{
    "summary": {
        "snap": {
            "added": [],
            "removed": [],
            "diff": []
        },
        "deb": {
            "added": [
                "curl",
                "libcurl4t64",
                "libldap-common",
                "libldap2",
                "libnghttp2-14",
                "libproc2-1",
                "libsasl2-2",
                "libsasl2-modules-db",
                "libssh2-1t64",
                "libssl4",
                "linux-image-7.3.0-5-generic",
                "linux-main-modules-zfs-7.3.0-5-generic",
                "linux-modules-7.3.0-5-generic",
                "openssh-common",
                "python3-charset-normalizer",
                "sqv"
            ],
            "removed": [
                "gpgv",
                "libgcrypt20",
                "libgpg-error0",
                "libproc2-0",
                "linux-image-7.0.0-14-generic",
                "linux-main-modules-zfs-7.0.0-14-generic",
                "linux-modules-7.0.0-14-generic",
                "python3-autocommand",
                "python3-inflect",
                "python3-jaraco.context",
                "python3-jaraco.functools",
                "python3-jaraco.text",
                "python3-more-itertools",
                "python3-pkg-resources",
                "python3-setuptools",
                "python3-typeguard",
                "python3-typing-extensions",
                "python3-zipp"
            ],
            "diff": [
                "adduser",
                "apparmor",
                "apport",
                "apport-core-dump-handler",
                "apt",
                "bash",
                "ca-certificates",
                "chrony",
                "cloud-init",
                "cloud-init-base",
                "console-setup",
                "console-setup-linux",
                "coreutils",
                "coreutils-from-uutils",
                "debianutils",
                "dhcpcd-base",
                "distro-info",
                "distro-info-data",
                "ethtool",
                "findutils",
                "fuse3",
                "gcc-16-base",
                "gettext-base",
                "gir1.2-girepository-3.0",
                "gir1.2-glib-2.0",
                "gnu-coreutils",
                "gzip",
                "iproute2",
                "kbd",
                "keyboard-configuration",
                "kmod",
                "libapparmor1",
                "libapt-pkg7.0",
                "libatomic1",
                "libaudit-common",
                "libaudit1",
                "libbrotli1",
                "libc-bin",
                "libc-gconv-modules-extra",
                "libc6",
                "libcap2",
                "libcap2-bin",
                "libcrypt1",
                "libelf1t64",
                "libexpat1",
                "libffi8",
                "libfido2-1",
                "libfreetype6",
                "libfuse3-4",
                "libgcc-s1",
                "libgirepository-2.0-0",
                "libglib2.0-0t64",
                "libgnutls30t64",
                "libgssapi-krb5-2",
                "libjs-sphinxdoc",
                "libk5crypto3",
                "libkmod2",
                "libkrb5-3",
                "libkrb5support0",
                "liblocale-gettext-perl",
                "libncursesw6",
                "libnetplan1",
                "libp11-kit0",
                "libpam-modules",
                "libpam-modules-bin",
                "libpam-runtime",
                "libpam-systemd",
                "libpam0g",
                "libpsl5t64",
                "libpython3-stdlib",
                "libpython3.14-minimal",
                "libpython3.14-stdlib",
                "libseccomp2",
                "libselinux1",
                "libsemanage-common",
                "libsemanage2",
                "libsqlite3-0",
                "libstdc++6",
                "libsystemd-shared",
                "libsystemd0",
                "libtext-charwidth-perl",
                "libtinfo6",
                "libudev1",
                "libzstd1",
                "linux-base",
                "linux-image-virtual",
                "login.defs",
                "mokutil",
                "ncurses-base",
                "ncurses-bin",
                "ncurses-term",
                "netplan-generator",
                "netplan.io",
                "openssh-client",
                "openssh-server",
                "openssh-sftp-server",
                "openssl",
                "openssl-provider-legacy",
                "passwd",
                "pci.ids",
                "perl-base",
                "procps",
                "python3",
                "python3-apport",
                "python3-bcrypt",
                "python3-certifi",
                "python3-cffi-backend",
                "python3-click",
                "python3-cryptography",
                "python3-distro-info",
                "python3-distupgrade",
                "python3-gi",
                "python3-httplib2",
                "python3-idna",
                "python3-jinja2",
                "python3-jsonpatch",
                "python3-lazr.restfulclient",
                "python3-lazr.uri",
                "python3-markupsafe",
                "python3-minimal",
                "python3-netplan",
                "python3-problem-report",
                "python3-requests",
                "python3-urllib3",
                "python3.14",
                "python3.14-minimal",
                "rust-coreutils",
                "sbsigntool",
                "snapd",
                "sudo-rs",
                "systemd",
                "systemd-resolved",
                "systemd-sysv",
                "tzdata",
                "ubuntu-cloud-minimal",
                "ubuntu-drivers-common",
                "ubuntu-keyring",
                "ubuntu-pro-client",
                "ubuntu-release-upgrader-core",
                "udev",
                "wget",
                "wireless-regdb",
                "xkb-data"
            ]
        }
    },
    "diff": {
        "deb": [
            {
                "name": "adduser",
                "from_version": {
                    "source_package_name": "adduser",
                    "source_package_version": "3.153ubuntu1",
                    "version": "3.153ubuntu1"
                },
                "to_version": {
                    "source_package_name": "adduser",
                    "source_package_version": "3.157ubuntu2",
                    "version": "3.157ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2166367,
                    2153280
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/tests/f/firstlastuidgid.t:",
                            "    - Fix autopkgtest firstlastuidgid.t uid ranges conflicting with",
                            "      systemd-sysusers allocation (LP: #2166367)",
                            ""
                        ],
                        "package": "adduser",
                        "version": "3.157ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166367
                        ],
                        "author": "Sebastien Bacher <seb128@ubuntu.com>",
                        "date": "Fri, 11 Sep 2026 12:08:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153280). Remaining changes:",
                            "    - extrausers support for adduser and gpasswd (LP #1323732)",
                            "    - Add support for ZFS home directories (LP #1873263)",
                            "    - Enable private home directories by default (LP #48734)",
                            "      Set DIR_MODE=0750 and SYS_DIR_MODE=0750 in the default adduser.conf,",
                            "      and match those in the check_octal fallback for invalid values.",
                            "    Dropped changes:",
                            "    - Add support for encrypting home directories (MR: !87)",
                            "      (upstreamed in Debian 3.157)",
                            "    - Regenerate po4a translation catalogs (build artefacts)",
                            ""
                        ],
                        "package": "adduser",
                        "version": "3.157ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153280
