet_conn_request",
                            "    - SAUCE: apparmor5.1.0 [24/61]: apparmor-next: apparmor: reserve mediation",
                            "      class for packet mediation",
                            "    - SAUCE: apparmor5.1.0 [25/61]: apparmor-next: apparmor: fix unconfined",
                            "      user namespace restriction forced stack",
                            "    - SAUCE: apparmor5.1.0 [26/61]: apparmor-next: apparmor: refactor xattr",
                            "      attachment, to take the file path",
                            "    - SAUCE: apparmor5.1.0 [27/61]: apparmor-next: apparmor: fix race",
                            "      condition in label replacement",
                            "    - SAUCE: apparmor5.1.0 [28/61]: apparmor-next: apparmor: make table entry",
                            "      count last enum for static tables",
                            "    - SAUCE: apparmor5.1.0 [29/61]: apparmor-next: apparmor: fix error debug",
                            "      output in fn_label_build",
                            "    - SAUCE: apparmor5.1.0 [30/61]: apparmor-next: apparmor: mark static",
                            "      tables and structs as read only",
                            "    - SAUCE: apparmor5.1.0 [31/61]: apparmor-next: apparmor: add audit mode to",
                            "      provide a mechanism to silence complain messages",
                            "    - SAUCE: apparmor5.1.0 [32/61]: apparmor-next: apparmor: fix auditing of",
                            "      mount binary data",
                            "    - SAUCE: apparmor5.1.0 [33/61]: apparmor-next: apparmor: refactory mount",
                            "      to use check_perms",
                            "    - SAUCE: apparmor5.1.0 [34/61]: apparmor-next: apparmor: drop use of",
                            "      _confined variant for iteration",
                            "    - SAUCE: apparmor5.1.0 [35/61]: apparmor-next: apparmor: constify aa_perms",
                            "      parameters that are read-only",
                            "    - SAUCE: apparmor5.1.0 [36/61]: apparmor-next: apparmor: constify",
                            "      aa_profile parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [37/61]: apparmor-next: apparmor: constify aa_dfa",
                            "      parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [38/61]: apparmor-next: apparmor: constify aa_label",
                            "      parameters on read-only query helpers",
                            "    - SAUCE: apparmor5.1.0 [39/61]: apparmor-next-next: apparmor: setup slab",
                            "      cache for audit data",
                            "    - SAUCE: apparmor5.1.0 [40/61]: apparmor-next-next: apparmor: add the",
                            "      ability for profiles to have a learning cache",
                            "    - SAUCE: apparmor5.1.0 [41/61]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.1.0 [42/61]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.1.0 [43/61]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.1.0 [44/61]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.1.0 [45/61]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.1.0 [46/61]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [47/61]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [48/61]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.1.0 [50/61]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.1.0 [51/61]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.1.0 [52/61]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.1.0 [53/61]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.1.0 [54/61]: apparmor: mqueue: prevent",
                            "      profile->disconnected double free in aa_free_profile",
                            "    - SAUCE: apparmor5.1.0 [55/61]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.1.0 [58/61]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.1.0 [56/61]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.1.0 [57/61]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.1.0 [49/61]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Drop DEP-8 tests from kernel packages (LP: #2160302)",
                            "    - [Packaging] Drop DEP-8 tests from kernel source",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] updateconfigs after rebase to v7.2-rc6",
                            "    - [Config] Enable SECURITY_APPARMOR_COMPRESSED_POLICY",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163401,
                            2147533,
                            1990064,
                            2144679,
                            2142956,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602,
                            2160302
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:46:26 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-2.2 -proposed tracker (LP: #2161304)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Changes.md: dropping reboot=pci quirks for sandy bridge hw",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161304
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:29:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-1.1 -proposed tracker (LP: #2160497)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160497,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:07:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-0.0 -proposed tracker (LP: #2159617)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] update annotations scripts",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.2-rc1 rebase",
                            "    - [Config] updateconfigs after v7.2-rc1 rebase",
                            "    - SAUCE: thunderbolt: fixup move of pci_device out of tb_nhi",
                            "    - [Packaging] integrate SBOM generation into the build",
                            "    - SAUCE: fixup s/strncpy/strscpy/ in compat_uts_machine= kernel command",
                            "      line override",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: media: venus: core: guard SC8280XP/SM8350 resources behind !IRIS",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159617,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47337",
                                "url": "https://ubuntu.com/security/CVE-2026-47337",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47334",
                                "url": "https://ubuntu.com/security/CVE-2026-47334",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47333",
                                "url": "https://ubuntu.com/security/CVE-2026-47333",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47332",
                                "url": "https://ubuntu.com/security/CVE-2026-47332",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47330",
