{
    "summary": {
        "snap": {
            "added": [],
            "removed": [],
            "diff": []
        },
        "deb": {
            "added": [
                "libntfs-3g90:s390x"
            ],
            "removed": [
                "libntfs-3g89t64:s390x"
            ],
            "diff": [
                "apparmor",
                "appstream",
                "cloud-init",
                "cloud-init-base",
                "distro-info",
                "distro-info-data",
                "dracut",
                "dracut-core",
                "dracut-install",
                "dracut-network",
                "findutils",
                "gnu-coreutils",
                "gzip",
                "kbd",
                "libapparmor1:s390x",
                "libappstream5:s390x",
                "libdrm-amdgpu1:s390x",
                "libdrm-common",
                "libdrm2:s390x",
                "libevdev2:s390x",
                "libexpat1:s390x",
                "libjson-c5:s390x",
                "liblmdb0:s390x",
                "liblz4-1:s390x",
                "libnss3:s390x",
                "libpam-modules:s390x",
                "libpam-modules-bin",
                "libpam-runtime",
                "libpam0g:s390x",
                "libplymouth5:s390x",
                "libpsl5t64:s390x",
                "libxmlb2:s390x",
                "login.defs",
                "ntfs-3g",
                "passwd",
                "pci.ids",
                "pinentry-curses",
                "plymouth",
                "plymouth-theme-ubuntu-text",
                "python3-bcrypt",
                "python3-distro-info",
                "python3-inflect",
                "python3-jwt",
                "python3-linkify-it",
                "python3-netaddr",
                "python3-pyasn1",
                "python3-rich",
                "python3-six",
                "python3-twisted",
                "python3-zope.interface",
                "tzdata",
                "ubuntu-pro-client",
                "ubuntu-pro-client-l10n",
                "ufw",
                "update-notifier-common",
                "xml-core"
            ]
        }
    },
    "diff": {
        "deb": [
            {
                "name": "apparmor",
                "from_version": {
                    "source_package_name": "apparmor",
                    "source_package_version": "5.0.1-0ubuntu1",
                    "version": "5.0.1-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "apparmor",
                    "source_package_version": "5.0.2-0ubuntu1",
                    "version": "5.0.2-0ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2152079
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Update patches to apply to new release:",
                            "    - d/p/u/profiles_disable_curl.patch",
                            "  * Add patch to fix transmission-gtk file chooser (LP: #2152079):",
                            "    - d/p/u/profiles-add-file-chooser-rules-to-abstractions-trans.patch",
                            ""
                        ],
                        "package": "apparmor",
                        "version": "5.0.2-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2152079
                        ],
                        "author": "Ryan Lee <ryan.lee@canonical.com>",
                        "date": "Mon, 13 Jul 2026 10:43:46 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "appstream",
                "from_version": {
                    "source_package_name": "appstream",
                    "source_package_version": "1.1.3-1",
                    "version": "1.1.3-1"
                },
                "to_version": {
                    "source_package_name": "appstream",
                    "source_package_version": "1.1.5-1",
                    "version": "1.1.5-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version: 1.1.5",
                            "    - Reintroduces bidirectional wildcard search for",
                            "      modaliases (Closes: #1084185)",
                            ""
                        ],
                        "package": "appstream",
                        "version": "1.1.5-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klumpp <mak@debian.org>",
                        "date": "Fri, 24 Jul 2026 20:34:44 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version: 1.1.4",
                            ""
                        ],
                        "package": "appstream",
                        "version": "1.1.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klumpp <mak@debian.org>",
                        "date": "Wed, 22 Jul 2026 18:48:38 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "cloud-init",
                "from_version": {
                    "source_package_name": "cloud-init",
                    "source_package_version": "26.2~3gbd85f29d-0ubuntu1",
                    "version": "26.2~3gbd85f29d-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "cloud-init",
                    "source_package_version": "26.2-0ubuntu1",
                    "version": "26.2-0ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upstream snapshot based on 26.2.",
                            "    List of changes from upstream can be found at",
                            "    https://raw.githubusercontent.com/canonical/cloud-init/26.2/ChangeLog",
                            ""
                        ],
                        "package": "cloud-init",
                        "version": "26.2-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Chad Smith <chad.smith@canonical.com>",
                        "date": "Tue, 28 Jul 2026 17:20:23 -0600"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "cloud-init-base",
                "from_version": {
                    "source_package_name": "cloud-init",
                    "source_package_version": "26.2~3gbd85f29d-0ubuntu1",
                    "version": "26.2~3gbd85f29d-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "cloud-init",
                    "source_package_version": "26.2-0ubuntu1",
                    "version": "26.2-0ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upstream snapshot based on 26.2.",
                            "    List of changes from upstream can be found at",
                            "    https://raw.githubusercontent.com/canonical/cloud-init/26.2/ChangeLog",
                            ""
                        ],
                        "package": "cloud-init",
                        "version": "26.2-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Chad Smith <chad.smith@canonical.com>",
                        "date": "Tue, 28 Jul 2026 17:20:23 -0600"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "distro-info",
                "from_version": {
                    "source_package_name": "distro-info",
                    "source_package_version": "1.15",
                    "version": "1.15"
                },
                "to_version": {
                    "source_package_name": "distro-info",
                    "source_package_version": "1.17",
                    "version": "1.17"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1012459
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * test: replace experimental by rc-buggy for distro-info-data 0.73",
                            ""
                        ],
                        "package": "distro-info",
                        "version": "1.17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Sun, 19 Jul 2026 16:17:03 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Format Python code with black 26.3",
                            "  * Perl library:",
                            "    - fix exporting convert_date",
                            "    - add get_all_series() function (Closes: #1141228, LP: #1012459)",
                            "  * Add autopkgtest for testing libdistro-info-perl",
                            "  * Bump Standards-Version to 4.7.4",
                            "  * Use pybuild-plugin-pyproject to build the Python module",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "distro-info",
                        "version": "1.16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            1012459
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Fri, 17 Jul 2026 00:35:41 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "distro-info-data",
                "from_version": {
                    "source_package_name": "distro-info-data",
                    "source_package_version": "0.73-1",
                    "version": "0.73-1"
                },
                "to_version": {
                    "source_package_name": "distro-info-data",
                    "source_package_version": "2026.07.30-1",
                    "version": "2026.07.30-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release:",
                            "    - Switch to calendar versioning (CalVer)",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "distro-info-data",
                        "version": "2026.07.30-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Thu, 30 Jul 2026 00:34:48 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dracut",
                "from_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "111-3",
                    "version": "111-3"
                },
                "to_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "111-6",
                    "version": "111-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2160087
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * dracut-core: depend on mount (e.g. needed by base module) (Closes: #1142204)",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "dracut",
                        "version": "111-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Fri, 17 Jul 2026 01:29:30 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * test(systemd): disable man page checks in verify test (LP: #2160087)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "111-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2160087
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Wed, 08 Jul 2026 12:18:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Miao Wang ]",
                            "  * test: use edk2 firmware for loong64 tests",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Add suggests/depends on new systemd-tpm package (since systemd 261-2)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "111-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Mon, 29 Jun 2026 13:01:36 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dracut-core",
                "from_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "111-3",
                    "version": "111-3"
                },
                "to_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "111-6",
                    "version": "111-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2160087
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * dracut-core: depend on mount (e.g. needed by base module) (Closes: #1142204)",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "dracut",
                        "version": "111-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Fri, 17 Jul 2026 01:29:30 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * test(systemd): disable man page checks in verify test (LP: #2160087)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "111-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2160087
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Wed, 08 Jul 2026 12:18:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Miao Wang ]",
                            "  * test: use edk2 firmware for loong64 tests",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Add suggests/depends on new systemd-tpm package (since systemd 261-2)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "111-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Mon, 29 Jun 2026 13:01:36 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dracut-install",
                "from_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "111-3",
                    "version": "111-3"
                },
                "to_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "111-6",
                    "version": "111-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2160087
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * dracut-core: depend on mount (e.g. needed by base module) (Closes: #1142204)",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "dracut",
                        "version": "111-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Fri, 17 Jul 2026 01:29:30 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * test(systemd): disable man page checks in verify test (LP: #2160087)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "111-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2160087
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Wed, 08 Jul 2026 12:18:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Miao Wang ]",
                            "  * test: use edk2 firmware for loong64 tests",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Add suggests/depends on new systemd-tpm package (since systemd 261-2)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "111-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Mon, 29 Jun 2026 13:01:36 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dracut-network",
                "from_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "111-3",
                    "version": "111-3"
                },
                "to_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "111-6",
                    "version": "111-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2160087
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * dracut-core: depend on mount (e.g. needed by base module) (Closes: #1142204)",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "dracut",
                        "version": "111-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Fri, 17 Jul 2026 01:29:30 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * test(systemd): disable man page checks in verify test (LP: #2160087)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "111-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2160087
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Wed, 08 Jul 2026 12:18:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Miao Wang ]",
                            "  * test: use edk2 firmware for loong64 tests",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Add suggests/depends on new systemd-tpm package (since systemd 261-2)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "111-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Mon, 29 Jun 2026 13:01:36 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "findutils",
                "from_version": {
                    "source_package_name": "findutils",
                    "source_package_version": "4.10.0-4",
                    "version": "4.10.0-4"
                },
                "to_version": {