                        ],
                        "author": "Nadzeya Hutsko <nadzeya@ubuntu.com>",
                        "date": "Mon, 13 Jul 2026 13:48:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Marc Haber ]",
                            "  * add script that runs the testsuite without autopkgtest",
                            "    (Closes: #1101457)",
                            "  * add a NOTE to adduser.8 regarding group membership (Closes: #1103776)",
                            "  * implement adduser --force-home.",
                            "    Thanks to Jeff Hanson (Closes: #472820)",
                            "  * Add new Romanian program and man page translation.",
                            "    Thanks to Remus-Gabriel Chelu (Closes: #1137603, #1137602)",
                            "  * update dutch program translation.",
                            "    Thanks to Frans Spiesschaert (Closes: #1118210, #1133696)",
                            "",
                            "  [ Dustin Kirkland ]",
                            "  * Add support for encrypting home directories",
                            "    * adduser: Add --encrypt-home option, which calls ecryptfs-setup-private",
                            "      for the hard work.",
                            "    * doc/adduser.8: document the --encrypt-home option",
                            "    * debian/control: suggest ecryptfs-utils >= 67-1",
                            "    * deluser: remove all of /var/lib/ecryptfs/$user with --remove-home",
                            "",
                            "  [ Mateus Rodrigues de Morais ]",
                            "  * Add encrypted home tests with isolation-machine restriction",
                            ""
                        ],
                        "package": "adduser",
                        "version": "3.157",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Haber <mh+debian-packages@zugschlus.de>",
                        "date": "Wed, 17 Jun 2026 22:36:50 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * ignore extra fields at the end of pool file lines",
                            "  * streamline log level names. (Closes: #1132881)",
                            "  * demote \"crontab not found\" warning to info",
                            "    it is now perfectly normal to run a system that doesn't have cron",
                            ""
                        ],
                        "package": "adduser",
                        "version": "3.156",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Haber <mh+debian-packages@zugschlus.de>",
                        "date": "Mon, 01 Jun 2026 07:06:57 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Marc Haber ]",
                            "  * remove GROUPHOMES and LETTERHOMES configuration options",
                            "  * remove SETGID_HOME configuration option",
                            "  * remove deprecated QUOTAUSER configuration option",
                            "  * remove debian/tests/f/cronjack.t",
                            "    useradd won't allow adding that user name any more",
                            "  * Depend on passwd 1:4.19.0-2. Remove cronjack.t test",
                            "    (Closes: #1124993)",
                            "  * Give chpasswd test values that it will accept (Closes: 1124992)",
                            "  * give Matt's work on existing_*_ okay another simplifying brush-up",
                            "  * po: Add Georgian translation.",
                            "    Thanks to Temuri Doghonadze",
                            "  * allow /etc/skel to contain files with UTF-8 file names.",
                            "    This moves home dir creation to a new module AdduserCreateHomedir",
                            "    Thanks to Mert Ok (Closes: #1125681)",
                            "  * copy over find_unused_* functions from upstream testsuites",
                            "    (Closes: #1015781)",
                            "  * man page improvements for adduser.8.",
                            "    Thanks to Bjarni Ingi Gislason (Closes: #1124790)",
                            "  * apply correcting patch from #1105900.",
                            "    Thanks to Bjarni Ingi Gislason (Closes: #1105900)",
                            "  * write test cases to trigger #1125601",
                            "  * Updated German man page translation.",
                            "    Thanks to Helge Kreutzmann (Closes: #1125135)",
                            "  * Updated Portuguese man page and program translation.",
                            "    Thanks to Américo Monteiro (Closes: #1118370)",
                            "  * Updated Dutch man page translation.",
                            "    Thanks to Frans Spiesschaert (Closes: #1118209)",
                            "",
                            "  [ Matt Barry ]",
                            "  * Add adduser --unlock [--system] and deluser --lock [--system]",
                            "    (Closes: #1008082, #1008083, #1008084)",
                            ""
                        ],
                        "package": "adduser",
                        "version": "3.155",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Haber <mh+debian-packages@zugschlus.de>",
                        "date": "Sat, 28 Mar 2026 10:16:28 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * The Happy New Year 2026 Release",
                            "",
                            "  [ Matt Barry ]",
                            "  * add --no-copy-skel option (Closes: #1099633)",
                            "  * document --no-copy-skel",
                            "  * refactor existing_*_ok",
                            "",
                            "  [ Marc Haber ]",
                            "  * make deluser --group work as documented.",
                            "  * have delgroup reject user-specific command line options.",
                            "  * correctly sanitize names in deluser.",
                            "    Thanks to Dagfinn Ilmari Mannsåker (Closes: #1109329)",
                            "  * update Swedish program and man page translation.",
                            "    Thanks to Daniel Nylander <daniel@danielnylander.se>",
                            "  * make adduser error out if --system and account has a password",
                            "    (Closes: #1099734)",
                            ""
                        ],
                        "package": "adduser",
                        "version": "3.154",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Haber <mh+debian-packages@zugschlus.de>",
                        "date": "Thu, 01 Jan 2026 00:00:10 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "apparmor",
                "from_version": {
                    "source_package_name": "apparmor",
                    "source_package_version": "5.0.1-0ubuntu1",
                    "version": "5.0.1-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "apparmor",
                    "source_package_version": "6.0.0~alpha1-0ubuntu1",
                    "version": "6.0.0~alpha1-0ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2152079
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * debian/control: add iwyu, pytest, pytest-xdist to Build-Depends",
                            "  * Drop patches that were applied upstream:",
                            "    - d/p/u/0001-parser-add-more-reserved-mediation-classes.patch",
                            "  * Refresh patches for new release:",
                            "    - d/p/u/0007-Set-parser-network.h-ip_conds-ptrs-to-null-in-its-fr.patch",
                            "  * Update patches for new release:",
                            "    - d/p/u/profiles-use-coreutils-tunable.patch",
                            "    - d/p/u/profiles_add_more_consoles_workaround.patch",
                            "    - d/p/u/profiles_disable_free.patch",
                            "  * Add patches to install a confining loupe profile:",
                            "    - d/p/u/0001-profiles-add-a-glycin-tunable.patch",
                            "    - d/p/u/0002-profiles-begin-adding-abstractions-for-the-XDG-Deskt.patch",
                            "    - d/p/u/0003-profiles-rewrite-the-loupe-profile.patch",
