{
    "summary": {
        "snap": {
            "added": [],
            "removed": [],
            "diff": []
        },
        "deb": {
            "added": [],
            "removed": [],
            "diff": [
                "console-setup",
                "console-setup-linux",
                "curl",
                "keyboard-configuration",
                "libcurl4t64",
                "snapd",
                "wget",
                "xxd"
            ]
        }
    },
    "diff": {
        "deb": [
            {
                "name": "console-setup",
                "from_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.226ubuntu1",
                    "version": "1.226ubuntu1"
                },
                "to_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.226ubuntu1.1",
                    "version": "1.226ubuntu1.1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2152901
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No change rebuild against keymapper 0.6.3ubuntu0~24.04 (LP: #2152901).",
                            "    This should produce the expected pc105.tree file that core24-based",
                            "    Subiquity consumes at build time.",
                            ""
                        ],
                        "package": "console-setup",
                        "version": "1.226ubuntu1.1",
                        "urgency": "medium",
                        "distributions": "noble",
                        "launchpad_bugs_fixed": [
                            2152901
                        ],
                        "author": "Olivier Gayot <olivier.gayot@canonical.com>",
                        "date": "Fri, 05 Jun 2026 16:57:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "console-setup-linux",
                "from_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.226ubuntu1",
                    "version": "1.226ubuntu1"
                },
                "to_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.226ubuntu1.1",
                    "version": "1.226ubuntu1.1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2152901
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No change rebuild against keymapper 0.6.3ubuntu0~24.04 (LP: #2152901).",
                            "    This should produce the expected pc105.tree file that core24-based",
                            "    Subiquity consumes at build time.",
                            ""
                        ],
                        "package": "console-setup",
                        "version": "1.226ubuntu1.1",
                        "urgency": "medium",
                        "distributions": "noble",
                        "launchpad_bugs_fixed": [
                            2152901
                        ],
                        "author": "Olivier Gayot <olivier.gayot@canonical.com>",
                        "date": "Fri, 05 Jun 2026 16:57:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "curl",
                "from_version": {
                    "source_package_name": "curl",
                    "source_package_version": "8.5.0-2ubuntu10.11",
                    "version": "8.5.0-2ubuntu10.11"
                },
                "to_version": {
                    "source_package_name": "curl",
                    "source_package_version": "8.5.0-2ubuntu10.12",
                    "version": "8.5.0-2ubuntu10.12"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-11856",
                        "url": "https://ubuntu.com/security/CVE-2026-11856",
                        "cve_description": "Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the  `Authorization:` header field meant for `hostA`, to `hostB`.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-03 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11856",
                                "url": "https://ubuntu.com/security/CVE-2026-11856",
                                "cve_description": "Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the  `Authorization:` header field meant for `hostA`, to `hostB`.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-03 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Authentication Bypass by Capture-replay",
                            "    - debian/patches/CVE-2026-11856.patch: Flush state on origin or credential",
                            "      change in lib/http_digest.c, lib/urldata.h, lib/vauth/digest.c, and",
                            "      lib/vauth/digest_sspi.c.",
                            "    - CVE-2026-11856",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.5.0-2ubuntu10.12",
                        "urgency": "medium",
                        "distributions": "noble-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Tue, 18 Aug 2026 13:28:10 -0600"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "keyboard-configuration",
                "from_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.226ubuntu1",
                    "version": "1.226ubuntu1"
                },
                "to_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.226ubuntu1.1",
                    "version": "1.226ubuntu1.1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2152901
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No change rebuild against keymapper 0.6.3ubuntu0~24.04 (LP: #2152901).",
                            "    This should produce the expected pc105.tree file that core24-based",
                            "    Subiquity consumes at build time.",
                            ""
                        ],
                        "package": "console-setup",
                        "version": "1.226ubuntu1.1",
                        "urgency": "medium",
                        "distributions": "noble",
                        "launchpad_bugs_fixed": [
                            2152901
                        ],