                                "url": "https://ubuntu.com/security/CVE-2026-47330",
                                "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47329",
                                "url": "https://ubuntu.com/security/CVE-2026-47329",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47327",
                                "url": "https://ubuntu.com/security/CVE-2026-47327",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47328",
                                "url": "https://ubuntu.com/security/CVE-2026-47328",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47326",
                                "url": "https://ubuntu.com/security/CVE-2026-47326",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-5.5 -proposed tracker (LP: #2156849)",
                            "",
                            "  * MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260",
                            "    renders upside-down (LP: #2155837)",
                            "    - SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14",
                            "      Premium PA14260",
                            "",
                            "  * ov08x40 module mounted upside down on a certain DELL platforms",
                            "    (LP: #2146517)",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for new Dell XPS laptops with",
                            "      upside down sensors",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for Dell 14 laptops with upside",
                            "      down sensors",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747)",
                            "    - SAUCE: apparmor: pass big_resp to handler",
                            "    - SAUCE: apparmor: remove redundant kref_init for listener->count",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47337",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47334",
                            "    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47333",
                            "    - SAUCE: apparmor: fix dfa unpacking size of the notification filter",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47332",
                            "    - SAUCE: apparmor: fix size check against type instead of pointer",
                            "",
                            "  * apparmor: LLVM/clang build failure due to uninitialized variable in",
                            "    notify.c (LP: #2148809) // CVE-2026-47330",
                            "    - SAUCE: apparmor: initialize variable used in uninitialized context",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47329",
                            "    - SAUCE: apparmor: fix name validation bypass on notification",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47327 //",
                            "    CVE-2026-47328",
                            "    - SAUCE: apparmor: fix glob memory leak after kstrdup",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47326",
                            "    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.0.0 [57/57]: apparmor: add the ability to use interface",
                            "      in network mediation.",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [29/57]: apparmor: fix fine grained inet mediation",
                            "      sock_file_perm",
                            "    - SAUCE: apparmor5.0.0 [32/57]: apparmor-next 7.1: apparmor: enable",
                            "      differential encoding",
                            "    - SAUCE: apparmor5.0.0 [33/57]: apparmor-next 7.1: apparmor: propagate",
                            "      -ENOMEM correctly in unpack_table",
                            "    - SAUCE: apparmor5.0.0 [36/57]: apparmor-next 7.1: apparmor: use",
                            "      __label_make_stale in __aa_proxy_redirect",
                            "    - SAUCE: apparmor5.0.0 [37/57]: apparmor-next 7.1: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.0.0 [39/57]: apparmor-next 7.1: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1: apparmor: fix",
                            "      rawdata_f_data implicit flex array",
                            "    - SAUCE: apparmor5.0.0 [42/57]: apparmor-next 7.1: apparmor: free rawdata",
                            "      as soon as possible",
                            "    - SAUCE: apparmor5.0.0 [43/57]: apparmor-next 7.1: apparmor: Initial",
                            "      support for compressed policies",
                            "    - SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1: apparmor: fix potential",
                            "      UAF in aa_replace_profiles",
                            "    - SAUCE: apparmor5.0.0 [45/57]: apparmor-next 7.1: apparmor: hide unused",
                            "      get_loaddata_common_ref() function",
                            "    - SAUCE: apparmor5.0.0 [47/57]: apparmor: fix packed tag on v5 header",
                            "      struct",
                            "    - SAUCE: apparmor5.0.0 [48/57]: apparmor: add temporal caching to audit",
                            "      responses.",
                            "    - SAUCE: apparmor5.0.0 [49/57]: apparmor: change fn_label_build() call to",
                            "      not return NULL",
                            "    - SAUCE: apparmor5.0.0 [50/57]: apparmor: make fn_label_build() capable of",
                            "      handling not supported",
                            "    - SAUCE: apparmor5.0.0 [51/57]: apparmor: move netfilter functions next to",
                            "      the LSM network operations",
                            "    - SAUCE: apparmor5.0.0 [52/57]: apparmor: move sock_rvc_skb() next to",
                            "      inet_conn_request",
                            "    - SAUCE: apparmor5.0.0 [53/57]: apparmor: fix af_unix local addr mediation",
                            "      binding",
                            "    - SAUCE: apparmor5.0.0 [54/57]: cleanups of apparmor af_unix mediation",
                            "    - SAUCE: apparmor5.0.0 [55/57]: apparmor: fix apparmor_secmark_check()",
                            "      when !inet and secmark defined.",
                            "    - SAUCE: apparmor5.0.0 [56/57]: apparmor: fix auditing of non-mediation",
                            "      falures",
                            "",
                            "  * snap service cannot change apparmor hat (LP: #2139664) // Jellyfin Desktop",
                            "    Flatpak doesn't work with the current AppArmor profile (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1: apparmor: grab ns lock",
                            "      and refresh when looking up changehat child profiles",
                            "",
                            "  * AppArmor blocks write(2) to network sockets with Linux 6.19 (LP: #2141298)",