                            "  * debian/apparmor.install: add glycin tunables",
                            ""
                        ],
                        "package": "apparmor",
                        "version": "6.0.0~alpha1-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ryan Lee <ryan.lee@canonical.com>",
                        "date": "Thu, 20 Aug 2026 12:05:00 -0700"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Update patches to apply to new release:",
                            "    - d/p/u/profiles_disable_curl.patch",
                            "  * Add patch to fix transmission-gtk file chooser (LP: #2152079):",
                            "    - d/p/u/profiles-add-file-chooser-rules-to-abstractions-trans.patch",
                            ""
                        ],
                        "package": "apparmor",
                        "version": "5.0.2-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2152079
                        ],
                        "author": "Ryan Lee <ryan.lee@canonical.com>",
                        "date": "Mon, 13 Jul 2026 10:43:46 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "apport",
                "from_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.35.0-0ubuntu1",
                    "version": "2.35.0-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.36.0-0ubuntu1",
                    "version": "2.36.0-0ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-77113",
                        "url": "https://ubuntu.com/security/CVE-2026-77113",
                        "cve_description": "",
                        "cve_priority": "n/a",
                        "cve_public_date": ""
                    }
                ],
                "launchpad_bugs_fixed": [
                    2161697,
                    2163744,
                    2109979,
                    2156405,
                    2161888,
                    2161957
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-77113",
                                "url": "https://ubuntu.com/security/CVE-2026-77113",
                                "cve_description": "",
                                "cve_priority": "n/a",
                                "cve_public_date": ""
                            }
                        ],
                        "log": [
                            "",
                            "  [ Benjamin Drung ]",
                            "  * New upstream release.",
                            "    - SECURITY UPDATE: path traversal during report extraction (LP: #2161697)",
                            "      + problem_report: validate key names in ProblemReport.load",
                            "      + CVE-2026-77113",
                            "    - apport_python_hook: support dbus-broker (LP: #2163744)",
                            "    - Fix partial writes for coredumps larger than 2 GiB (LP: #2109979)",
                            "  * autopkgtest: remove unneeded dirmngr dependency",
                            "  * Drop patches applied upstream and refresh remaining patches",
                            "  * python3-apport: Tighten python3-problem-report dependency to >= 2.36",
                            "  * Let python3-problem-report break apport << 2.36 (for apport-unpack)",
                            "",
                            "  [ Kat Kuo ]",
                            "  * oem-getlogs: Remove Ubuntu Report call and get DCD directly (LP: #2156405)",
                            ""
                        ],
                        "package": "apport",
                        "version": "2.36.0-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161697,
                            2163744,
                            2109979,
                            2156405
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 16:48:31 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * test: wait for child processes to complete execve() (LP: #2161888)",
                            "  * test: add riscv64 entry to archmap (see LP #2159030)",
                            "  * test: increase waiting timeout from 5/10 to 30 seconds (see LP #2159030)",
                            "  * rewrite check_files_md5 in pure Python (LP: #2161957)",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "apport",
                        "version": "2.35.0-0ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161888,
                            2161957
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 14:06:05 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "apport-core-dump-handler",
                "from_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.35.0-0ubuntu1",
                    "version": "2.35.0-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.36.0-0ubuntu1",
                    "version": "2.36.0-0ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-77113",
                        "url": "https://ubuntu.com/security/CVE-2026-77113",
                        "cve_description": "",
                        "cve_priority": "n/a",
                        "cve_public_date": ""
                    }
                ],
                "launchpad_bugs_fixed": [
                    2161697,
                    2163744,
                    2109979,
                    2156405,
                    2161888,
                    2161957
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-77113",
                                "url": "https://ubuntu.com/security/CVE-2026-77113",
                                "cve_description": "",
                                "cve_priority": "n/a",
                                "cve_public_date": ""
                            }
                        ],
                        "log": [
                            "",
                            "  [ Benjamin Drung ]",
                            "  * New upstream release.",
                            "    - SECURITY UPDATE: path traversal during report extraction (LP: #2161697)",
                            "      + problem_report: validate key names in ProblemReport.load",
                            "      + CVE-2026-77113",
                            "    - apport_python_hook: support dbus-broker (LP: #2163744)",
                            "    - Fix partial writes for coredumps larger than 2 GiB (LP: #2109979)",
                            "  * autopkgtest: remove unneeded dirmngr dependency",
                            "  * Drop patches applied upstream and refresh remaining patches",
                            "  * python3-apport: Tighten python3-problem-report dependency to >= 2.36",
                            "  * Let python3-problem-report break apport << 2.36 (for apport-unpack)",
                            "",
                            "  [ Kat Kuo ]",
                            "  * oem-getlogs: Remove Ubuntu Report call and get DCD directly (LP: #2156405)",
                            ""
                        ],
                        "package": "apport",
                        "version": "2.36.0-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161697,
                            2163744,
                            2109979,
                            2156405
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 16:48:31 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * test: wait for child processes to complete execve() (LP: #2161888)",
                            "  * test: add riscv64 entry to archmap (see LP #2159030)",
                            "  * test: increase waiting timeout from 5/10 to 30 seconds (see LP #2159030)",
                            "  * rewrite check_files_md5 in pure Python (LP: #2161957)",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "apport",
                        "version": "2.35.0-0ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161888,
                            2161957
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 14:06:05 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "apt",
                "from_version": {
                    "source_package_name": "apt",
                    "source_package_version": "3.2.0",
                    "version": "3.2.0"
                },
                "to_version": {
                    "source_package_name": "apt",
                    "source_package_version": "3.3.3",