                    "source_package_name": "findutils",
                    "source_package_version": "4.11.0-2",
                    "version": "4.11.0-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "findutils",
                        "version": "4.11.0-2",
                        "urgency": "low",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Sat, 25 Jul 2026 10:38:50 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            ""
                        ],
                        "package": "findutils",
                        "version": "4.11.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Sat, 11 Jul 2026 11:33:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream GIT snapshot 375275acad9efd2bee6cde9794dfdb5b049e2fe4.",
                            "    (Generated with make dist.)",
                            "    + Drop cherry-picked patch.",
                            "  * [lintian] update b-d  libselinux1-dev libselinux-dev",
                            "  * [lintian] Drop redundant Rules-Requires-Root: no",
                            "  * Bump copyright year for debian/",
                            "  * Drop superfluous cme override. (fix.scanned.copyright)",
                            "  * Add copyright.template to be used as basis for cme update dpkg-copyright.",
                            "  * Update fill.copyright.blanks.yml.",
                            "  * Run",
                            "    cp debian/copyright.template debian/copyright && cme update dpkg-copyright",
                            "  * Use v14 debhelper-compat mode.",
                            "  * Move debian/findutils.NEWS to debian/NEWS.  apt-listchanges does not",
                            "    handle differing NEWS entries in binary packages built from the same",
                            "    source well.",
                            "  * Add debian/NEWS entry.",
                            ""
                        ],
                        "package": "findutils",
                        "version": "4.10.0+git20260625-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Sat, 27 Jun 2026 14:23:50 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gnu-coreutils",
                "from_version": {
                    "source_package_name": "coreutils",
                    "source_package_version": "9.7-3ubuntu2",
                    "version": "9.7-3ubuntu2"
                },
                "to_version": {
                    "source_package_name": "coreutils",
                    "source_package_version": "9.10-1ubuntu1",
                    "version": "9.10-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153293
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable. Remaining changes:",
                            "    - Rename the binary package to gnu-coreutils and build with 'gnu' prefix",
                            "    - Run the autopkgtest against both Rust and GNU versions.",
                            "      Disable the failing nanosecond test case for stat for Rust, and",
                            "      re-enable it for the GNU version only.  Some specific care had to be",
                            "      taken around swapping the default provider: The coreutils-from-uutils",
                            "      are Protected: yes, so we need to remove them inside the test script.",
                            "    - d/rules:",
                            "     +  Allow cross-build and enable tests when not cross-building",
                            "    - d/p/72_id_checkngroups.patch: refreshed",
                            "    - debian/patches/80_fedora_sysinfo.dpatch",
                            "      + make 'uname -i -p' return the real processor/hardware, instead of",
                            "        unknown. Patch cherry-picked from Fedora 12 (original:",
                            "        coreutils-4.5.3-sysinfo.patch, from the coreutils-7.6-5.src.rpm).",
                            "    - debian/patches/99_float_endian_detection: Fix detection of floating",
                            "      point endianness.",
                            "    - d/p/treat-devtmpfs-and-squashfs-as-dummy-filesystems.patch:",
                            "      + Avoid displaying snaps in output from df and other tools, by excluding",
                            "        display of squashfs filesystems.",
                            "      + Exclude devtmpfs filesystems in output from df and other tools since",
                            "        it is a dummy filesystem.",
                            "      (refreshed)",
                            "    - d/p/cp-n.diff: skip tests/cp/cp-i.sh upstream test",
                            "      The behavior of cp -n is different in Debian than in upstream, and this",
                            "      test assumes upstream behavior of -n, and how it interacts with -i.",
                            "      (refreshed)",
                            "  * Dropped (upstreamed) changes:",
                            "    - d/p/lp2137373-skip-dirent-inode-sorting-for-lustre.patch:",
                            "      Fix slow performance of 'du' on large directories (>= 10K files) on",
                            "      Lustre filesystems by skipping inode sorting. The default behaviour of",
                            "      sorting dirents by inode numbers negatively impacts performance on",
                            "      Lustre because it interferes with Lustre's ability to prefetch file",
                            "      metadata via statahead. (LP: 2137373)",
                            "  * Rename two debian/coreutils -> debian/gnu-coreutils forgotten files",
                            "  * (Closes LP: #2153293)",
                            ""
                        ],
                        "package": "coreutils",
                        "version": "9.10-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153293
                        ],
                        "author": "Pierre-Elliott Bécue <peb@debian.org>",
                        "date": "Mon, 20 Jul 2026 23:29:40 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            "    - cksum now supports sha3",
                            "  * update to policy 4.7.3 (minor changes)",
                            ""
                        ],
                        "package": "coreutils",
                        "version": "9.10-1",
                        "urgency": "low",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Stone <mstone@debian.org>",
                        "date": "Thu, 26 Feb 2026 16:59:53 -0500"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gzip",
                "from_version": {
                    "source_package_name": "gzip",
                    "source_package_version": "1.14-1~exp2ubuntu2",
                    "version": "1.14-1~exp2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "gzip",
                    "source_package_version": "1.14-1~exp2ubuntu3",
                    "version": "1.14-1~exp2ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-41991",
                        "url": "https://ubuntu.com/security/CVE-2026-41991",
                        "cve_description": "GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.  This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-29 12:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-41992",
                        "url": "https://ubuntu.com/security/CVE-2026-41992",
                        "cve_description": "GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.  This issue has been fixed in the commit 63dbf6b3b9e6e781df1a6a64e609b10e23969681",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-29 12:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-41991",
                                "url": "https://ubuntu.com/security/CVE-2026-41991",
                                "cve_description": "GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.  This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-29 12:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-41992",
                                "url": "https://ubuntu.com/security/CVE-2026-41992",
                                "cve_description": "GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.  This issue has been fixed in the commit 63dbf6b3b9e6e781df1a6a64e609b10e23969681",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-29 12:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: insecure temp file handling",
                            "    - debian/patches/CVE-2026-41991.patch: gzexe: use -C if lacking mktemp in",
                            "      gzexe.in, zdiff.in.",
                            "    - CVE-2026-41991",
                            "  * SECURITY UPDATE: overflow in LZH decompression logic",
                            "    - debian/patches/CVE-2026-41992.patch: gzip: don’t mishandle .lzh after .Z",
                            "      in unlzh.c.",
                            "    - CVE-2026-41992",
                            ""
                        ],
                        "package": "gzip",
                        "version": "1.14-1~exp2ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Fri, 03 Jul 2026 07:50:04 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "kbd",
                "from_version": {
                    "source_package_name": "kbd",
                    "source_package_version": "2.7.1-2ubuntu2",
                    "version": "2.7.1-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "kbd",
                    "source_package_version": "2.9.0-1ubuntu1",
                    "version": "2.9.0-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153310
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153310). Remaining changes:",
                            "    - Add setfont, kbd_mode, and loadkeys to initramfs for console-setup.",
                            "    - Change loadkeys to find any console not in raw mode when invoked",
                            "      without an explicit console parameter, in case the foreground console",
                            "      is in raw mode.",
                            "    - Use ckbcomp to get the keyboard layout if other data files are not",
                            "      available.",
                            "    - debian/control: Depend on console-setup | console-setup-mini, since",
                            "      console-setup-mini also Depends on kbd now through console-setup-linux.",
                            "  * Dropped changes:",
                            "    - Add setvtrgb to kbd-udeb. Ubuntu does not build udebs any more.",
                            ""
                        ],
                        "package": "kbd",
                        "version": "2.9.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153310
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Wed, 15 Jul 2026 13:02:07 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "",
                            "  [ Andreas Henriksson ]",
                            "  * New upstream release.",
                            "  * Drop debian/patches/ppc-keycode0-test.patch, fixed upstream.",
                            "  * Drop debian/patches/Support-KT_DEAD2-diacritics.patch, fixed upstream.",
                            "",
                            "  [ Michael Biebl ]",
                            "  * kbd-udeb: Move binaries to canonical location in /usr. (Closes: #1122352)",
                            ""
                        ],
                        "package": "kbd",
                        "version": "2.9.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Henriksson <andreas@fatal.se>",
                        "date": "Sun, 14 Dec 2025 10:38:41 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libapparmor1:s390x",
                "from_version": {
                    "source_package_name": "apparmor",
                    "source_package_version": "5.0.1-0ubuntu1",
                    "version": "5.0.1-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "apparmor",
                    "source_package_version": "5.0.2-0ubuntu1",
                    "version": "5.0.2-0ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2152079
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Update patches to apply to new release:",
                            "    - d/p/u/profiles_disable_curl.patch",
                            "  * Add patch to fix transmission-gtk file chooser (LP: #2152079):",
                            "    - d/p/u/profiles-add-file-chooser-rules-to-abstractions-trans.patch",
                            ""
                        ],
                        "package": "apparmor",
                        "version": "5.0.2-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2152079
                        ],
                        "author": "Ryan Lee <ryan.lee@canonical.com>",
                        "date": "Mon, 13 Jul 2026 10:43:46 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libappstream5:s390x",
                "from_version": {
                    "source_package_name": "appstream",
                    "source_package_version": "1.1.3-1",
                    "version": "1.1.3-1"
                },
                "to_version": {
                    "source_package_name": "appstream",
                    "source_package_version": "1.1.5-1",
                    "version": "1.1.5-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version: 1.1.5",
                            "    - Reintroduces bidirectional wildcard search for",
                            "      modaliases (Closes: #1084185)",
                            ""
                        ],
                        "package": "appstream",
                        "version": "1.1.5-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klumpp <mak@debian.org>",
                        "date": "Fri, 24 Jul 2026 20:34:44 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version: 1.1.4",
                            ""
                        ],
                        "package": "appstream",
                        "version": "1.1.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klumpp <mak@debian.org>",
                        "date": "Wed, 22 Jul 2026 18:48:38 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libdrm-amdgpu1:s390x",
                "from_version": {
                    "source_package_name": "libdrm",
                    "source_package_version": "2.4.134-1",
                    "version": "2.4.134-1"
                },
                "to_version": {
                    "source_package_name": "libdrm",
                    "source_package_version": "2.4.134-3",
                    "version": "2.4.134-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Enable freedreno on i386 too",
                            ""
                        ],
                        "package": "libdrm",
                        "version": "2.4.134-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <tjaalton@debian.org>",
                        "date": "Mon, 29 Jun 2026 12:24:58 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Enable freedreno on amd64",