                            "    - SAUCE: apparmor5.0.0 [28/57]: apparmor: fix aa_label_sk_perm to check",
                            "      for RULE_MEDIATES_NET",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.0.0 [1/57]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.0.0 [2/57]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.0.0 [3/57]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.0.0 [4/57]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.0.0 [5/57]: Revert \"apparmor: gate make fine grained",
                            "      unix mediation behind v9 abi\"",
                            "    - SAUCE: apparmor5.0.0 [6/57]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.0.0 [7/57]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [8/57]: apparmor: lift compatibility check out of",
                            "      profile_af_perm",
                            "    - SAUCE: apparmor5.0.0 [9/57]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [10/57]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.0.0 [12/57]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.0.0 [13/57]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.0.0 [14/57]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.0.0 [15/57]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.0.0 [16/57]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.0.0 [19/57]: apparmor: prompt: setup slab cache for",
                            "      audit data",
                            "    - SAUCE: apparmor5.0.0 [20/57]: apparmor: prompt: add the ability for",
                            "      profiles to have a learning cache",
                            "    - SAUCE: apparmor5.0.0 [21/57]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "    - SAUCE: apparmor5.0.0 [22/57]: apparmor: prompt: pass prompt boolean",
                            "      through into path_name as well",
                            "    - SAUCE: apparmor5.0.0 [23/57]: apparmor: check for supported version in",
                            "      notification messages.",
                            "    - SAUCE: apparmor5.0.0 [24/57]: apparmor: refactor building notice so it",
                            "      is easier to extend",
                            "    - SAUCE: apparmor5.0.0 [25/57]: apparmor: switch from ENOTSUPP to",
                            "      EPROTONOSUPPORT",
                            "    - SAUCE: apparmor5.0.0 [26/57]: apparmor: add support for meta data tags",
                            "    - SAUCE: apparmor5.0.0 [27/57]: apparmor: prevent profile->disconnected",
                            "      double free in aa_free_profile",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.0.0 [17/57]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.0.0 [18/57]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.0.0 [11/57]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] enable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "    - [Packaging] Fix cross-builds",
                            "    - [Config] updateconfigs after v7.1 rebase",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2156849,
                            2155837,
                            2146517,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2148809,
                            2151747,
                            2151747,
                            2151747,
                            1990064,
                            2144679,
                            2142956,
                            2139664,
                            2142956,
                            2141298,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:38:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-1.1 -proposed tracker (LP: #2154256)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "",
                            "  * resolute ubuntu_kernel_selftests:seccomp_build test compilation issue",
                            "    (LP: #2154174)",
                            "    - SAUCE: selftests/seccomp fix compilation issue for amd64",
                            "",
                            "  * Kernel 6.19-rc8 does not include GPIB driver (LP: #2152714)",
                            "    - [Config] Enable CONFIG_GPIB for amd64",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.1-rc4 rebase",
                            "    - [packaging] Install gdb scripts again",
                            "    - [Config] updateconfigs after v7.1-rc5 rebase",
                            "    - [Packaging] templates: Use a for-loop for run-parts",
                            "    - [Packaging] Remove dead debian.master/rules.d/x32.mk",
                            "    - [Packaging] Remove orphaned debian/v4l2loopback-modules.ignore",
                            "    - [Packaging] Remove orphaned debian/zfs-modules.ignore",
                            "    - [Packaging] Remove deprecated linux-doc transitional stub",
                            "    - [Packaging] Remove dead comment referencing gcc-4.7 in control.stub.in",
                            "    - [Packaging] Remove dead comment in ppc64el.mk",
                            "    - [Packaging] Remove stale legacy code",
                            "    - [Packaging] rules: Drop an obsolete check for do_zstd_ko",
                            "    - [Config] toolchain version update",
                            "    - [Packaging] update Ubuntu.md",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154256,
                            1786013,
                            2154174,
                            2152714
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:08:55 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 09:59:13 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * resolute/linux: 7.0.0-15.15 -proposed tracker (LP: #2148866)",
                            "",
                            "  * Qualcomm X1E: Speaker overdrive causes hardware protection shutdown",
                            "    (LP: #2149808)",
                            "    - SAUCE: ASoC: qcom: x1e80100: limit speaker volumes",
                            "",
                            "  * intel-ipu7 / intel-ipu7-isys modules are shipped unsigned in latest",
                            "    Resolute kernels, breaking Secure Boot systems  (LP: #2148718)",
                            "    - [packaging] add intel-ipu7 to signature inclusion list",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2148866,
                            2149808,
                            2148718
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:02:19 +0200"
                    }
                ],
                "notes": "linux-tools-7.2.0-5 version '7.2.0-5.5' (source package linux version '7.2.0-5.5') was added. linux-tools-7.2.0-5 version '7.2.0-5.5' has the same source package name, linux, as removed package linux-headers-7.0.0-14. As such we can use the source package version of the removed package, '7.0.0-14.14', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-tools-7.2.0-5-generic",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-47337",