                    "version": "3.3.3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158000,
                    2150631
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  This release introduces initial interactive help output for apt(8)",
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * cmdline: add declarative option help printer",
                            "  * mirror: Scale fan-out with the square root of the number of files",
                            "",
                            "  [ Simon Johnsson ]",
                            "  * cmdline: add command-specific help texts",
                            "",
                            "  [ Zara Grigoryan ]",
                            "  * cmdline: render declarative options in command help",
                            "  * cmdline: mark option descriptions for translation",
                            "  * cmdline: refine command-specific help rendering",
                            "",
                            "  [ Andriy Pysyk ]",
                            "  * Fix fuzzy entries in Ukrainian translation for APT 3.3.2 + terminology consistency improvements",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Fri, 14 Aug 2026 17:51:56 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * Document and test combined `build-dep --arch-only --indep-only`",
                            "  * ftparchive: fix heap overflow in ContentsExtract::DoItem",
                            "  * deb: guard against unsigned underflow when trimming control newlines",
                            "  * gpgv: don't advance past the null terminator in PushEntryWithKeyID",
                            "  * ftparchive: replace ContentsExtract's manual buffer with std::vector<char>",
                            "  * test: Limit valgrind to 1024 open files",
                            "  * hashes: Fix lingering OpenSSL error (Closes: #1140227)",
                            "  * test: use `gnurm` where available",
                            "  * Convert command-line option-parsing to declarative format",
                            "  * Fix crash when an aux file request is redirected",
                            "  * Reply to aux requests with the original URI if redirected",
                            "  * debian/apt-daily.service: Add timeouts.",
                            "    30 mins for apt-daily.service, 12 hours for apt-daily-upgrade.service",
                            "    should be sufficient. (LP: #2158000)",
                            "",
                            "  [ наб ]",
                            "  * apt-transport-https(1): document host-specific SSLCert, SSLKey, Verify-Host with host:: instead of ::host",
                            "",
                            "  [ David Kalnischkies ]",
                            "  * aptwebserver: Refuse client immediately on TLS handshake",
                            "",
                            "  [ Américo Monteiro ]",
                            "  * Portuguese manpages translation update (Closes: #1133965)",
                            "",
                            "  [ Frans Spiesschaert ]",
                            "  * Dutch program translation update (Closes: #1135221)",
                            "  * Dutch manpages translation update (Closes: #1135222)",
                            "",
                            "  [ Remus-Gabriel Chelu ]",
                            "  * Romanian program translation update (Closes: #1139336)",
                            "",
                            "  [ Mark Atwood ]",
                            "  * hashes: include <span> for std::span",
                            "  * hashes: don't crash on an unavailable digest",
                            "  * test: exercise hashes with a disabled digest",
                            "",
                            "  [ dongshengyuan ]",
                            "  * Fix installing a deb with colon in path",
                            "",
                            "  [ Simon Johnsson ]",
                            "  * apt-pkg: rename \"OpenPGP signature verification failed\" to \"Signature verification failed\"",
                            "",
                            "  [ Andreas Noteng ]",
                            "  * Norwegian Bokmål (nb) translation update",
                            "",
                            "  [ Temuri Doghonadze ]",
                            "  * po: Add Georgian translation",
                            "",
                            "  [ Andriy Pysyk ]",
                            "  * Update Ukrainian translation for 3.3.1",
                            "",
                            "  [ Mikhail Khachayants ]",
                            "  * srvrec: reject res_query answers bigger than our buffer",
                            "",
                            "  [ Ramesh Adhikari ]",
                            "  * tagfile: fix unbounded backward scan in Fill()'s trailing-newline check",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2158000
                        ],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 22:43:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * solver3: Follow installed Suggests earlier",
                            "  * Fix `noexcept` as pointed out by gcc",
                            "  * Fix wrongful std::make_unique conversion",
                            "  * Fix regression in dirstream (Closes: #1136441)",
                            "",
                            "  [ Varun Varma ]",
                            "  * Warn if auth.conf is unreadable (LP: #2150631)",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2150631
                        ],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Sun, 17 May 2026 21:21:50 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Anders Kaseorg ]",
                            "  * Fix Phased-Update-Percentage probability mistake",
                            "",
                            "  [ Simon Johnsson ]",
                            "  * Scale history-list to screen width",
                            "  * Optimize ShortenCommand",
                            "  * Change GetKindString to not use .data() call",
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * Drop warning about unstable CLI interface.",
                            "    A specific CLI version can now be requested using the --cli-version",
                            "    flag, and old versions can be deprecated on a reasonable cadence.",
                            "    Therefore, a warning is no longer necessary.",
                            "  * hashes: Use std::span instead of std::basic_string_view",
                            "  * sources.list(5): Document Contact/Bugs/Description fields.",
                            "    Thanks to josch for the suggestion",
                            "  * Require sqv for builds on supported archs and !pkg.apt.nosqv",
                            "",
                            "  [ Zheyu Shen ]",
                            "  * fix apt patterns parsing bug for pre-depends",
                            "",
                            "  [ Herman Semenoff ]",
                            "  * apt: funcs called with a string literal consisting of a single character",
                            "  * apt-pkg/acquire: use range based for loop C++17",
                            "  * apt: push to emplace C++11 if possible",
                            "  * apt: modernize to make_unique C++17",
                            "  * apt-pkg: methods: fixed many minor memleaks",
                            "",
                            "  [ наб ]",
                            "  * sources.list(5): th[r]ough typo",
                            "",
                            "  [ Sebastian Krzyszkowiak ]",
                            "  * acquire-item: Fix up the error message on committing aborted transaction",
                            "  * pkgAcqMetaClearSig: Abort transaction when pkgAcquire::Run has been cancelled",
                            "    (Closes: #1078608)",
                            "  * pkgAcqMetaBase: Commit InRelease after other transaction items",