                        "author": "Olivier Gayot <olivier.gayot@canonical.com>",
                        "date": "Fri, 05 Jun 2026 16:57:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libcurl4t64",
                "from_version": {
                    "source_package_name": "curl",
                    "source_package_version": "8.5.0-2ubuntu10.11",
                    "version": "8.5.0-2ubuntu10.11"
                },
                "to_version": {
                    "source_package_name": "curl",
                    "source_package_version": "8.5.0-2ubuntu10.12",
                    "version": "8.5.0-2ubuntu10.12"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-11856",
                        "url": "https://ubuntu.com/security/CVE-2026-11856",
                        "cve_description": "Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the  `Authorization:` header field meant for `hostA`, to `hostB`.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-03 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11856",
                                "url": "https://ubuntu.com/security/CVE-2026-11856",
                                "cve_description": "Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the  `Authorization:` header field meant for `hostA`, to `hostB`.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-03 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Authentication Bypass by Capture-replay",
                            "    - debian/patches/CVE-2026-11856.patch: Flush state on origin or credential",
                            "      change in lib/http_digest.c, lib/urldata.h, lib/vauth/digest.c, and",
                            "      lib/vauth/digest_sspi.c.",
                            "    - CVE-2026-11856",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.5.0-2ubuntu10.12",
                        "urgency": "medium",
                        "distributions": "noble-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Tue, 18 Aug 2026 13:28:10 -0600"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "snapd",
                "from_version": {
                    "source_package_name": "snapd",
                    "source_package_version": "2.76+ubuntu24.04.1",
                    "version": "2.76+ubuntu24.04.1"
                },
                "to_version": {
                    "source_package_name": "snapd",
                    "source_package_version": "2.76.3+ubuntu24.04",
                    "version": "2.76.3+ubuntu24.04"
                },
                "cves": [
                    {
                        "cve": "CVE-2024-5300",
                        "url": "https://ubuntu.com/security/CVE-2024-5300",
                        "cve_description": "An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns \"complete\" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-21 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-3888",
                        "url": "https://ubuntu.com/security/CVE-2026-3888",
                        "cve_description": "Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-03-17 14:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2158301,
                    2159940,
                    2157692,
                    2067006
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2158301",
                            "    - FDE: support keyboard configuration at install-time for first-boot",
                            "    - FDE: re-enable passphrases/PINs at install-time",
                            "    - FDE: require volumes authentication if HWROT is missing",
                            "    - FDE: bump secboot to rev 457b03a16d19",
                            "    - FDE: use new secboot API for reprovision TPM",
                            "    - Cross-distro: modify SELinux policy to use",
                            "      init_named_socket_activation() for allowing systemd to start snapd",
                            "      through socket activation",
                            "    - packaging: make sure that usr/bin/snap is built with correct build",
                            "      tags on debian sid",
                            "    - Ensure profiles are setup before running prepare-{slot, plug}*",
                            "      hooks",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76.3+ubuntu24.04",
                        "urgency": "medium",
                        "distributions": "noble",
                        "launchpad_bugs_fixed": [
                            2158301
                        ],
                        "author": "Katie May <katie.may@canonical.com>",
                        "date": "Tue, 07 Jul 2026 10:06:48 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2159940",
                            "    - interfaces: steam-support, docker-support | fix mountinfo denial",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76.2+ubuntu24.04",
                        "urgency": "medium",
                        "distributions": "noble",
                        "launchpad_bugs_fixed": [
                            2159940
                        ],
                        "author": "Katie May <katie.may@canonical.com>",
                        "date": "Tue, 07 Jul 2026 08:38:51 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2024-5300",
                                "url": "https://ubuntu.com/security/CVE-2024-5300",
                                "cve_description": "An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns \"complete\" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-21 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-3888",
                                "url": "https://ubuntu.com/security/CVE-2026-3888",
                                "cve_description": "Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-03-17 14:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2157692",
                            "    - LP: #2067006 CVE-2024-5300",