                        "url": "https://ubuntu.com/security/CVE-2026-47337",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47334",
                        "url": "https://ubuntu.com/security/CVE-2026-47334",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47333",
                        "url": "https://ubuntu.com/security/CVE-2026-47333",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47332",
                        "url": "https://ubuntu.com/security/CVE-2026-47332",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47330",
                        "url": "https://ubuntu.com/security/CVE-2026-47330",
                        "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47329",
                        "url": "https://ubuntu.com/security/CVE-2026-47329",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47327",
                        "url": "https://ubuntu.com/security/CVE-2026-47327",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47328",
                        "url": "https://ubuntu.com/security/CVE-2026-47328",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47326",
                        "url": "https://ubuntu.com/security/CVE-2026-47326",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163667,
                    2163401,
                    2147533,
                    1990064,
                    2144679,
                    2142956,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2160302,
                    2161304,
                    2160497,
                    1786013,
                    2159617,
                    1786013,
                    2156849,
                    2155837,
                    2146517,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2148809,
                    2151747,
                    2151747,
                    2151747,
                    1990064,
                    2144679,
                    2142956,
                    2139664,
                    2142956,
                    2141298,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2154256,
                    1786013,
                    2154174,
                    2152714,
                    2148866,
                    2149808,
                    2148718
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.2.0-5.5 -proposed tracker (LP: #2163667)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163667
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 16:59:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-4.4 -proposed tracker (LP: #2163401)",
                            "",
                            "  * AA: disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED (LP: #2147533)",
                            "    - [Config] disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.1.0 [60/61]: apparmor: skb: add the ability to use",
                            "      interface in network mediation.",
                            "    - SAUCE: apparmor5.1.0 [61/61]: apparmor: skb: switch to using sk_ctx crit",
                            "      section",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.1.0 [59/61]: apparmor: skb: fix",
                            "      apparmor_secmark_check() when !inet and secmark defined.",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.1.0 [1/61]: apparmor-next: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.1.0 [2/61]: apparmor-next: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.1.0 [3/61]: apparmor-next: apparmor: Initial support",
                            "      for compressed policies",
                            "    - SAUCE: apparmor5.1.0 [4/61]: apparmor-next: apparmor: fix alternate",
                            "      loaders ability to load compressed policy",
                            "    - SAUCE: apparmor5.1.0 [5/61]: apparmor-next: apparmor: replace",
                            "      decompress_zstd() prototype with its entity",
                            "    - SAUCE: apparmor5.1.0 [6/61]: apparmor-next: apparmor: leverage",
                            "      audit_log_n_untrustedstring() when possible",
                            "    - SAUCE: apparmor5.1.0 [7/61]: apparmor-next: apparmor: switch website",
                            "      link to https",
                            "    - SAUCE: apparmor5.1.0 [8/61]: apparmor-next: apparmor: compressed_data",
                            "      not described in aa_get_data_from_compressed",
                            "    - SAUCE: apparmor5.1.0 [9/61]: apparmor-next: apparmor: Fix build failure",
                            "      when ZSTD_DECOMPRESS is not enabled",
                            "    - SAUCE: apparmor5.1.0 [10/61]: apparmor-next: apparmor: fix implicit",
                            "      declaration of function 'decompress_zstd'",
                            "    - SAUCE: apparmor5.1.0 [11/61]: apparmor-next: apparmor: Fix warning:",
                            "      'decompress_zstd' defined but not used",
                            "    - SAUCE: apparmor5.1.0 [12/61]: apparmor-next: apparmor: use",
                            "      SEND_SIG_NOINFO instead of NULL in aa_audit()",
                            "    - SAUCE: apparmor5.1.0 [13/61]: apparmor-next: apparmor: fix cred UAF",
                            "      caused by begin_current_label_crit_section()",
                            "    - SAUCE: apparmor5.1.0 [14/61]: apparmor-next: apparmor: optimize",
                            "      current_label_crit_section() with needput",
                            "    - SAUCE: apparmor5.1.0 [15/61]: apparmor-next: apparmor: fix integer",
                            "      overflow in verify_tags() bounds check",
                            "    - SAUCE: apparmor5.1.0 [16/61]: apparmor-next: apparmor: fix out-of-bounds",
                            "      write when null terminating a label vec",
                            "    - SAUCE: apparmor5.1.0 [17/61]: apparmor-next: apparmor: fix error",
                            "      handling for copy_from_user in policy_update",
                            "    - SAUCE: apparmor5.1.0 [18/61]: apparmor-next: apparmor: make",
                            "      MEDIATES_AF_UNIX its own fn",
                            "    - SAUCE: apparmor5.1.0 [19/61]: apparmor-next: apparmor: refactor network",
                            "      sock mediation in preparation for inet mediation",
                            "    - SAUCE: apparmor5.1.0 [20/61]: apparmor-next: apparmor: push inet",
                            "      mediation into profile callbacks, and improve auditing",
                            "    - SAUCE: apparmor5.1.0 [21/61]: apparmor-next: apparmor: refactor network",
                            "      socket mediation to support compatibility",