                            "    (Closes: #1078608)",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Fix bug reference",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.0",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Fri, 01 May 2026 18:40:52 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "bash",
                "from_version": {
                    "source_package_name": "bash",
                    "source_package_version": "5.3-2ubuntu1",
                    "version": "5.3-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "bash",
                    "source_package_version": "5.3-3ubuntu1",
                    "version": "5.3-3ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153285
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable (LP: #2153285). Remaining changes:",
                            "    - d/skel.bashrc: Run lesspipe.",
                            "    - d/skel.bashrc: Enable ls aliases.",
                            "    - d/skel.bashrc: Set options in ll alias to -alF.",
                            "    - d/skel.bashrc: Define an alert alias.",
                            "    - d/skel.bashrc: Enable colored grep aliases.",
                            "    - d/p/deb-bash-config.diff: Set the default path to comply with",
                            "      Debian policy.",
                            "    - d/tests: Add autopkgtest for the built-in path.",
                            "    - d/rules: Use /usr/bin/bash as SHELL.",
                            ""
                        ],
                        "package": "bash",
                        "version": "5.3-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153285
                        ],
                        "author": "Zineb Zaadoud <zineb.zaadoud@canonical.com>",
                        "date": "Mon, 10 Aug 2026 11:37:44 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Build with -O1 on sh4 (Adrian Glaubitz). Addresses: #1130485.",
                            ""
                        ],
                        "package": "bash",
                        "version": "5.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 03 May 2026 21:28:45 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ca-certificates",
                "from_version": {
                    "source_package_name": "ca-certificates",
                    "source_package_version": "20260601",
                    "version": "20260601"
                },
                "to_version": {
                    "source_package_name": "ca-certificates",
                    "source_package_version": "20260816",
                    "version": "20260816"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update Mozilla certificate authority bundle to version 2.90",
                            "    The following certificate authorities were added (+):",
                            "    + \"SECOM TLS ECC Root CA 2024\"",
                            "    + \"SECOM TLS RSA Root CA 2024\"",
                            "    + \"Telia EC TLS Root CA v3\"",
                            "    + \"Telia RSA TLS Root CA v3\"",
                            "    The following certificate authorities were removed (-):",
                            "    - \"Atos TrustedRoot 2011\"",
                            "    - \"Entrust Root Certification Authority\"",
                            "    - \"SecureSign Root CA12\"",
                            "    - \"ePKI Root Certification Authority\"",
                            ""
                        ],
                        "package": "ca-certificates",
                        "version": "20260816",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Julien Cristau <jcristau@debian.org>",
                        "date": "Sun, 16 Aug 2026 23:04:36 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "chrony",
                "from_version": {
                    "source_package_name": "chrony",
                    "source_package_version": "4.8-2ubuntu2",
                    "version": "4.8-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "chrony",
                    "source_package_version": "4.8-4ubuntu2",
                    "version": "4.8-4ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2161782,
                    2154097
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix NTP sources being left offline after a link flap on systemd-networkd",
                            "    hosts: (LP: #2161782)",
                            "    - d/p/examples-add-improved-networkd-dispatcher-script.patch: cherry-pick",
                            "      upstream's dedicated networkd-dispatcher script.",
                            "    - d/chrony.examples: install chrony.networkd-dispatcher.",
                            "    - d/chrony.links: create symlinks for the new networkd-dispatcher script.",
                            ""
                        ],
                        "package": "chrony",
                        "version": "4.8-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161782
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Wed, 26 Aug 2026 11:28:57 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2154097). Remaining changes:",
                            "    - Set -x as default if unable to set time (e.g. in containers) (LP #1589780)",
                            "      Chrony is a single service which acts as both NTP client (i.e. syncing the",
                            "      local clock) and NTP server (i.e. providing NTP services to the network),",
                            "      and that is both desired and expected in the vast majority of cases.",
                            "      But in containers syncing the local clock is usually impossible, but this",
                            "      shall not break the providing of NTP services to the network.",
                            "      To some extent this makes chrony's default config more similar to 'ntpd',",
                            "      which complained in syslog but still provided NTP server service in those",
                            "      cases.",
                            "      + debian/chrony.service: allow the service to run without CAP_SYS_TIME",
                            "      + d/control: add new dependency libcap2-bin for capsh (usually",
                            "        installed anyway, but make them explicit to be sure).",
                            "      + d/chrony.default: new option SYNC_IN_CONTAINER to not fall",
                            "        back (Default off)",
                            "      + d/chronyd-starter.sh: wrapper to handle special cases in",
                            "        containers and if CAP_SYS_TIME is missing. Effectively allows",
                            "        running the NTP server in containers on a default installation",
                            "        and avoid failing to sync time (or if allowed to sync, avoid",
                            "        multiple containers fighting over it by accident).",
                            "      + d/chrony.install: Make chrony-starter.sh available on install.",
                            "      + d/docs, d/README.container: Provide documentation about the",
                            "        handling of this case.",
                            "    - d/rules, d/chrony.examples: Ship restricted service as an example",
                            "      not installed to the system for use.  (See LP #2051028)",
                            "    - d/chrony.conf: remove Debian NTP pool and Document non-NTS sources from",
                            "      DHCP (LP #2115565)",
                            "    - Install Ubuntu NTP sources in",
                            "      /etc/chrony/sources.d/ubuntu-ntp-pools.sources, gated on a low priority",
                            "      (default yes) debconf question (LP #2048876):",
                            "      + d/templates: Add debconf question to customize installation of",
                            "        /etc/chrony/sources.d/ubuntu-ntp-pools.sources",
                            "      + d/chrony.install, d/ubuntu-ntp-pools.sources: Install",
                            "        ubuntu-ntp-pools.sources in /usr/share/chrony",
                            "      + d/control: add dependency on debconf",
                            "      + d/postinst: handle Ubuntu pools via debconf and ucf",
                            "      + d/postrm: handle Ubuntu pools via debconf and ucf",