                            ""
                        ],
                        "package": "libdrm",
                        "version": "2.4.134-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <tjaalton@debian.org>",
                        "date": "Wed, 24 Jun 2026 12:10:20 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libdrm-common",
                "from_version": {
                    "source_package_name": "libdrm",
                    "source_package_version": "2.4.134-1",
                    "version": "2.4.134-1"
                },
                "to_version": {
                    "source_package_name": "libdrm",
                    "source_package_version": "2.4.134-3",
                    "version": "2.4.134-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Enable freedreno on i386 too",
                            ""
                        ],
                        "package": "libdrm",
                        "version": "2.4.134-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <tjaalton@debian.org>",
                        "date": "Mon, 29 Jun 2026 12:24:58 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Enable freedreno on amd64",
                            ""
                        ],
                        "package": "libdrm",
                        "version": "2.4.134-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <tjaalton@debian.org>",
                        "date": "Wed, 24 Jun 2026 12:10:20 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libdrm2:s390x",
                "from_version": {
                    "source_package_name": "libdrm",
                    "source_package_version": "2.4.134-1",
                    "version": "2.4.134-1"
                },
                "to_version": {
                    "source_package_name": "libdrm",
                    "source_package_version": "2.4.134-3",
                    "version": "2.4.134-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Enable freedreno on i386 too",
                            ""
                        ],
                        "package": "libdrm",
                        "version": "2.4.134-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <tjaalton@debian.org>",
                        "date": "Mon, 29 Jun 2026 12:24:58 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Enable freedreno on amd64",
                            ""
                        ],
                        "package": "libdrm",
                        "version": "2.4.134-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <tjaalton@debian.org>",
                        "date": "Wed, 24 Jun 2026 12:10:20 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libevdev2:s390x",
                "from_version": {
                    "source_package_name": "libevdev",
                    "source_package_version": "1.13.6+dfsg-2",
                    "version": "1.13.6+dfsg-2"
                },
                "to_version": {
                    "source_package_name": "libevdev",
                    "source_package_version": "1.13.6+dfsg-3",
                    "version": "1.13.6+dfsg-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Switch to stable debhelper compatibility level 14.",
                            ""
                        ],
                        "package": "libevdev",
                        "version": "1.13.6+dfsg-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stephen Kitt <skitt@debian.org>",
                        "date": "Sat, 04 Jul 2026 11:12:28 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libexpat1:s390x",
                "from_version": {
                    "source_package_name": "expat",
                    "source_package_version": "2.8.1-1",
                    "version": "2.8.1-1"
                },
                "to_version": {
                    "source_package_name": "expat",
                    "source_package_version": "2.8.2-1",
                    "version": "2.8.2-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-56131",
                        "url": "https://ubuntu.com/security/CVE-2026-56131",
                        "cve_description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-19 06:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56132",
                        "url": "https://ubuntu.com/security/CVE-2026-56132",
                        "cve_description": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-19 06:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-50219",
                        "url": "https://ubuntu.com/security/CVE-2026-50219",
                        "cve_description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-04 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56403",
                        "url": "https://ubuntu.com/security/CVE-2026-56403",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56404",
                        "url": "https://ubuntu.com/security/CVE-2026-56404",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in addBinding.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56405",
                        "url": "https://ubuntu.com/security/CVE-2026-56405",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56406",
                        "url": "https://ubuntu.com/security/CVE-2026-56406",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56407",
                        "url": "https://ubuntu.com/security/CVE-2026-56407",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56408",
                        "url": "https://ubuntu.com/security/CVE-2026-56408",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in copyString.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56409",
                        "url": "https://ubuntu.com/security/CVE-2026-56409",
                        "cve_description": "xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56410",
                        "url": "https://ubuntu.com/security/CVE-2026-56410",
                        "cve_description": "xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56411",
                        "url": "https://ubuntu.com/security/CVE-2026-56411",
                        "cve_description": "xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 17:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56412",
                        "url": "https://ubuntu.com/security/CVE-2026-56412",
                        "cve_description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 17:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-56131",
                                "url": "https://ubuntu.com/security/CVE-2026-56131",
                                "cve_description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-19 06:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56132",
                                "url": "https://ubuntu.com/security/CVE-2026-56132",
                                "cve_description": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-19 06:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-50219",
                                "url": "https://ubuntu.com/security/CVE-2026-50219",
                                "cve_description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-04 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56403",
                                "url": "https://ubuntu.com/security/CVE-2026-56403",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56404",
                                "url": "https://ubuntu.com/security/CVE-2026-56404",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in addBinding.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56405",
                                "url": "https://ubuntu.com/security/CVE-2026-56405",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56406",
                                "url": "https://ubuntu.com/security/CVE-2026-56406",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56407",
                                "url": "https://ubuntu.com/security/CVE-2026-56407",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56408",
                                "url": "https://ubuntu.com/security/CVE-2026-56408",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in copyString.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56409",
                                "url": "https://ubuntu.com/security/CVE-2026-56409",
                                "cve_description": "xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56410",
                                "url": "https://ubuntu.com/security/CVE-2026-56410",
                                "cve_description": "xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56411",
                                "url": "https://ubuntu.com/security/CVE-2026-56411",
                                "cve_description": "xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 17:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56412",
                                "url": "https://ubuntu.com/security/CVE-2026-56412",
                                "cve_description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 17:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1138862, #1140387, #1140388, #1140557):",
                            "    - fixes CVE-2026-56131: protect XML_ResumeParser() from being called from",
                            "      a handler,",
                            "    - fixes CVE-2026-56132: fix out-of-bound scaffolding index store in",
                            "      doProlog(),",
                            "    - fixes CVE-2026-50219: disallow calls to some functions to guard Expat",
                            "      bindings from memory corruption,",
                            "    - fixes CVE-2026-56403: integer overflow in storeAtts(),",
                            "    - fixes CVE-2026-56404: integer overflow in addBinding(),",
                            "    - fixes CVE-2026-56405: integer overflow in getAttributeId(),",
                            "    - fixes CVE-2026-56406: integer overflow in XML_ParseBuffer(),",
                            "    - fixes CVE-2026-56407: integer overflow in textLen handling,",
                            "    - fixes CVE-2026-56408: integer overflow in copyString(),",
                            "    - fixes CVE-2026-56409: integer overflow in output path join in xmlwf,",
                            "    - fixes CVE-2026-56410: integer overflow in resolveSystemId() in xmlwf,",
                            "    - fixes CVE-2026-56411: Integer overflow in notation list allocation",
                            "      in xmlwf,",
                            "    - fixes CVE-2026-56412: guard XML_TOK_DATA_CHARS handler calls",
                            "      in doCdataSection().",
                            ""
                        ],
                        "package": "expat",
                        "version": "2.8.2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Thu, 25 Jun 2026 19:44:46 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libjson-c5:s390x",
                "from_version": {
                    "source_package_name": "json-c",
                    "source_package_version": "0.18+ds-3",
                    "version": "0.18+ds-3"
                },
                "to_version": {
                    "source_package_name": "json-c",
                    "source_package_version": "0.19+ds-1",
                    "version": "0.19+ds-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            "  * d/control: Update standards version to 4.7.4",
                            "  * d/control: Add xdd in build-deps",
                            "  * d/symbols: update symbols file",
                            ""
                        ],
                        "package": "json-c",
                        "version": "0.19+ds-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Nicolas Mora <babelouest@debian.org>",
                        "date": "Sun, 28 Jun 2026 12:08:28 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "liblmdb0:s390x",
                "from_version": {
                    "source_package_name": "lmdb",
                    "source_package_version": "0.9.31-1build2",
                    "version": "0.9.31-1build2"
                },
                "to_version": {
                    "source_package_name": "lmdb",
                    "source_package_version": "0.9.35-1",
                    "version": "0.9.35-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2132257
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change mass rebuild for Ubuntu 26.04 (LP: #2132257)",
                            ""
                        ],
                        "package": "lmdb",
                        "version": "0.9.31-1build2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2132257
                        ],
                        "author": "Sebastien Bacher <seb128@ubuntu.com>",
                        "date": "Mon, 01 Dec 2025 13:54:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No change rebuild for 64-bit time_t and frame pointers.",
                            ""
                        ],
                        "package": "lmdb",
                        "version": "0.9.31-1build1",
                        "urgency": "high",
                        "distributions": "noble",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Mon, 08 Apr 2024 18:11:23 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "liblz4-1:s390x",
                "from_version": {
                    "source_package_name": "lz4",
                    "source_package_version": "1.10.0-8",
                    "version": "1.10.0-8"
                },
                "to_version": {
                    "source_package_name": "lz4",
                    "source_package_version": "1.10.0-10",
                    "version": "1.10.0-10"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/tests: disable versionsTest.",
                            ""
                        ],
                        "package": "lz4",
                        "version": "1.10.0-10",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Nobuhiro Iwamatsu <iwamatsu@debian.org>",
                        "date": "Tue, 21 Apr 2026 11:35:15 +0900"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/patches",
                            "    - Add tests-test-lz4-abi.py-Drop-m32-and-m64-option-for-te.patch.",
                            "    - Add tests-test-lz4-versions.py-Drop-the-building-of-32-b.patch.",
                            "    - Add fix-test-lz4-list.py.patch.",
                            "  * d/source/local-options: Add extend-diff-ignore",
                            ""
                        ],
                        "package": "lz4",
                        "version": "1.10.0-9",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Nobuhiro Iwamatsu <iwamatsu@debian.org>",
                        "date": "Fri, 10 Apr 2026 13:34:42 +0900"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libnss3:s390x",
                "from_version": {
                    "source_package_name": "nss",
                    "source_package_version": "2:3.124-1",