                            "    - SAUCE: apparmor5.1.0 [22/61]: apparmor-next: apparmor: move netfilter",
                            "      functions next to the LSM network operations",
                            "    - SAUCE: apparmor5.1.0 [23/61]: apparmor-next: apparmor: move",
                            "      sock_rcv_skb() next to inet_conn_request",
                            "    - SAUCE: apparmor5.1.0 [24/61]: apparmor-next: apparmor: reserve mediation",
                            "      class for packet mediation",
                            "    - SAUCE: apparmor5.1.0 [25/61]: apparmor-next: apparmor: fix unconfined",
                            "      user namespace restriction forced stack",
                            "    - SAUCE: apparmor5.1.0 [26/61]: apparmor-next: apparmor: refactor xattr",
                            "      attachment, to take the file path",
                            "    - SAUCE: apparmor5.1.0 [27/61]: apparmor-next: apparmor: fix race",
                            "      condition in label replacement",
                            "    - SAUCE: apparmor5.1.0 [28/61]: apparmor-next: apparmor: make table entry",
                            "      count last enum for static tables",
                            "    - SAUCE: apparmor5.1.0 [29/61]: apparmor-next: apparmor: fix error debug",
                            "      output in fn_label_build",
                            "    - SAUCE: apparmor5.1.0 [30/61]: apparmor-next: apparmor: mark static",
                            "      tables and structs as read only",
                            "    - SAUCE: apparmor5.1.0 [31/61]: apparmor-next: apparmor: add audit mode to",
                            "      provide a mechanism to silence complain messages",
                            "    - SAUCE: apparmor5.1.0 [32/61]: apparmor-next: apparmor: fix auditing of",
                            "      mount binary data",
                            "    - SAUCE: apparmor5.1.0 [33/61]: apparmor-next: apparmor: refactory mount",
                            "      to use check_perms",
                            "    - SAUCE: apparmor5.1.0 [34/61]: apparmor-next: apparmor: drop use of",
                            "      _confined variant for iteration",
                            "    - SAUCE: apparmor5.1.0 [35/61]: apparmor-next: apparmor: constify aa_perms",
                            "      parameters that are read-only",
                            "    - SAUCE: apparmor5.1.0 [36/61]: apparmor-next: apparmor: constify",
                            "      aa_profile parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [37/61]: apparmor-next: apparmor: constify aa_dfa",
                            "      parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [38/61]: apparmor-next: apparmor: constify aa_label",
                            "      parameters on read-only query helpers",
                            "    - SAUCE: apparmor5.1.0 [39/61]: apparmor-next-next: apparmor: setup slab",
                            "      cache for audit data",
                            "    - SAUCE: apparmor5.1.0 [40/61]: apparmor-next-next: apparmor: add the",
                            "      ability for profiles to have a learning cache",
                            "    - SAUCE: apparmor5.1.0 [41/61]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.1.0 [42/61]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.1.0 [43/61]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.1.0 [44/61]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.1.0 [45/61]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.1.0 [46/61]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [47/61]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [48/61]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.1.0 [50/61]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.1.0 [51/61]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.1.0 [52/61]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.1.0 [53/61]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.1.0 [54/61]: apparmor: mqueue: prevent",
                            "      profile->disconnected double free in aa_free_profile",
                            "    - SAUCE: apparmor5.1.0 [55/61]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.1.0 [58/61]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.1.0 [56/61]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.1.0 [57/61]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.1.0 [49/61]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Drop DEP-8 tests from kernel packages (LP: #2160302)",
                            "    - [Packaging] Drop DEP-8 tests from kernel source",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] updateconfigs after rebase to v7.2-rc6",
                            "    - [Config] Enable SECURITY_APPARMOR_COMPRESSED_POLICY",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163401,
                            2147533,
                            1990064,
                            2144679,
                            2142956,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602,
                            2160302
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:46:26 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-2.2 -proposed tracker (LP: #2161304)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Changes.md: dropping reboot=pci quirks for sandy bridge hw",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161304
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:29:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-1.1 -proposed tracker (LP: #2160497)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160497,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:07:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-0.0 -proposed tracker (LP: #2159617)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] update annotations scripts",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.2-rc1 rebase",
                            "    - [Config] updateconfigs after v7.2-rc1 rebase",
                            "    - SAUCE: thunderbolt: fixup move of pci_device out of tb_nhi",
                            "    - [Packaging] integrate SBOM generation into the build",
                            "    - SAUCE: fixup s/strncpy/strscpy/ in compat_uts_machine= kernel command",
                            "      line override",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: media: venus: core: guard SC8280XP/SM8350 resources behind !IRIS",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159617,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47337",
                                "url": "https://ubuntu.com/security/CVE-2026-47337",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47334",
                                "url": "https://ubuntu.com/security/CVE-2026-47334",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47333",