                            "    - CVE-2026-3888",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76.1+ubuntu24.04",
                        "urgency": "medium",
                        "distributions": "noble",
                        "launchpad_bugs_fixed": [
                            2157692,
                            2067006
                        ],
                        "author": "Ernest Lotter <ernest.lotter@canonical.com>",
                        "date": "Thu, 25 Jun 2026 13:09:05 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "wget",
                "from_version": {
                    "source_package_name": "wget",
                    "source_package_version": "1.21.4-1ubuntu4.4",
                    "version": "1.21.4-1ubuntu4.4"
                },
                "to_version": {
                    "source_package_name": "wget",
                    "source_package_version": "1.21.4-1ubuntu4.5",
                    "version": "1.21.4-1ubuntu4.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-58472",
                        "url": "https://ubuntu.com/security/CVE-2026-58472",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163754
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58472",
                                "url": "https://ubuntu.com/security/CVE-2026-58472",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY REGRESSION: Incomplete fix for CVE-2026-58472 (LP: #2163754)",
                            "    - debian/patches/CVE-2026-58472-post1.patch: Fix buffer overflow in",
                            "      src/convert.c",
                            ""
                        ],
                        "package": "wget",
                        "version": "1.21.4-1ubuntu4.5",
                        "urgency": "medium",
                        "distributions": "noble-security",
                        "launchpad_bugs_fixed": [
                            2163754
                        ],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Wed, 19 Aug 2026 18:00:36 -0600"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "xxd",
                "from_version": {
                    "source_package_name": "vim",
                    "source_package_version": "2:9.1.0016-1ubuntu7.18",
                    "version": "2:9.1.0016-1ubuntu7.18"
                },
                "to_version": {
                    "source_package_name": "vim",
                    "source_package_version": "2:9.1.0016-1ubuntu7.19",
                    "version": "2:9.1.0016-1ubuntu7.19"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-28417",
                        "url": "https://ubuntu.com/security/CVE-2026-28417",
                        "cve_description": "Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-02-27 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73071",
                        "url": "https://ubuntu.com/security/CVE-2026-73071",
                        "cve_description": "Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 16:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73072",
                        "url": "https://ubuntu.com/security/CVE-2026-73072",
                        "cve_description": "Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 16:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73074",
                        "url": "https://ubuntu.com/security/CVE-2026-73074",
                        "cve_description": "Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen value from get_text_props() to increment a uint16_t property count beyond 0xffff, wrapping the count to zero and copying existing text-property records into a heap allocation sized for none of them. This issue is fixed in version 9.2.0841.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 16:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73076",
                        "url": "https://ubuntu.com/security/CVE-2026-73076",
                        "cve_description": "Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through :!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 16:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73077",
                        "url": "https://ubuntu.com/security/CVE-2026-73077",
                        "cve_description": "Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating shell arguments. fnameescape() and PATH_ESC_CHARS do not neutralize shell metacharacters before ShKeywordPrg, ZshKeywordPrg, or GetHelp invokes bash, zsh, or PowerShell, allowing arbitrary operating-system commands to execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0839.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 16:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73078",
                        "url": "https://ubuntu.com/security/CVE-2026-73078",
                        "cve_description": "Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed :menu commands. s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), g:netrw_menu_escape, EX_TRLBAR, and netrw#MakeTgt() fail to neutralize the | command separator or single quotes at five construction sites, allowing a crafted path browsed or bookmarked in GUI Vim to execute arbitrary Ex and operating-system commands. This issue is fixed in version 9.2.0840.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 16:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163785
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-28417",
                                "url": "https://ubuntu.com/security/CVE-2026-28417",
                                "cve_description": "Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-02-27 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73071",
                                "url": "https://ubuntu.com/security/CVE-2026-73071",
                                "cve_description": "Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 16:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73072",