                    "version": "2:3.124-1"
                },
                "to_version": {
                    "source_package_name": "nss",
                    "source_package_version": "2:3.126-1",
                    "version": "2:3.126-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16389",
                        "url": "https://ubuntu.com/security/CVE-2026-16389",
                        "cve_description": "Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-21 13:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16389",
                                "url": "https://ubuntu.com/security/CVE-2026-16389",
                                "cve_description": "Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-21 13:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "    - Fixes CVE-2026-16389.",
                            "  * debian/libnss3.symbols: Add NSS_3.126 symbol version.",
                            ""
                        ],
                        "package": "nss",
                        "version": "2:3.126-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mike Hommey <glandium@debian.org>",
                        "date": "Wed, 22 Jul 2026 07:30:13 +0900"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpam-modules:s390x",
                "from_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu3",
                    "version": "1.7.0-5ubuntu3"
                },
                "to_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu4",
                    "version": "1.7.0-5ubuntu4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-54411",
                        "url": "https://ubuntu.com/security/CVE-2026-54411",
                        "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-14 18:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-54411",
                                "url": "https://ubuntu.com/security/CVE-2026-54411",
                                "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-14 18:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: password recovery via timing discrepancy in pam_userdb",
                            "    module string comparisons",
                            "    - debian/patches/CVE-2026-54411.patch: pam_userdb: fix password comparison",
                            "      timing leak in libpam/include/pam_inline.h,",
                            "      modules/pam_userdb/pam_userdb.c.",
                            "    - CVE-2026-54411",
                            ""
                        ],
                        "package": "pam",
                        "version": "1.7.0-5ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Thu, 16 Jul 2026 09:34:12 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpam-modules-bin",
                "from_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu3",
                    "version": "1.7.0-5ubuntu3"
                },
                "to_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu4",
                    "version": "1.7.0-5ubuntu4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-54411",
                        "url": "https://ubuntu.com/security/CVE-2026-54411",
                        "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-14 18:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-54411",
                                "url": "https://ubuntu.com/security/CVE-2026-54411",
                                "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-14 18:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: password recovery via timing discrepancy in pam_userdb",
                            "    module string comparisons",
                            "    - debian/patches/CVE-2026-54411.patch: pam_userdb: fix password comparison",
                            "      timing leak in libpam/include/pam_inline.h,",
                            "      modules/pam_userdb/pam_userdb.c.",
                            "    - CVE-2026-54411",
                            ""
                        ],
                        "package": "pam",
                        "version": "1.7.0-5ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Thu, 16 Jul 2026 09:34:12 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpam-runtime",
                "from_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu3",
                    "version": "1.7.0-5ubuntu3"
                },
                "to_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu4",
                    "version": "1.7.0-5ubuntu4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-54411",
                        "url": "https://ubuntu.com/security/CVE-2026-54411",
                        "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-14 18:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-54411",
                                "url": "https://ubuntu.com/security/CVE-2026-54411",
                                "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-14 18:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: password recovery via timing discrepancy in pam_userdb",
                            "    module string comparisons",
                            "    - debian/patches/CVE-2026-54411.patch: pam_userdb: fix password comparison",
                            "      timing leak in libpam/include/pam_inline.h,",
                            "      modules/pam_userdb/pam_userdb.c.",
                            "    - CVE-2026-54411",
                            ""
                        ],
                        "package": "pam",
                        "version": "1.7.0-5ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Thu, 16 Jul 2026 09:34:12 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpam0g:s390x",
                "from_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu3",
                    "version": "1.7.0-5ubuntu3"
                },
                "to_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu4",
                    "version": "1.7.0-5ubuntu4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-54411",
                        "url": "https://ubuntu.com/security/CVE-2026-54411",
                        "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-14 18:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-54411",
                                "url": "https://ubuntu.com/security/CVE-2026-54411",
                                "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-14 18:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: password recovery via timing discrepancy in pam_userdb",
                            "    module string comparisons",
                            "    - debian/patches/CVE-2026-54411.patch: pam_userdb: fix password comparison",
                            "      timing leak in libpam/include/pam_inline.h,",
                            "      modules/pam_userdb/pam_userdb.c.",
                            "    - CVE-2026-54411",
                            ""
                        ],
                        "package": "pam",
                        "version": "1.7.0-5ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Thu, 16 Jul 2026 09:34:12 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libplymouth5:s390x",
                "from_version": {
                    "source_package_name": "plymouth",
                    "source_package_version": "24.004.60+git20250831.4a3c171d-0ubuntu8",
                    "version": "24.004.60+git20250831.4a3c171d-0ubuntu8"
                },
                "to_version": {
                    "source_package_name": "plymouth",
                    "source_package_version": "24.004.60+git20250831.4a3c171d-0ubuntu9",
                    "version": "24.004.60+git20250831.4a3c171d-0ubuntu9"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2144770
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2144770-Fix-reload-when-happening-early.patch:",
                            "    - Fix reload when happening early (LP: #2144770)",
                            ""
                        ],
                        "package": "plymouth",
                        "version": "24.004.60+git20250831.4a3c171d-0ubuntu9",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2144770
                        ],
                        "author": "Dariusz Gadomski <dgadomski@ubuntu.com>",
                        "date": "Fri, 10 Apr 2026 13:34:55 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpsl5t64:s390x",
                "from_version": {
                    "source_package_name": "libpsl",
                    "source_package_version": "0.22.0-1",
                    "version": "0.22.0-1"
                },
                "to_version": {
                    "source_package_name": "libpsl",
                    "source_package_version": "0.23.0-1",
                    "version": "0.23.0-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-8924",
                        "url": "https://ubuntu.com/security/CVE-2026-8924",
                        "cve_description": "A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-07-03 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-8924",
                                "url": "https://ubuntu.com/security/CVE-2026-8924",
                                "cve_description": "A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-07-03 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream version 0.23.0",
                            "    - Properly handle leading dot in domains (see also CVE-2026-8924)",
                            "  * d/patches/0003-rename-cdata-in-docs-as-well.patch: fix doc build",
                            ""
                        ],
                        "package": "libpsl",
                        "version": "0.23.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Florian Ernst <florian@debian.org>",
                        "date": "Mon, 13 Jul 2026 15:58:07 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libxmlb2:s390x",
                "from_version": {
                    "source_package_name": "libxmlb",
                    "source_package_version": "0.3.24-2",
                    "version": "0.3.24-2"
                },
                "to_version": {
                    "source_package_name": "libxmlb",
                    "source_package_version": "0.3.29-1",
                    "version": "0.3.29-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            ""
                        ],
                        "package": "libxmlb",
                        "version": "0.3.29-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mario Limonciello <superm1@debian.org>",
                        "date": "Tue, 28 Jul 2026 00:02:36 -0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            ""
                        ],
                        "package": "libxmlb",
                        "version": "0.3.28-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mario Limonciello <superm1@debian.org>",
                        "date": "Tue, 30 Jun 2026 08:15:02 -0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            "  * d/control: Add libzstd-dev to libxmlb-dev Depends (Closes: #1140908)",
                            ""
                        ],
                        "package": "libxmlb",
                        "version": "0.3.27-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mario Limonciello <superm1@debian.org>",
                        "date": "Sun, 28 Jun 2026 12:29:07 -0500"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "login.defs",
                "from_version": {
                    "source_package_name": "shadow",
                    "source_package_version": "1:4.17.4-2ubuntu3",
                    "version": "1:4.17.4-2ubuntu3"
                },
                "to_version": {
                    "source_package_name": "shadow",
                    "source_package_version": "1:4.19.3-2ubuntu1",
                    "version": "1:4.19.3-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153355
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153355). Remaining changes:",
                            "    - d/p/: Enable private home directories by default",
                            "    - debian/{source_shadow.py,login.defs.install}: Add apport hook",
                            "    - d/p/1010_extrausers.patch: add libnss-extrausers support to passwd/usermod",
                            "    - d/p/1011_extrausers_toggle.patch: extrausers support for useradd/groupadd",
                            "    - d/p/1012_extrausers_chfn.patch: --extrausers support for chfn tool",
                            "    - d/p/1013_extrausers_deluser.patch: --extrausers support for userdel",
                            "    - d/p/1014_extrausers_delgroup.patch: --extrausers support for groupdel",
                            "    - d/p/1016_extrausers_gpasswd.patch: extrausers support for gpasswd",
                            "    - d/t/{control,numeric-username}: test that fully numeric names are rejected",
                            "    - d/t/smoke: Extend for extrausers support",
                            "    - Add some cursory tests for the extrausers features",
                            "    - d/p/lp2063200: fix useradd group validation with extrausers (LP 2063200)",
                            "    - d/p/: disallow pure numeric user and group names (LP 2076898)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.3-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153355
                        ],
                        "author": "Nadzeya Hutsko <nadzeya.hutsko@canonical.com>",
                        "date": "Mon, 01 Jun 2026 15:59:52 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix getsubids parsing of /etc/subgid.",
                            "    Thanks to Aurelien Jarno (Closes: #1132509)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 02 Apr 2026 19:44:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.19.3",
                            "  * Update Upstream signing keys",
                            "  * d/watch: enable pgpmode=auto",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Mon, 23 Feb 2026 09:54:37 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.19.2",
                            "  * Refresh patches, drop upstream-applied chkhask patches",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Sun, 25 Jan 2026 14:18:54 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import upstream patches to fix hash check (Closes: #1124835)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 08 Jan 2026 00:01:00 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * chpasswd: Disable broken hash check, bug #1124835",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Wed, 07 Jan 2026 11:11:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Disable logind integration on !linux",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Tue, 06 Jan 2026 02:38:50 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.19.0",
                            "  * Refresh patches",
                            "  * Drop upstream-applied patches",