                                "url": "https://ubuntu.com/security/CVE-2026-47333",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47332",
                                "url": "https://ubuntu.com/security/CVE-2026-47332",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47330",
                                "url": "https://ubuntu.com/security/CVE-2026-47330",
                                "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47329",
                                "url": "https://ubuntu.com/security/CVE-2026-47329",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47327",
                                "url": "https://ubuntu.com/security/CVE-2026-47327",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47328",
                                "url": "https://ubuntu.com/security/CVE-2026-47328",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47326",
                                "url": "https://ubuntu.com/security/CVE-2026-47326",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-5.5 -proposed tracker (LP: #2156849)",
                            "",
                            "  * MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260",
                            "    renders upside-down (LP: #2155837)",
                            "    - SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14",
                            "      Premium PA14260",
                            "",
                            "  * ov08x40 module mounted upside down on a certain DELL platforms",
                            "    (LP: #2146517)",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for new Dell XPS laptops with",
                            "      upside down sensors",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for Dell 14 laptops with upside",
                            "      down sensors",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747)",
                            "    - SAUCE: apparmor: pass big_resp to handler",
                            "    - SAUCE: apparmor: remove redundant kref_init for listener->count",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47337",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47334",
                            "    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47333",
                            "    - SAUCE: apparmor: fix dfa unpacking size of the notification filter",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47332",
                            "    - SAUCE: apparmor: fix size check against type instead of pointer",
                            "",
                            "  * apparmor: LLVM/clang build failure due to uninitialized variable in",
                            "    notify.c (LP: #2148809) // CVE-2026-47330",
                            "    - SAUCE: apparmor: initialize variable used in uninitialized context",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47329",
                            "    - SAUCE: apparmor: fix name validation bypass on notification",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47327 //",
                            "    CVE-2026-47328",
                            "    - SAUCE: apparmor: fix glob memory leak after kstrdup",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47326",
                            "    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.0.0 [57/57]: apparmor: add the ability to use interface",
                            "      in network mediation.",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [29/57]: apparmor: fix fine grained inet mediation",
                            "      sock_file_perm",
                            "    - SAUCE: apparmor5.0.0 [32/57]: apparmor-next 7.1: apparmor: enable",
                            "      differential encoding",
                            "    - SAUCE: apparmor5.0.0 [33/57]: apparmor-next 7.1: apparmor: propagate",
                            "      -ENOMEM correctly in unpack_table",
                            "    - SAUCE: apparmor5.0.0 [36/57]: apparmor-next 7.1: apparmor: use",
                            "      __label_make_stale in __aa_proxy_redirect",
                            "    - SAUCE: apparmor5.0.0 [37/57]: apparmor-next 7.1: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.0.0 [39/57]: apparmor-next 7.1: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1: apparmor: fix",
                            "      rawdata_f_data implicit flex array",
                            "    - SAUCE: apparmor5.0.0 [42/57]: apparmor-next 7.1: apparmor: free rawdata",
                            "      as soon as possible",
                            "    - SAUCE: apparmor5.0.0 [43/57]: apparmor-next 7.1: apparmor: Initial",
                            "      support for compressed policies",
                            "    - SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1: apparmor: fix potential",
                            "      UAF in aa_replace_profiles",
                            "    - SAUCE: apparmor5.0.0 [45/57]: apparmor-next 7.1: apparmor: hide unused",
                            "      get_loaddata_common_ref() function",
                            "    - SAUCE: apparmor5.0.0 [47/57]: apparmor: fix packed tag on v5 header",
                            "      struct",
                            "    - SAUCE: apparmor5.0.0 [48/57]: apparmor: add temporal caching to audit",
                            "      responses.",
                            "    - SAUCE: apparmor5.0.0 [49/57]: apparmor: change fn_label_build() call to",
                            "      not return NULL",
                            "    - SAUCE: apparmor5.0.0 [50/57]: apparmor: make fn_label_build() capable of",
                            "      handling not supported",
                            "    - SAUCE: apparmor5.0.0 [51/57]: apparmor: move netfilter functions next to",
                            "      the LSM network operations",
                            "    - SAUCE: apparmor5.0.0 [52/57]: apparmor: move sock_rvc_skb() next to",
                            "      inet_conn_request",
                            "    - SAUCE: apparmor5.0.0 [53/57]: apparmor: fix af_unix local addr mediation",
                            "      binding",
                            "    - SAUCE: apparmor5.0.0 [54/57]: cleanups of apparmor af_unix mediation",
                            "    - SAUCE: apparmor5.0.0 [55/57]: apparmor: fix apparmor_secmark_check()",
                            "      when !inet and secmark defined.",
                            "    - SAUCE: apparmor5.0.0 [56/57]: apparmor: fix auditing of non-mediation",
                            "      falures",
                            "",
                            "  * snap service cannot change apparmor hat (LP: #2139664) // Jellyfin Desktop",