                            "      + d/NEWS: Add information about default time sources moving out from",
                            "        chrony.conf to /etc/chrony/sources.d/ubuntu-ntp-pools.sources.",
                            "      + d/chrony.config: debconf script to handle Ubuntu pools",
                            "      + d/t/control, d/t/default-ubuntu-sources-behavior: new test to check the",
                            "        debconf behavior",
                            "    - Use Ubuntu NTS servers by default (LP #2084585):",
                            "      + d/conf.d/ubuntu-nts.conf: refer to the CA used to sign the NTS bootstrap",
                            "        server",
                            "      + d/nts-bootstrap-{,staging}-ubuntu.crt: CA certificate for the NTS",
                            "        bootstrap servers",
                            "      + d/chrony.install: install the NTS bootstrap CAs",
                            "      + d/ubuntu-ntp-pools.sources: use NTS by default",
                            "      + d/t/default-ubuntu-sources-behavior: update tests for NTS support",
                            "      + d/NEWS: add news entry about the NTS change",
                            "    - d/chrony.service: Allow real chronyd to send READY=1 via sd_notify in",
                            "      place of the chronyd-starter.sh wrapper.",
                            "    - d/control: Recommends: networkd-dispatcher (LP #2132159)",
                            "    - configure: switch sed separator from % to # to cope with dpkg",
                            "    - d/t/upstream-simulation-test-suite: revert update of clknetsim done in",
                            "      4.8-1 which redefines __open64_2 and breaks armhf build",
                            "  * Dropped:",
                            "    - d/t/helper-functions: show some logs in case of failure",
                            "      [In 4.8-3]",
                            "    - d/usr.sbin.chronyd: adjust apparmor rule so that chronyd is also allowed",
                            "      to access subdirectories of /run/chrony",
                            "      [In 4.8-3]",
                            ""
                        ],
                        "package": "chrony",
                        "version": "4.8-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154097
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:11:13 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/:",
                            "    - Bump dh compat to 14.",
                            "",
                            "  * debian/chrony.{if*,ppp*}:",
                            "    - Don't exit immediately if `chronyc onoffline` fails (Closes: #1011533)",
                            "    - Check for chronyd.sock instead of chronyd.pid. The existence of the PID",
                            "    file does not guarantee that the command socket is available.",
                            "",
                            "  * debian/control:",
                            "    - Bump Standards-Version to 4.7.4 (no changes required.)",
                            "",
                            "  * debian/copyright:",
                            "    - Update copyright year for debian/*.",
                            ""
                        ],
                        "package": "chrony",
                        "version": "4.8-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Vincent Blut <vincent.debian@free.fr>",
                        "date": "Mon, 22 Jun 2026 16:52:45 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Vincent Blut ]",
                            "  * debian/:",
                            "    - Format packaging files with `debputy reformat`.",
                            "",
                            "  * debian/control:",
                            "    - Use debputy's X-Style: black.",
                            "    - Bump Standards-Version to 4.7.3 (no changes required).",
                            "    - Fix lintian error 'invalid-arch-string-in-source-relation'.",
                            "",
                            "  * debian/patches/:",
                            "    - Drop skip-flaky-007-cmdmon-system-test.patch.",
                            "    - Cherry-pick test_-make-007-cmdmon-test-even-more-reliable.patch from",
                            "    upstream.",
                            "",
                            "  * debian/tests/:",
                            "    - Drop time-sources-from-dhcp-servers autopkgtest as it depends on",
                            "    the no longer available in testing isc-dhcp-{client,server} packages.",
                            "",
                            "  * debian/tests/upstream-simulation-test-suite:",
                            "    - No need to build clknetsim with extra CFLAGS on armel and armhf.",
                            "",
                            "  [ Andreas Hasenack ]",
                            "  * debian/tests/helper-functions:",
                            "    - Show some logs in case of failure.",
                            "",
                            "  * debian/usr.sbin.chronyd:",
                            "    - Adjust apparmor rule so that chronyd is also allowed to access",
                            "    subdirectories of /run/chrony.",
                            ""
                        ],
                        "package": "chrony",
                        "version": "4.8-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Vincent Blut <vincent.debian@free.fr>",
                        "date": "Thu, 26 Feb 2026 15:03:53 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "cloud-init",
                "from_version": {
                    "source_package_name": "cloud-init",
                    "source_package_version": "26.2~3gbd85f29d-0ubuntu1",
                    "version": "26.2~3gbd85f29d-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "cloud-init",
                    "source_package_version": "26.2-0ubuntu1",
                    "version": "26.2-0ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upstream snapshot based on 26.2.",
                            "    List of changes from upstream can be found at",
                            "    https://raw.githubusercontent.com/canonical/cloud-init/26.2/ChangeLog",
                            ""
                        ],
                        "package": "cloud-init",
                        "version": "26.2-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Chad Smith <chad.smith@canonical.com>",
                        "date": "Tue, 28 Jul 2026 17:20:23 -0600"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "cloud-init-base",
                "from_version": {
                    "source_package_name": "cloud-init",
                    "source_package_version": "26.2~3gbd85f29d-0ubuntu1",
                    "version": "26.2~3gbd85f29d-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "cloud-init",
                    "source_package_version": "26.2-0ubuntu1",
                    "version": "26.2-0ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upstream snapshot based on 26.2.",
                            "    List of changes from upstream can be found at",
                            "    https://raw.githubusercontent.com/canonical/cloud-init/26.2/ChangeLog",
                            ""
                        ],
                        "package": "cloud-init",
                        "version": "26.2-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Chad Smith <chad.smith@canonical.com>",
                        "date": "Tue, 28 Jul 2026 17:20:23 -0600"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "console-setup",
                "from_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.248ubuntu2",
                    "version": "1.248ubuntu2"
                },
                "to_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.248ubuntu3",
                    "version": "1.248ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild to pick up xkeyboard-config 2.48-1",
                            ""
                        ],
                        "package": "console-setup",