                            "  * Add new build-dependency on libsystemd-dev [linux-any]",
                            "  * login.defs: Remove commented out USERDEL_CMD",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Tue, 06 Jan 2026 01:16:37 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Frans Spiesschaert ]",
                            "  * Update Dutch translations (Closes: #1115411)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.18.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Wed, 17 Sep 2025 00:46:09 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.18.0",
                            "  * Refresh patches",
                            "  * d/copyright: update for upstream-deleted code",
                            "  * Drop newly unnecessay Build-Depends: bison",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.18.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Tue, 26 Aug 2025 23:05:38 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ntfs-3g",
                "from_version": {
                    "source_package_name": "ntfs-3g",
                    "source_package_version": "1:2026.2.25-1",
                    "version": "1:2026.2.25-1"
                },
                "to_version": {
                    "source_package_name": "ntfs-3g",
                    "source_package_version": "1:2026.7.7-2",
                    "version": "1:2026.7.7-2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-42616",
                        "url": "https://ubuntu.com/security/CVE-2026-42616",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in cat() in  cat.c that allows an attacker to corrupt heap memory in the ntfscat  binary by crafting a malicious NTFS image. The overflow is triggered by  reading a file.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42617",
                        "url": "https://ubuntu.com/security/CVE-2026-42617",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap  memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS  image. The overflow is triggered by extending a directory, e.g., by  creating a file.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42618",
                        "url": "https://ubuntu.com/security/CVE-2026-42618",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_decompress() in compress.c that allows an attacker to corrupt one  byte of heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by reading the special  crafted file.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-46569",
                        "url": "https://ubuntu.com/security/CVE-2026-46569",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to  corrupt heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by extending a  directory, e.g., by creating a file.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-46570",
                        "url": "https://ubuntu.com/security/CVE-2026-46570",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to  corrupt heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by reading crafted file  metadata.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-46571",
                        "url": "https://ubuntu.com/security/CVE-2026-46571",
                        "cve_description": "In NTFS-3G through 2026.2.25, a out-of-bounds read exists in  ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to  read possibly confidential information in ntfs-3g process memory by  crafting a malicious NTFS image. The out-of-bounds read is triggered by  a readlink on a corrupted file.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-46572",
                        "url": "https://ubuntu.com/security/CVE-2026-46572",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to  corrupt heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by creating a file in a  crafted directory.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56135",
                        "url": "https://ubuntu.com/security/CVE-2026-56135",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the  function build_inherited_id() in libntfs-3g/security.c that allows an  attacker to corrupt heap memory in the SUID-root ntfs-3g binary by  crafting a malicious NTFS image. The overflow is triggered by creating a  file in a crafted directory.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56136",
                        "url": "https://ubuntu.com/security/CVE-2026-56136",
                        "cve_description": "In NTFS-3G through 2026.2.25, an out-of-bounds read exists in  ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read  possibly confidential information in an ntfs-3g process by crafting a  malicious NTFS image. This read operation is triggered by creation of a  file with a crafted name.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to Sid.",
                            "  * Update copyright file.",
                            ""
                        ],
                        "package": "ntfs-3g",
                        "version": "1:2026.7.7-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sun, 19 Jul 2026 13:36:46 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-42616",
                                "url": "https://ubuntu.com/security/CVE-2026-42616",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in cat() in  cat.c that allows an attacker to corrupt heap memory in the ntfscat  binary by crafting a malicious NTFS image. The overflow is triggered by  reading a file.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42617",
                                "url": "https://ubuntu.com/security/CVE-2026-42617",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap  memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS  image. The overflow is triggered by extending a directory, e.g., by  creating a file.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42618",
                                "url": "https://ubuntu.com/security/CVE-2026-42618",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_decompress() in compress.c that allows an attacker to corrupt one  byte of heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by reading the special  crafted file.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-46569",
                                "url": "https://ubuntu.com/security/CVE-2026-46569",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to  corrupt heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by extending a  directory, e.g., by creating a file.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-46570",
                                "url": "https://ubuntu.com/security/CVE-2026-46570",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to  corrupt heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by reading crafted file  metadata.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-46571",
                                "url": "https://ubuntu.com/security/CVE-2026-46571",
                                "cve_description": "In NTFS-3G through 2026.2.25, a out-of-bounds read exists in  ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to  read possibly confidential information in ntfs-3g process memory by  crafting a malicious NTFS image. The out-of-bounds read is triggered by  a readlink on a corrupted file.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-46572",
                                "url": "https://ubuntu.com/security/CVE-2026-46572",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to  corrupt heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by creating a file in a  crafted directory.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56135",
                                "url": "https://ubuntu.com/security/CVE-2026-56135",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the  function build_inherited_id() in libntfs-3g/security.c that allows an  attacker to corrupt heap memory in the SUID-root ntfs-3g binary by  crafting a malicious NTFS image. The overflow is triggered by creating a  file in a crafted directory.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56136",
                                "url": "https://ubuntu.com/security/CVE-2026-56136",
                                "cve_description": "In NTFS-3G through 2026.2.25, an out-of-bounds read exists in  ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read  possibly confidential information in an ntfs-3g process by crafting a  malicious NTFS image. This read operation is triggered by creation of a  file with a crafted name.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1142144):",
                            "    - fixes CVE-2026-42616: heap buffer overflow in cat(),",
                            "    - fixes CVE-2026-42617: heap buffer overflow in ntfs_ir_to_ib(),",
                            "    - fixes CVE-2026-42618: heap buffer overflow in ntfs_decompress(),",
                            "    - fixes CVE-2026-46569: missing range check in ntfs_ib_copy_tail(),",
                            "    - fixes CVE-2026-46570: heap memory corruption in ntfs_index_walk_down(),",
                            "    - fixes CVE-2026-46571: out of bounds read in ntfs_fix_file_name(),",
                            "    - fixes CVE-2026-46572: heap buffer overflow in ntfs_ib_cut_tail(),",
                            "    - fixes CVE-2026-56135: heap buffer overflow in build_inherited_id(),",
                            "    - fixes CVE-2026-56136: out of bounds memmove in ntfs_ir_nill().",
                            "  * Update copyright file.",
                            "  * Update Standards-Version to 4.7.2 .",
                            "  * Library transition from libntfs-3g89 to libntfs-3g90 .",
                            ""
                        ],
                        "package": "ntfs-3g",
                        "version": "1:2026.7.7-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Wed, 15 Jul 2026 22:16:05 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "passwd",
                "from_version": {
                    "source_package_name": "shadow",
                    "source_package_version": "1:4.17.4-2ubuntu3",
                    "version": "1:4.17.4-2ubuntu3"
                },
                "to_version": {
                    "source_package_name": "shadow",
                    "source_package_version": "1:4.19.3-2ubuntu1",
                    "version": "1:4.19.3-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153355
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153355). Remaining changes:",
                            "    - d/p/: Enable private home directories by default",
                            "    - debian/{source_shadow.py,login.defs.install}: Add apport hook",
                            "    - d/p/1010_extrausers.patch: add libnss-extrausers support to passwd/usermod",
                            "    - d/p/1011_extrausers_toggle.patch: extrausers support for useradd/groupadd",
                            "    - d/p/1012_extrausers_chfn.patch: --extrausers support for chfn tool",
                            "    - d/p/1013_extrausers_deluser.patch: --extrausers support for userdel",
                            "    - d/p/1014_extrausers_delgroup.patch: --extrausers support for groupdel",
                            "    - d/p/1016_extrausers_gpasswd.patch: extrausers support for gpasswd",
                            "    - d/t/{control,numeric-username}: test that fully numeric names are rejected",
                            "    - d/t/smoke: Extend for extrausers support",
                            "    - Add some cursory tests for the extrausers features",
                            "    - d/p/lp2063200: fix useradd group validation with extrausers (LP 2063200)",
                            "    - d/p/: disallow pure numeric user and group names (LP 2076898)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.3-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153355
                        ],
                        "author": "Nadzeya Hutsko <nadzeya.hutsko@canonical.com>",
                        "date": "Mon, 01 Jun 2026 15:59:52 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix getsubids parsing of /etc/subgid.",
                            "    Thanks to Aurelien Jarno (Closes: #1132509)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 02 Apr 2026 19:44:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.19.3",
                            "  * Update Upstream signing keys",
                            "  * d/watch: enable pgpmode=auto",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Mon, 23 Feb 2026 09:54:37 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.19.2",
                            "  * Refresh patches, drop upstream-applied chkhask patches",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Sun, 25 Jan 2026 14:18:54 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import upstream patches to fix hash check (Closes: #1124835)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 08 Jan 2026 00:01:00 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * chpasswd: Disable broken hash check, bug #1124835",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Wed, 07 Jan 2026 11:11:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Disable logind integration on !linux",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Tue, 06 Jan 2026 02:38:50 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.19.0",
                            "  * Refresh patches",
                            "  * Drop upstream-applied patches",
                            "  * Add new build-dependency on libsystemd-dev [linux-any]",
                            "  * login.defs: Remove commented out USERDEL_CMD",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Tue, 06 Jan 2026 01:16:37 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Frans Spiesschaert ]",
                            "  * Update Dutch translations (Closes: #1115411)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.18.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Wed, 17 Sep 2025 00:46:09 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.18.0",
                            "  * Refresh patches",
                            "  * d/copyright: update for upstream-deleted code",
                            "  * Drop newly unnecessay Build-Depends: bison",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.18.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Tue, 26 Aug 2025 23:05:38 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "pci.ids",
                "from_version": {
                    "source_package_name": "pci.ids",
                    "source_package_version": "0.0~2026.06.16-1",
                    "version": "0.0~2026.06.16-1"
                },
                "to_version": {
                    "source_package_name": "pci.ids",
                    "source_package_version": "0.0~2026.07.21-1",
                    "version": "0.0~2026.07.21-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "pci.ids",
                        "version": "0.0~2026.07.21-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guillem Jover <guillem@debian.org>",
                        "date": "Sun, 26 Jul 2026 03:55:02 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "pci.ids",