                                "url": "https://ubuntu.com/security/CVE-2026-73072",
                                "cve_description": "Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 16:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73074",
                                "url": "https://ubuntu.com/security/CVE-2026-73074",
                                "cve_description": "Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen value from get_text_props() to increment a uint16_t property count beyond 0xffff, wrapping the count to zero and copying existing text-property records into a heap allocation sized for none of them. This issue is fixed in version 9.2.0841.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 16:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73076",
                                "url": "https://ubuntu.com/security/CVE-2026-73076",
                                "cve_description": "Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through :!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 16:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73077",
                                "url": "https://ubuntu.com/security/CVE-2026-73077",
                                "cve_description": "Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating shell arguments. fnameescape() and PATH_ESC_CHARS do not neutralize shell metacharacters before ShKeywordPrg, ZshKeywordPrg, or GetHelp invokes bash, zsh, or PowerShell, allowing arbitrary operating-system commands to execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0839.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 16:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73078",
                                "url": "https://ubuntu.com/security/CVE-2026-73078",
                                "cve_description": "Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed :menu commands. s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), g:netrw_menu_escape, EX_TRLBAR, and netrw#MakeTgt() fail to neutralize the | command separator or single quotes at five construction sites, allowing a crafted path browsed or bookmarked in GUI Vim to execute arbitrary Ex and operating-system commands. This issue is fixed in version 9.2.0840.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 16:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY REGRESSION: Incomplete fix for CVE-2026-28417 (LP: #2163785)",
                            "    - debian/patches/CVE-2026-28417-pre1.patch: Add NetrwValidateHostname in",
                            "      runtime/autoload/netrw.vim",
                            "    - debian/patches/CVE-2026-28417.patch: Add fixes to NetrwValidateHostname",
                            "      in runtime/autoload/netrw.vim",
                            "  * SECURITY UPDATE: Use-after-free on json decode error.",
                            "    - debian/patches/CVE-2026-73071.patch: Report the position from the",
                            "      current reader in src/json.c.",
                            "    - CVE-2026-73071",
                            "  * SECURITY UPDATE: Heap buffer overflow in set_sofo().",
                            "    - debian/patches/CVE-2026-73072.patch: Reset sl_sal_first in",
                            "      src/spellfile.c.",
                            "    - CVE-2026-73072",
                            "  * SECURITY UPDATE: Heap overflow when adding > 65535 text properties.",
                            "    - debian/patches/CVE-2026-73074.patch: Verify that the number of text",
                            "      properties falls within the limit in src/errors.h and src/textprop.c.",
                            "    - CVE-2026-73074",
                            "  * SECURITY UPDATE: Code execution via VimballRecord file.",
                            "    - debian/patches/CVE-2026-73076.patch: Forbid arbitrary commands, fix",
                            "      broken directory deletion code, and refactor code in",
                            "      runtime/autoload/vimball.vim",
                            "    - CVE-2026-73076",
                            "  * SECURITY UPDATE: Arbitrary code execution via keyword lookup.",
                            "    - debian/patches/CVE-2026-73077.patch: For powershell, quote the commands",
                            "      using single quotes, for sh/zsh pass the argument as a separate list",
                            "      item to term_start()/system() in runtime/ftplugin/ps1.vim, ../sh.vim,",
                            "      and ../zsh.vim.",
                            "    - CVE-2026-73077",
                            "  * SECURITY UPDATE: Code injection in netrw via bookmarks.",
                            "    - debian/patches/CVE-2026-73078.patch: Escape the '|' explicitly in",
                            "      runtime/autoload/netrw.vim.",
                            "    - CVE-2026-73078",
                            ""
                        ],
                        "package": "vim",
                        "version": "2:9.1.0016-1ubuntu7.19",
                        "urgency": "medium",
                        "distributions": "noble-security",
                        "launchpad_bugs_fixed": [
                            2163785
                        ],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Tue, 18 Aug 2026 14:09:09 -0600"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "added": {
        "deb": [],
        "snap": []
    },
    "removed": {
        "deb": [],
        "snap": []
    },
    "notes": "Changelog diff for Ubuntu 24.04 noble image from daily image serial 20260818 to 20260822",
    "from_series": "noble",
    "to_series": "noble",
    "from_serial": "20260818",
    "to_serial": "20260822",
    "from_manifest_filename": "daily_manifest.previous",
    "to_manifest_filename": "manifest.current"
}