                            "    Flatpak doesn't work with the current AppArmor profile (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1: apparmor: grab ns lock",
                            "      and refresh when looking up changehat child profiles",
                            "",
                            "  * AppArmor blocks write(2) to network sockets with Linux 6.19 (LP: #2141298)",
                            "    - SAUCE: apparmor5.0.0 [28/57]: apparmor: fix aa_label_sk_perm to check",
                            "      for RULE_MEDIATES_NET",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.0.0 [1/57]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.0.0 [2/57]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.0.0 [3/57]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.0.0 [4/57]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.0.0 [5/57]: Revert \"apparmor: gate make fine grained",
                            "      unix mediation behind v9 abi\"",
                            "    - SAUCE: apparmor5.0.0 [6/57]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.0.0 [7/57]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [8/57]: apparmor: lift compatibility check out of",
                            "      profile_af_perm",
                            "    - SAUCE: apparmor5.0.0 [9/57]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [10/57]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.0.0 [12/57]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.0.0 [13/57]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.0.0 [14/57]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.0.0 [15/57]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.0.0 [16/57]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.0.0 [19/57]: apparmor: prompt: setup slab cache for",
                            "      audit data",
                            "    - SAUCE: apparmor5.0.0 [20/57]: apparmor: prompt: add the ability for",
                            "      profiles to have a learning cache",
                            "    - SAUCE: apparmor5.0.0 [21/57]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "    - SAUCE: apparmor5.0.0 [22/57]: apparmor: prompt: pass prompt boolean",
                            "      through into path_name as well",
                            "    - SAUCE: apparmor5.0.0 [23/57]: apparmor: check for supported version in",
                            "      notification messages.",
                            "    - SAUCE: apparmor5.0.0 [24/57]: apparmor: refactor building notice so it",
                            "      is easier to extend",
                            "    - SAUCE: apparmor5.0.0 [25/57]: apparmor: switch from ENOTSUPP to",
                            "      EPROTONOSUPPORT",
                            "    - SAUCE: apparmor5.0.0 [26/57]: apparmor: add support for meta data tags",
                            "    - SAUCE: apparmor5.0.0 [27/57]: apparmor: prevent profile->disconnected",
                            "      double free in aa_free_profile",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.0.0 [17/57]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.0.0 [18/57]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.0.0 [11/57]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] enable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "    - [Packaging] Fix cross-builds",
                            "    - [Config] updateconfigs after v7.1 rebase",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2156849,
                            2155837,
                            2146517,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2148809,
                            2151747,
                            2151747,
                            2151747,
                            1990064,
                            2144679,
                            2142956,
                            2139664,
                            2142956,
                            2141298,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:38:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-1.1 -proposed tracker (LP: #2154256)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "",
                            "  * resolute ubuntu_kernel_selftests:seccomp_build test compilation issue",
                            "    (LP: #2154174)",
                            "    - SAUCE: selftests/seccomp fix compilation issue for amd64",
                            "",
                            "  * Kernel 6.19-rc8 does not include GPIB driver (LP: #2152714)",
                            "    - [Config] Enable CONFIG_GPIB for amd64",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.1-rc4 rebase",
                            "    - [packaging] Install gdb scripts again",
                            "    - [Config] updateconfigs after v7.1-rc5 rebase",
                            "    - [Packaging] templates: Use a for-loop for run-parts",
                            "    - [Packaging] Remove dead debian.master/rules.d/x32.mk",
                            "    - [Packaging] Remove orphaned debian/v4l2loopback-modules.ignore",
                            "    - [Packaging] Remove orphaned debian/zfs-modules.ignore",
                            "    - [Packaging] Remove deprecated linux-doc transitional stub",
                            "    - [Packaging] Remove dead comment referencing gcc-4.7 in control.stub.in",
                            "    - [Packaging] Remove dead comment in ppc64el.mk",
                            "    - [Packaging] Remove stale legacy code",
                            "    - [Packaging] rules: Drop an obsolete check for do_zstd_ko",
                            "    - [Config] toolchain version update",
                            "    - [Packaging] update Ubuntu.md",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154256,
                            1786013,
                            2154174,
                            2152714
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:08:55 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 09:59:13 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * resolute/linux: 7.0.0-15.15 -proposed tracker (LP: #2148866)",
                            "",
                            "  * Qualcomm X1E: Speaker overdrive causes hardware protection shutdown",
                            "    (LP: #2149808)",
                            "    - SAUCE: ASoC: qcom: x1e80100: limit speaker volumes",
                            "",
                            "  * intel-ipu7 / intel-ipu7-isys modules are shipped unsigned in latest",
                            "    Resolute kernels, breaking Secure Boot systems  (LP: #2148718)",
                            "    - [packaging] add intel-ipu7 to signature inclusion list",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2148866,
                            2149808,
                            2148718
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:02:19 +0200"