                        "version": "0.0~2026.07.06-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guillem Jover <guillem@debian.org>",
                        "date": "Mon, 06 Jul 2026 23:43:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "pci.ids",
                        "version": "0.0~2026.07.03-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guillem Jover <guillem@debian.org>",
                        "date": "Sat, 04 Jul 2026 01:51:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "pinentry-curses",
                "from_version": {
                    "source_package_name": "pinentry",
                    "source_package_version": "1.3.2-4ubuntu1",
                    "version": "1.3.2-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "pinentry",
                    "source_package_version": "1.3.3-2ubuntu1",
                    "version": "1.3.3-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2160263
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2160263). Remaining changes:",
                            "    - d/{control,rules}: don't build pinentry-qt on i386",
                            "      (dependencies are not in i386, as we decided to reduce the",
                            "      coverage for this architecture to a minimal set)",
                            "    - Build depend on libfltk1.3-dev for i386 only.",
                            "      (libfltk1.4-dev is not in i386, as we decided to reduce the coverage for",
                            "      this architecture to a minimal set)",
                            ""
                        ],
                        "package": "pinentry",
                        "version": "1.3.3-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160263
                        ],
                        "author": "Pierre-Elliott Bécue <pierre-elliott.becue@canonical.com>",
                        "date": "Wed, 29 Jul 2026 11:47:40 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "pinentry",
                        "version": "1.3.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Sat, 11 Jul 2026 16:30:18 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "    + Drop cherry-picked patch.",
                            "  * Use debhelper v14 compat mode.",
                            "  * Add infrastructure to generate copyright file with cme.",
                            "  * Run",
                            "    cp debian/copyright.template debian/copyright && cme update dpkg-copyright",
                            ""
                        ],
                        "package": "pinentry",
                        "version": "1.3.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Sat, 04 Jul 2026 13:31:38 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "plymouth",
                "from_version": {
                    "source_package_name": "plymouth",
                    "source_package_version": "24.004.60+git20250831.4a3c171d-0ubuntu8",
                    "version": "24.004.60+git20250831.4a3c171d-0ubuntu8"
                },
                "to_version": {
                    "source_package_name": "plymouth",
                    "source_package_version": "24.004.60+git20250831.4a3c171d-0ubuntu9",
                    "version": "24.004.60+git20250831.4a3c171d-0ubuntu9"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2144770
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2144770-Fix-reload-when-happening-early.patch:",
                            "    - Fix reload when happening early (LP: #2144770)",
                            ""
                        ],
                        "package": "plymouth",
                        "version": "24.004.60+git20250831.4a3c171d-0ubuntu9",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2144770
                        ],
                        "author": "Dariusz Gadomski <dgadomski@ubuntu.com>",
                        "date": "Fri, 10 Apr 2026 13:34:55 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "plymouth-theme-ubuntu-text",
                "from_version": {
                    "source_package_name": "plymouth",
                    "source_package_version": "24.004.60+git20250831.4a3c171d-0ubuntu8",
                    "version": "24.004.60+git20250831.4a3c171d-0ubuntu8"
                },
                "to_version": {
                    "source_package_name": "plymouth",
                    "source_package_version": "24.004.60+git20250831.4a3c171d-0ubuntu9",
                    "version": "24.004.60+git20250831.4a3c171d-0ubuntu9"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2144770
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2144770-Fix-reload-when-happening-early.patch:",
                            "    - Fix reload when happening early (LP: #2144770)",
                            ""
                        ],
                        "package": "plymouth",
                        "version": "24.004.60+git20250831.4a3c171d-0ubuntu9",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2144770
                        ],
                        "author": "Dariusz Gadomski <dgadomski@ubuntu.com>",
                        "date": "Fri, 10 Apr 2026 13:34:55 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-bcrypt",
                "from_version": {
                    "source_package_name": "python-bcrypt",
                    "source_package_version": "5.0.0-3build1",
                    "version": "5.0.0-3build1"
                },
                "to_version": {
                    "source_package_name": "python-bcrypt",
                    "source_package_version": "5.0.0-5",
                    "version": "5.0.0-5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "",
                            "  [ Peter Michael Green ]",
                            "  * Adjust packaging for getrandom 0.4 (closes: #1130519).",
                            ""
                        ],
                        "package": "python-bcrypt",
                        "version": "5.0.0-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Tue, 31 Mar 2026 16:31:49 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Accept pyo3 0.28.",
                            ""
                        ],
                        "package": "python-bcrypt",
                        "version": "5.0.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jelmer Vernooĳ <jelmer@debian.org>",
                        "date": "Tue, 17 Mar 2026 10:01:51 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-distro-info",
                "from_version": {
                    "source_package_name": "distro-info",
                    "source_package_version": "1.15",
                    "version": "1.15"
                },
                "to_version": {
                    "source_package_name": "distro-info",
                    "source_package_version": "1.17",
                    "version": "1.17"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1012459
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * test: replace experimental by rc-buggy for distro-info-data 0.73",
                            ""
                        ],
                        "package": "distro-info",
                        "version": "1.17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Sun, 19 Jul 2026 16:17:03 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Format Python code with black 26.3",
                            "  * Perl library:",
                            "    - fix exporting convert_date",
                            "    - add get_all_series() function (Closes: #1141228, LP: #1012459)",
                            "  * Add autopkgtest for testing libdistro-info-perl",
                            "  * Bump Standards-Version to 4.7.4",
                            "  * Use pybuild-plugin-pyproject to build the Python module",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "distro-info",
                        "version": "1.16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            1012459
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Fri, 17 Jul 2026 00:35:41 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-inflect",
                "from_version": {
                    "source_package_name": "python-inflect",
                    "source_package_version": "7.5.0-1build1",
                    "version": "7.5.0-1build1"
                },
                "to_version": {
                    "source_package_name": "python-inflect",
                    "source_package_version": "7.5.0-2",
                    "version": "7.5.0-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Add debian/salsa-ci.yml",
                            "  * Rewrite d/watch in v5 format",
                            "  * Use dh-sequence-python3",
                            "  * Drop \"Rules-Requires-Root: no\": it is the default now",
                            "  * Bump Standards-Version to 4.7.4, drop Priority: tag",
                            "  * Mark test build-deps as <!nocheck>",
                            ""
                        ],
                        "package": "python-inflect",
                        "version": "7.5.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sun, 05 Jul 2026 18:31:43 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-jwt",
                "from_version": {
                    "source_package_name": "pyjwt",
                    "source_package_version": "2.12.1-1",
                    "version": "2.12.1-1"
                },
                "to_version": {
                    "source_package_name": "pyjwt",
                    "source_package_version": "2.13.0-1",
                    "version": "2.13.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "  * [0cbf1ea] New upstream version 2.13.0",
                            ""
                        ],
                        "package": "pyjwt",
                        "version": "2.13.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Carsten Schoenert <c.schoenert@t-online.de>",
                        "date": "Wed, 01 Jul 2026 17:01:04 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-linkify-it",
                "from_version": {
                    "source_package_name": "linkify-it-py",
                    "source_package_version": "2.1.0-1",
                    "version": "2.1.0-1"
                },
                "to_version": {
                    "source_package_name": "linkify-it-py",
                    "source_package_version": "2.1.0-2",
                    "version": "2.1.0-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * adopted Alexandre Detiste's MR, thanks!",
                            "    Closes: #1141471",
                            ""
                        ],
                        "package": "linkify-it-py",
                        "version": "2.1.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Georges Khaznadar <georgesk@debian.org>",
                        "date": "Wed, 29 Jul 2026 11:27:52 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-netaddr",
                "from_version": {
                    "source_package_name": "python-netaddr",
                    "source_package_version": "1.3.0-1build1",
                    "version": "1.3.0-1build1"
                },
                "to_version": {
                    "source_package_name": "python-netaddr",
                    "source_package_version": "1.3.0-2",
                    "version": "1.3.0-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team Upload",
                            "  * Drop \"Rules-Requires-Root: no\": it is the default now",
                            "  * Rewrite d/watch in v5 format",
                            "  * Bump Standards-Version to 4.7.4, drop Priority: tag",
                            "  * Set upstream metadata fields: Contact, Documentation, Repository.",
                            "  * Add debian/salsa-ci.yml",
                            "  * Mark localehelper as <!nocheck>",
                            ""
                        ],
                        "package": "python-netaddr",
                        "version": "1.3.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sat, 04 Jul 2026 10:29:14 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-pyasn1",
                "from_version": {
                    "source_package_name": "pyasn1",
                    "source_package_version": "0.6.3-1",
                    "version": "0.6.3-1"
                },
                "to_version": {
                    "source_package_name": "pyasn1",
                    "source_package_version": "0.6.4-1",
                    "version": "0.6.4-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-59885",
                        "url": "https://ubuntu.com/security/CVE-2026-59885",
                        "cve_description": "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-14 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59884",
                        "url": "https://ubuntu.com/security/CVE-2026-59884",
                        "cve_description": "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-14 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59886",
                        "url": "https://ubuntu.com/security/CVE-2026-59886",
                        "cve_description": "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-14 17:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-59885",
                                "url": "https://ubuntu.com/security/CVE-2026-59885",
                                "cve_description": "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-14 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59884",
                                "url": "https://ubuntu.com/security/CVE-2026-59884",
                                "cve_description": "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-14 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59886",
                                "url": "https://ubuntu.com/security/CVE-2026-59886",
                                "cve_description": "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-14 17:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream release (closes: #1142388):",
                            "    - CVE-2026-59885 (GHSA-8ppf-4f7h-5ppj): Fixed quadratic time complexity",
                            "      in the OBJECT IDENTIFIER and RELATIVE-OID decoders.",
                            "    - CVE-2026-59884 (GHSA-m4p7-r5rc-7g4j): Limited BER long-form tag IDs to",
                            "      20 octets (140 bits), matching the OID arc limit introduced in 0.6.2.",
                            "    - CVE-2026-59886 (GHSA-hm4w-wwcw-mr6r): Fixed excessive memory and CPU",
                            "      consumption in Real.__float__() for values with large base-10",
                            "      exponents.",
                            "  * Standards-Version: 4.7.4.",
                            ""
                        ],
                        "package": "pyasn1",
                        "version": "0.6.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Tue, 21 Jul 2026 10:18:24 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-rich",