                        "version": "1.248ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Rik Mills <rikmills@kde.org>",
                        "date": "Mon, 14 Sep 2026 12:24:26 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "console-setup-linux",
                "from_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.248ubuntu2",
                    "version": "1.248ubuntu2"
                },
                "to_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.248ubuntu3",
                    "version": "1.248ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild to pick up xkeyboard-config 2.48-1",
                            ""
                        ],
                        "package": "console-setup",
                        "version": "1.248ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Rik Mills <rikmills@kde.org>",
                        "date": "Mon, 14 Sep 2026 12:24:26 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "coreutils",
                "from_version": {
                    "source_package_name": "coreutils-from",
                    "source_package_version": "0.0.0~ubuntu28",
                    "version": "9.5-1ubuntu2+0.0.0~ubuntu28"
                },
                "to_version": {
                    "source_package_name": "coreutils-from",
                    "source_package_version": "2ubuntu1",
                    "version": "9.10+2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2163383
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian experimental; remaining changes:",
                            "    - Build coreutils, coreutils-from-gnu",
                            "      + Only allow uutils and gnu coreutils",
                            "      + Remove Protected: yes from coreutils-from-gnu",
                            "      + Build-Depends on gnu-coreutils",
                            "  * Run update-links",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 13:23:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/rules: Bump gnu-coreutils version to 9.10",
                            "  * coreutils-from-uutils: Require 0.10",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Tue, 25 Aug 2026 13:20:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian experimental; remaining changes:",
                            "    - Specify minimum rust-coreutils version",
                            "    - Build coreutils, coreutils-from-gnu",
                            "    - Remove Protected: yes from coreutils-from-gnu",
                            "    - Only allow uutils and gnu coreutils",
                            "  * Dropped changes:",
                            "    - coreutils-from-uutils:",
                            "      + Break libdigest-sha3-perl",
                            "      + Pre-Depends gnu-coreutils",
                            "  * New changes:",
                            "    - Bump declared GNU coreutils version to 9.10",
                            "    - Bump rust-coreutils Pre-Depends to 0.10",
                            "    - Run update-links for Ubuntu",
                            "      + Install sha384sum in coreutils-from-busybox",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 13:06:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            "    - Drop coreutils, coreutils-from-gnu for unstable",
                            "  * Pick up all bug fixes from Ubuntu:",
                            "    - Remove extraneous diversions in postinst",
                            "    - diversions: Use the correct file paths for all files",
                            "    - uutils: Use /usr/lib/cargo/bin/coreutils/* as symlink targets",
                            "  * Misc:",
                            "    - Run update-links",
                            "    - d/control: Add Vcs-Git and Vcs-Browser fields",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Tue, 25 Aug 2026 12:43:42 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Initial version of swappable coreutils, for details see",
                            "    https://discourse.ubuntu.com/t/migration-to-rust-coreutils-in-25-10/59708",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "0.0.0",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Thu, 08 May 2025 12:17:09 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * uutils: Reinstate cp and df from rust-coreutils (LP: #2163383)",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "0.0.0~ubuntu29",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163383
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Thu, 13 Aug 2026 10:18:40 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "coreutils-from-uutils",
                "from_version": {
                    "source_package_name": "coreutils-from",
                    "source_package_version": "0.0.0~ubuntu28",
                    "version": "0.0.0~ubuntu28"
                },
                "to_version": {
                    "source_package_name": "coreutils-from",
                    "source_package_version": "2ubuntu1",
                    "version": "2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2163383
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian experimental; remaining changes:",
                            "    - Build coreutils, coreutils-from-gnu",
                            "      + Only allow uutils and gnu coreutils",
                            "      + Remove Protected: yes from coreutils-from-gnu",
                            "      + Build-Depends on gnu-coreutils",
                            "  * Run update-links",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 13:23:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/rules: Bump gnu-coreutils version to 9.10",
                            "  * coreutils-from-uutils: Require 0.10",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Tue, 25 Aug 2026 13:20:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian experimental; remaining changes:",
                            "    - Specify minimum rust-coreutils version",
                            "    - Build coreutils, coreutils-from-gnu",
                            "    - Remove Protected: yes from coreutils-from-gnu",
                            "    - Only allow uutils and gnu coreutils",
                            "  * Dropped changes:",
                            "    - coreutils-from-uutils:",
                            "      + Break libdigest-sha3-perl",
                            "      + Pre-Depends gnu-coreutils",
                            "  * New changes:",
                            "    - Bump declared GNU coreutils version to 9.10",
                            "    - Bump rust-coreutils Pre-Depends to 0.10",
                            "    - Run update-links for Ubuntu",
                            "      + Install sha384sum in coreutils-from-busybox",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 13:06:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            "    - Drop coreutils, coreutils-from-gnu for unstable",
                            "  * Pick up all bug fixes from Ubuntu:",
                            "    - Remove extraneous diversions in postinst",
                            "    - diversions: Use the correct file paths for all files",
                            "    - uutils: Use /usr/lib/cargo/bin/coreutils/* as symlink targets",
                            "  * Misc:",
                            "    - Run update-links",
                            "    - d/control: Add Vcs-Git and Vcs-Browser fields",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Tue, 25 Aug 2026 12:43:42 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Initial version of swappable coreutils, for details see",
                            "    https://discourse.ubuntu.com/t/migration-to-rust-coreutils-in-25-10/59708",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "0.0.0",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Thu, 08 May 2025 12:17:09 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * uutils: Reinstate cp and df from rust-coreutils (LP: #2163383)",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "0.0.0~ubuntu29",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163383
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Thu, 13 Aug 2026 10:18:40 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "debianutils",
                "from_version": {