                    }
                ],
                "notes": "linux-tools-7.2.0-5-generic version '7.2.0-5.5' (source package linux version '7.2.0-5.5') was added. linux-tools-7.2.0-5-generic version '7.2.0-5.5' has the same source package name, linux, as removed package linux-headers-7.0.0-14. As such we can use the source package version of the removed package, '7.0.0-14.14', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "python3-charset-normalizer",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "python-charset-normalizer",
                    "source_package_version": "3.4.7-2",
                    "version": "3.4.7-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Add debian/salsa-ci.yml to test <nodoc> profile",
                            "  * Tag Sphinx build-deps as <!nodoc>",
                            "  * Bump Standards-Version to 4.7.4, drop Priority: tag",
                            "  * Rewrite d/watch in v5 format",
                            ""
                        ],
                        "package": "python-charset-normalizer",
                        "version": "3.4.7-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sun, 05 Jul 2026 14:33:21 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream release:",
                            "    - Correctly propagate bytes|bytearray support in functions",
                            "      (Closes: #1135452).",
                            ""
                        ],
                        "package": "python-charset-normalizer",
                        "version": "3.4.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Wed, 06 May 2026 14:49:29 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Explicitly check that mypyc works for each supported Python version",
                            "    (closes: #1121820).",
                            ""
                        ],
                        "package": "python-charset-normalizer",
                        "version": "3.4.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Wed, 03 Dec 2025 11:42:51 +0000"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "sqv",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "rust-sequoia-sqv",
                    "source_package_version": "1.4.0-1ubuntu2",
                    "version": "1.4.0-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "rust-sequoia-sqv",
                        "version": "1.4.0-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 16:15:33 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable. Remaining changes:",
                            "    - debian/rules:",
                            "      + enable build size optimizations on 32-bit",
                            "      + add vendor targets",
                            "    - debian/patches:",
                            "      + remove unused deps from Cargo.toml",
                            "      + run cargo update",
                            "    - debian/control:",
                            "      + remove vendored Build-Depends-Arch",
                            "      + add libssl-dev and pkgconf Depends",
                            "      + Build-Depend on libclang-dev for bindgen",
                            "      + Update XS-Vendored-Sources-Rust field",
                            "    - d/README.source: add vendoring instructions",
                            "    - Update vendored rust crates",
                            "    - Update debian/source/include-binaries",
                            ""
                        ],
                        "package": "rust-sequoia-sqv",
                        "version": "1.4.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Mon, 13 Jul 2026 11:51:26 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Package sequoia-sqv 1.4.0 from crates.io using debcargo 2.8.3",
                            "    - update d/copyright years.",
                            ""
                        ],
                        "package": "rust-sequoia-sqv",
                        "version": "1.4.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Holger Levsen <holger@debian.org>",
                        "date": "Sun, 28 Jun 2026 11:20:20 +0200"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "tpm-udev",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "tpm2-tss",
                    "source_package_version": "4.1.3-7ubuntu1",
                    "version": "4.1.3-7ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2154861
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Added patches for OpenSSL4 compatibility (LP: #2154861)",
                            "    - d/p/fix-for-openssl4-compat.patch",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154861
                        ],
                        "author": "Alan Moore <alan.moore@canonical.com>",
                        "date": "Wed, 5 Aug 2026 13:51:08 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:07:29 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Downgrade dependency from lib packages to tpm-udev to recommends",
                            "    (Closes: #1141826)",
                            ""
                        ],
                        "package": "tpm2-tss",
                        "version": "4.1.3-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mario Limonciello <superm1@debian.org>",
                        "date": "Mon, 13 Jul 2026 23:55:55 -0500"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "removed": {
        "deb": [
            {
                "name": "busybox-initramfs",
                "from_version": {
                    "source_package_name": "busybox",
                    "source_package_version": "1:1.37.0-10.1ubuntu2",
                    "version": "1:1.37.0-10.1ubuntu2"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-headers-7.0.0-14",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-headers-7.0.0-14-generic",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-image-7.0.0-14-generic",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-main-modules-zfs-7.0.0-14-generic",
                "from_version": {
                    "source_package_name": "linux-main-signed",
                    "source_package_version": "7.0.0-14.14+3",
                    "version": "7.0.0-14.14+3"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-modules-7.0.0-14-generic",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-tools-7.0.0-14",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-tools-7.0.0-14-generic",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "notes": "Changelog diff for Ubuntu 26.10 stonking image from daily image serial 20260810 to 20260911",
    "from_series": "stonking",
    "to_series": "stonking",
    "from_serial": "20260810",
    "to_serial": "20260911",
    "from_manifest_filename": "daily_manifest.previous",
    "to_manifest_filename": "manifest.current"
}