                "from_version": {
                    "source_package_name": "rich",
                    "source_package_version": "13.9.4-1.2",
                    "version": "13.9.4-1.2"
                },
                "to_version": {
                    "source_package_name": "rich",
                    "source_package_version": "15.0.0-1",
                    "version": "15.0.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * debian/patches/*",
                            "    - drop patches, merged upstream",
                            ""
                        ],
                        "package": "rich",
                        "version": "15.0.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sandro Tosi <morph@debian.org>",
                        "date": "Thu, 16 Apr 2026 01:42:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * ack nmu",
                            ""
                        ],
                        "package": "rich",
                        "version": "13.9.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sandro Tosi <morph@debian.org>",
                        "date": "Wed, 11 Mar 2026 01:09:06 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-six",
                "from_version": {
                    "source_package_name": "six",
                    "source_package_version": "1.17.0-2build1",
                    "version": "1.17.0-2build1"
                },
                "to_version": {
                    "source_package_name": "six",
                    "source_package_version": "1.17.0-3",
                    "version": "1.17.0-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team Upload",
                            "  * Add debian/salsa-ci.yml",
                            "  * Annotate build-deps as <!nodoc> or <!nocheck>",
                            "  * Bump Standards-Version to 4.7.4, drop Priority tag",
                            "  * Rewrite d/watch in v5 format",
                            ""
                        ],
                        "package": "six",
                        "version": "1.17.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sat, 04 Jul 2026 13:37:44 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-twisted",
                "from_version": {
                    "source_package_name": "twisted",
                    "source_package_version": "25.5.0-5",
                    "version": "25.5.0-5"
                },
                "to_version": {
                    "source_package_name": "twisted",
                    "source_package_version": "26.4.0-4",
                    "version": "26.4.0-4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-42304",
                        "url": "https://ubuntu.com/security/CVE-2026-42304",
                        "cve_description": "Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-13 21:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team Upload",
                            "  * Mark python3-hamcrest & python3-zope.interface as <!nocheck>",
                            ""
                        ],
                        "package": "twisted",
                        "version": "26.4.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sat, 04 Jul 2026 11:44:53 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Replace OpenSSL.crypto.X509Req with pyca/cryptography CSR (closes:",
                            "    #1140931).",
                            "  * Drop \"Priority: optional\", default as of dpkg-dev 1.22.13.",
                            "  * Standards-Version: 4.7.4.",
                            ""
                        ],
                        "package": "twisted",
                        "version": "26.4.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 29 Jun 2026 11:22:56 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team Upload",
                            "  * Rename gitlab-ci.yml -> salsa-ci.yml",
                            "  * Salsa CI: test <!nodoc> & <!nocheck> build profiles",
                            "  * Mark some dependencies <!nocheck> or <!nodoc>",
                            ""
                        ],
                        "package": "twisted",
                        "version": "26.4.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Thu, 25 Jun 2026 22:53:57 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-42304",
                                "url": "https://ubuntu.com/security/CVE-2026-42304",
                                "cve_description": "Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-13 21:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release:",
                            "    - CVE-2026-42304: twisted.names was fixed for Denial of Service (DoS)",
                            "      attack via resource exhaustion during DNS name decompression.",
                            ""
                        ],
                        "package": "twisted",
                        "version": "26.4.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 11 May 2026 14:18:49 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-zope.interface",
                "from_version": {
                    "source_package_name": "zope.interface",
                    "source_package_version": "8.5-2",
                    "version": "8.5-2"
                },
                "to_version": {
                    "source_package_name": "zope.interface",
                    "source_package_version": "8.5-3",
                    "version": "8.5-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team Upload",
                            "  * Mark python3-coverage & python3-zope.event as <!nocheck>",
                            ""
                        ],
                        "package": "zope.interface",
                        "version": "8.5-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Wed, 01 Jul 2026 08:17:28 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "tzdata",
                "from_version": {
                    "source_package_name": "tzdata",
                    "source_package_version": "2026b-1ubuntu2",
                    "version": "2026b-1ubuntu2"
                },
                "to_version": {
                    "source_package_name": "tzdata",
                    "source_package_version": "2026c-1ubuntu1",
                    "version": "2026c-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2161092
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2161092). Remaining changes:",
                            "    - Ship 2026b ICU timezone data which are utilized by PHP in tzdata-icu",
                            "    - Add autopkgtest test case for ICU timezone data",
                            "    - Point Vcs-Browser/Git to Launchpad",
                            "  * Dropped changes:",
                            "    - Declare breaking rust-coreutils before version 0.5.0.",
                            "      Ubuntu 26.04 \"resolute\" has rust-coreutils 0.8.0.",
                            "  * Update the ICU timezone data to 2026c",
                            "  * Add autopkgtest test case for ICU timezone data 2026c",
                            ""
                        ],
                        "package": "tzdata",
                        "version": "2026c-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161092
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Fri, 17 Jul 2026 14:34:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 2026c:",
                            "    - Alberta moved to permanent -06 on 2026-06-18, so it will not fall back",
                            "      from -06 to -07 on 2026-11-01.",
                            "    - Morocco moves to permanent +00 on 2026-09-20.",
                            "  * Add autopkgtest test case for 2026c release",
                            ""
                        ],
                        "package": "tzdata",
                        "version": "2026c-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 13 Jul 2026 22:18:20 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-pro-client",
                "from_version": {
                    "source_package_name": "ubuntu-advantage-tools",
                    "source_package_version": "37.2ubuntu",
                    "version": "37.2ubuntu"
                },
                "to_version": {
                    "source_package_name": "ubuntu-advantage-tools",
                    "source_package_version": "37.2ubuntu1",
                    "version": "37.2ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-9494",
                        "url": "https://ubuntu.com/security/CVE-2026-9494",
                        "cve_description": "An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11386",
                        "url": "https://ubuntu.com/security/CVE-2026-11386",
                        "cve_description": "An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-12391",
                        "url": "https://ubuntu.com/security/CVE-2026-12391",
                        "cve_description": "An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-9494",
                                "url": "https://ubuntu.com/security/CVE-2026-9494",
                                "cve_description": "An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11386",
                                "url": "https://ubuntu.com/security/CVE-2026-11386",
                                "cve_description": "An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-12391",
                                "url": "https://ubuntu.com/security/CVE-2026-12391",
                                "cve_description": "An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Information disclosure",
                            "    - Remove credentials out of argv into apt's own auth.conf.d facility.",
                            "    - CVE-2026-9494",
                            "  * SECURITY UPDATE: Improper input validation",
                            "    - enforce StrictStringDataValue to applicable fields in directives",
                            "    - reject newline, carriage return, spaces, and shell meta characters",
                            "      in StrictStringDataValue",
                            "    - CVE-2026-11386",
                            "  * SECURITY UPDATE: Symlink attack",
                            "    - reject symlink log files in user-controlled directory trees during",
                            "      pro collect-logs",
                            "    - restrict pro collect-logs generated support archive permission to",
                            "      root only",
                            "    - CVE-2026-12391",
                            ""
                        ],
                        "package": "ubuntu-advantage-tools",
                        "version": "37.2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Eduardo Barretto <eduardo.barretto@canonical.com>",
                        "date": "Mon, 06 Jul 2026 11:34:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-pro-client-l10n",
                "from_version": {
                    "source_package_name": "ubuntu-advantage-tools",
                    "source_package_version": "37.2ubuntu",
                    "version": "37.2ubuntu"
                },
                "to_version": {
                    "source_package_name": "ubuntu-advantage-tools",
                    "source_package_version": "37.2ubuntu1",
                    "version": "37.2ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-9494",
                        "url": "https://ubuntu.com/security/CVE-2026-9494",
                        "cve_description": "An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11386",
                        "url": "https://ubuntu.com/security/CVE-2026-11386",
                        "cve_description": "An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-12391",
                        "url": "https://ubuntu.com/security/CVE-2026-12391",
                        "cve_description": "An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-9494",
                                "url": "https://ubuntu.com/security/CVE-2026-9494",
                                "cve_description": "An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11386",
                                "url": "https://ubuntu.com/security/CVE-2026-11386",
                                "cve_description": "An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-12391",
                                "url": "https://ubuntu.com/security/CVE-2026-12391",
                                "cve_description": "An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Information disclosure",
                            "    - Remove credentials out of argv into apt's own auth.conf.d facility.",
                            "    - CVE-2026-9494",
                            "  * SECURITY UPDATE: Improper input validation",
                            "    - enforce StrictStringDataValue to applicable fields in directives",
                            "    - reject newline, carriage return, spaces, and shell meta characters",
                            "      in StrictStringDataValue",
                            "    - CVE-2026-11386",
                            "  * SECURITY UPDATE: Symlink attack",
                            "    - reject symlink log files in user-controlled directory trees during",
                            "      pro collect-logs",
                            "    - restrict pro collect-logs generated support archive permission to",
                            "      root only",
                            "    - CVE-2026-12391",
                            ""
                        ],
                        "package": "ubuntu-advantage-tools",
                        "version": "37.2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Eduardo Barretto <eduardo.barretto@canonical.com>",
                        "date": "Mon, 06 Jul 2026 11:34:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ufw",
                "from_version": {
                    "source_package_name": "ufw",
                    "source_package_version": "0.36.2-9build1",
                    "version": "0.36.2-9build1"
                },
                "to_version": {
                    "source_package_name": "ufw",
                    "source_package_version": "0.36.2-10",
                    "version": "0.36.2-10"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2129024
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/ufw.postinst, debian/ufw.postrm, debian/ufw.preinst,",
                            "    debian/ufw.prerm: use 'set -e' in the script body rather than passing",
                            "    -e on the shebang line (thanks, Debian Janitor)",
                            "  * debian/watch: update to version=5 and verify upstream OpenPGP",
                            "    signatures",
                            "  * debian/upstream/signing-key.asc: add upstream signing key",
                            "  * debian/control: update Standards-Version to 4.7.4 and drop the",
                            "    source Priority field; per 5.6.6, binary packages inherit 'optional'",
                            "  * debian/control: drop obsolete Python-Version field",
                            "  * debian/control: bump debhelper compat to 14",
                            "  * debian/ufw.lintian-overrides, debian/source/lintian-overrides: refresh",
                            "    for current lintian: drop unused entries (spelling-error-in-changelog,",
                            "    spare-manual-page) and the unoverridable mismatched-override entry;",
                            "    override typo-in-manual-page (the ufw(8) examples show literal rule",
                            "    syntax) and maintainer-manual-page (changelog.Debian.pre-0.27.1 is not",
                            "    a man page)",
                            "  * Add debian/po/ca.po. Thanks poc senderi (Closes: 1117114)",
                            "  * Add debian/po/zh_CN.po and debian/po/zh_TW.po. Thanks Yangfl",
                            "    (Closes: 1124732)",
                            "  * Honor debconf preseeding when installing (LP: #2129024):",
                            "    - debian/config: only sync the enabled state from /etc/ufw/ufw.conf",
                            "      into debconf on reconfigure. ufw.conf is created by postinst and",
                            "      survives remove, so syncing on install overwrote preseeded answers",
                            "    - debian/ufw.preinst: sync the enabled state on upgrade instead, and",
                            "      reset the ufw/existing_configuration seen flag on install so the",
                            "      allowed ports answers are processed again on reinstall",
                            "    - debian/control: Pre-Depends on debconf for the preinst debconf use",
                            "      (per lintian missing-debconf-dependency-for-preinst)",
                            "  * debian/tests/unittest: drop privileges when the testbed runs tests as",
                            "    root (the non-root unit tests assert on unprivileged behavior;",
                            "    ci.debian.net runs them as a user, but eg the null runner does not)",
                            ""
                        ],
                        "package": "ufw",
                        "version": "0.36.2-10",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2129024
                        ],
                        "author": "Jamie Strandboge <jdstrand@ubuntu.com>",
                        "date": "Sat, 04 Jul 2026 15:19:53 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "update-notifier-common",
                "from_version": {
                    "source_package_name": "update-notifier",
                    "source_package_version": "3.209",
                    "version": "3.209"
                },
                "to_version": {
                    "source_package_name": "update-notifier",
                    "source_package_version": "3.210",
                    "version": "3.210"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * reboot: Catch GNOME Shell reboot dialog cancel",
                            "  * reboot: Revamp reboot notification looks and logic",
                            "  * reboot: Add strings for future deferred-unattended-upgrades feature",
                            "  * d/update-notifier-common.install: Install in usr/lib/ instead of lib/",
                            ""
                        ],
                        "package": "update-notifier",
                        "version": "3.210",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Thu, 30 Jul 2026 16:58:59 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "xml-core",
                "from_version": {
                    "source_package_name": "xml-core",
                    "source_package_version": "0.20",
                    "version": "0.20"
                },
                "to_version": {
                    "source_package_name": "xml-core",
                    "source_package_version": "0.21",
                    "version": "0.21"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * QA upload.",
                            "",
                            "  [ Étienne Mollier ]",
                            "  * Improve error message to include entity URI.",
                            "    Closes: #1010134",
                            ""
                        ],
                        "package": "xml-core",
                        "version": "0.21",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Germann <bage@debian.org>",
                        "date": "Fri, 03 Jul 2026 23:10:52 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "added": {
        "deb": [
            {
                "name": "libntfs-3g90:s390x",
                "from_version": {
                    "source_package_name": "ntfs-3g",
                    "source_package_version": "1:2026.2.25-1",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "ntfs-3g",
                    "source_package_version": "1:2026.7.7-2",
                    "version": "1:2026.7.7-2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-42616",
                        "url": "https://ubuntu.com/security/CVE-2026-42616",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in cat() in  cat.c that allows an attacker to corrupt heap memory in the ntfscat  binary by crafting a malicious NTFS image. The overflow is triggered by  reading a file.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42617",
                        "url": "https://ubuntu.com/security/CVE-2026-42617",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap  memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS  image. The overflow is triggered by extending a directory, e.g., by  creating a file.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42618",
                        "url": "https://ubuntu.com/security/CVE-2026-42618",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_decompress() in compress.c that allows an attacker to corrupt one  byte of heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by reading the special  crafted file.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-46569",
                        "url": "https://ubuntu.com/security/CVE-2026-46569",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to  corrupt heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by extending a  directory, e.g., by creating a file.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-46570",
                        "url": "https://ubuntu.com/security/CVE-2026-46570",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to  corrupt heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by reading crafted file  metadata.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-46571",
                        "url": "https://ubuntu.com/security/CVE-2026-46571",
                        "cve_description": "In NTFS-3G through 2026.2.25, a out-of-bounds read exists in  ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to  read possibly confidential information in ntfs-3g process memory by  crafting a malicious NTFS image. The out-of-bounds read is triggered by  a readlink on a corrupted file.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-46572",
                        "url": "https://ubuntu.com/security/CVE-2026-46572",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to  corrupt heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by creating a file in a  crafted directory.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56135",
                        "url": "https://ubuntu.com/security/CVE-2026-56135",
                        "cve_description": "In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the  function build_inherited_id() in libntfs-3g/security.c that allows an  attacker to corrupt heap memory in the SUID-root ntfs-3g binary by  crafting a malicious NTFS image. The overflow is triggered by creating a  file in a crafted directory.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56136",
                        "url": "https://ubuntu.com/security/CVE-2026-56136",
                        "cve_description": "In NTFS-3G through 2026.2.25, an out-of-bounds read exists in  ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read  possibly confidential information in an ntfs-3g process by crafting a  malicious NTFS image. This read operation is triggered by creation of a  file with a crafted name.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-15 12:00:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to Sid.",
                            "  * Update copyright file.",
                            ""
                        ],
                        "package": "ntfs-3g",
                        "version": "1:2026.7.7-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sun, 19 Jul 2026 13:36:46 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-42616",
                                "url": "https://ubuntu.com/security/CVE-2026-42616",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in cat() in  cat.c that allows an attacker to corrupt heap memory in the ntfscat  binary by crafting a malicious NTFS image. The overflow is triggered by  reading a file.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42617",
                                "url": "https://ubuntu.com/security/CVE-2026-42617",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap  memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS  image. The overflow is triggered by extending a directory, e.g., by  creating a file.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42618",
                                "url": "https://ubuntu.com/security/CVE-2026-42618",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_decompress() in compress.c that allows an attacker to corrupt one  byte of heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by reading the special  crafted file.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-46569",
                                "url": "https://ubuntu.com/security/CVE-2026-46569",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to  corrupt heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by extending a  directory, e.g., by creating a file.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-46570",
                                "url": "https://ubuntu.com/security/CVE-2026-46570",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to  corrupt heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by reading crafted file  metadata.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-46571",
                                "url": "https://ubuntu.com/security/CVE-2026-46571",
                                "cve_description": "In NTFS-3G through 2026.2.25, a out-of-bounds read exists in  ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to  read possibly confidential information in ntfs-3g process memory by  crafting a malicious NTFS image. The out-of-bounds read is triggered by  a readlink on a corrupted file.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-46572",
                                "url": "https://ubuntu.com/security/CVE-2026-46572",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap buffer overflow exists in  ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to  corrupt heap memory in the SUID-root ntfs-3g binary by crafting a  malicious NTFS image. The overflow is triggered by creating a file in a  crafted directory.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56135",
                                "url": "https://ubuntu.com/security/CVE-2026-56135",
                                "cve_description": "In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the  function build_inherited_id() in libntfs-3g/security.c that allows an  attacker to corrupt heap memory in the SUID-root ntfs-3g binary by  crafting a malicious NTFS image. The overflow is triggered by creating a  file in a crafted directory.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56136",
                                "url": "https://ubuntu.com/security/CVE-2026-56136",
                                "cve_description": "In NTFS-3G through 2026.2.25, an out-of-bounds read exists in  ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read  possibly confidential information in an ntfs-3g process by crafting a  malicious NTFS image. This read operation is triggered by creation of a  file with a crafted name.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-15 12:00:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1142144):",
                            "    - fixes CVE-2026-42616: heap buffer overflow in cat(),",
                            "    - fixes CVE-2026-42617: heap buffer overflow in ntfs_ir_to_ib(),",
                            "    - fixes CVE-2026-42618: heap buffer overflow in ntfs_decompress(),",
                            "    - fixes CVE-2026-46569: missing range check in ntfs_ib_copy_tail(),",
                            "    - fixes CVE-2026-46570: heap memory corruption in ntfs_index_walk_down(),",
                            "    - fixes CVE-2026-46571: out of bounds read in ntfs_fix_file_name(),",
                            "    - fixes CVE-2026-46572: heap buffer overflow in ntfs_ib_cut_tail(),",
                            "    - fixes CVE-2026-56135: heap buffer overflow in build_inherited_id(),",
                            "    - fixes CVE-2026-56136: out of bounds memmove in ntfs_ir_nill().",
                            "  * Update copyright file.",
                            "  * Update Standards-Version to 4.7.2 .",
                            "  * Library transition from libntfs-3g89 to libntfs-3g90 .",
                            ""
                        ],
                        "package": "ntfs-3g",
                        "version": "1:2026.7.7-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Wed, 15 Jul 2026 22:16:05 +0200"
                    }
                ],
                "notes": "libntfs-3g90:s390x version '1:2026.7.7-2' (source package ntfs-3g version '1:2026.7.7-2') was added. libntfs-3g90:s390x version '1:2026.7.7-2' has the same source package name, ntfs-3g, as removed package libntfs-3g89t64:s390x. As such we can use the source package version of the removed package, '1:2026.2.25-1', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "removed": {
        "deb": [
            {
                "name": "libntfs-3g89t64:s390x",
                "from_version": {
                    "source_package_name": "ntfs-3g",
                    "source_package_version": "1:2026.2.25-1",
                    "version": "1:2026.2.25-1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "notes": "Changelog diff for Ubuntu 26.10 stonking image from daily image serial 20260726 to 20260801",
    "from_series": "stonking",
    "to_series": "stonking",
    "from_serial": "20260726",
    "to_serial": "20260801",
    "from_manifest_filename": "daily_manifest.previous",
    "to_manifest_filename": "manifest.current"
}