                    "source_package_name": "debianutils",
                    "source_package_version": "5.23.2build1",
                    "version": "5.23.2build1"
                },
                "to_version": {
                    "source_package_name": "debianutils",
                    "source_package_version": "5.24",
                    "version": "5.24"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/control: Bump standards version from 4.7.2 to 4.7.4, bump",
                            "    debhelper-compat version from 13 to 14, and remove redundant",
                            "    field, Rules-Requires-Root: no.",
                            "  * acinclude.m4: Update DEBIANUTILS_VERSION to 5.24.",
                            "  * run-parts.c: Recognise short option for --debug (Closes: #1131363).",
                            "  * run-parts: Add options -A, --after and -B, --before for greater",
                            "    flexibility (Closes: #1131375).",
                            "  * d/tests/run-parts.test: Extend testing of run-parts for new options.",
                            ""
                        ],
                        "package": "debianutils",
                        "version": "5.24",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Ileana Dumitrescu <ileanadumitrescu95@gmail.com>",
                        "date": "Thu, 27 Aug 2026 17:54:35 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dhcpcd-base",
                "from_version": {
                    "source_package_name": "dhcpcd",
                    "source_package_version": "1:10.3.2-4",
                    "version": "1:10.3.2-4"
                },
                "to_version": {
                    "source_package_name": "dhcpcd",
                    "source_package_version": "1:10.3.2-6",
                    "version": "1:10.3.2-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * [autopkgtest]",
                            "    + Make the timesyncd test request an NTP server FQDN via DHCPv6 option 56.",
                            "    = Still request NTP server IPs via DHCPv4 option 42 and DHCPv6 option 31.",
                            ""
                        ],
                        "package": "dhcpcd",
                        "version": "1:10.3.2-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Martin-Éric Racine <martin-eric.racine@iki.fi>",
                        "date": "Mon, 27 Jul 2026 16:05:35 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * [autopkgtest]",
                            "    + Make the timesyncd test produce more usefull output.",
                            "  * [lintian-brush.conf]",
                            "    + Add override to maintain Bookworm compatibility.",
                            ""
                        ],
                        "package": "dhcpcd",
                        "version": "1:10.3.2-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Martin-Éric Racine <martin-eric.racine@iki.fi>",
                        "date": "Mon, 27 Jul 2026 12:01:25 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "distro-info",
                "from_version": {
                    "source_package_name": "distro-info",
                    "source_package_version": "1.15",
                    "version": "1.15"
                },
                "to_version": {
                    "source_package_name": "distro-info",
                    "source_package_version": "1.17",
                    "version": "1.17"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1012459
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * test: replace experimental by rc-buggy for distro-info-data 0.73",
                            ""
                        ],
                        "package": "distro-info",
                        "version": "1.17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Sun, 19 Jul 2026 16:17:03 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Format Python code with black 26.3",
                            "  * Perl library:",
                            "    - fix exporting convert_date",
                            "    - add get_all_series() function (Closes: #1141228, LP: #1012459)",
                            "  * Add autopkgtest for testing libdistro-info-perl",
                            "  * Bump Standards-Version to 4.7.4",
                            "  * Use pybuild-plugin-pyproject to build the Python module",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "distro-info",
                        "version": "1.16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            1012459
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Fri, 17 Jul 2026 00:35:41 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "distro-info-data",
                "from_version": {
                    "source_package_name": "distro-info-data",
                    "source_package_version": "0.73-1",
                    "version": "0.73-1"
                },
                "to_version": {
                    "source_package_name": "distro-info-data",
                    "source_package_version": "2026.08.20-1",
                    "version": "2026.08.20-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release:",
                            "    - Devuan experimental really is called experimental.",
                            ""
                        ],
                        "package": "distro-info-data",
                        "version": "2026.08.20-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Thu, 20 Aug 2026 10:36:09 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release:",
                            "    - Switch to calendar versioning (CalVer)",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "distro-info-data",
                        "version": "2026.07.30-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Thu, 30 Jul 2026 00:34:48 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ethtool",
                "from_version": {
                    "source_package_name": "ethtool",
                    "source_package_version": "1:7.0-1",
                    "version": "1:7.0-1"
                },
                "to_version": {
                    "source_package_name": "ethtool",
                    "source_package_version": "1:7.1-1",
                    "version": "1:7.1-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release: 7.1",
                            ""
                        ],
                        "package": "ethtool",
                        "version": "1:7.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Salvatore Bonaccorso <carnil@debian.org>",
                        "date": "Wed, 15 Jul 2026 09:46:17 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "findutils",
                "from_version": {
                    "source_package_name": "findutils",
                    "source_package_version": "4.10.0-4",
                    "version": "4.10.0-4"
                },
                "to_version": {
                    "source_package_name": "findutils",
                    "source_package_version": "4.11.0-2",
                    "version": "4.11.0-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "findutils",
                        "version": "4.11.0-2",
                        "urgency": "low",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Sat, 25 Jul 2026 10:38:50 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            ""
                        ],
                        "package": "findutils",
                        "version": "4.11.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Sat, 11 Jul 2026 11:33:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream GIT snapshot 375275acad9efd2bee6cde9794dfdb5b049e2fe4.",
                            "    (Generated with make dist.)",
                            "    + Drop cherry-picked patch.",
                            "  * [lintian] update b-d  libselinux1-dev libselinux-dev",
                            "  * [lintian] Drop redundant Rules-Requires-Root: no",
                            "  * Bump copyright year for debian/",
                            "  * Drop superfluous cme override. (fix.scanned.copyright)",
                            "  * Add copyright.template to be used as basis for cme update dpkg-copyright.",
                            "  * Update fill.copyright.blanks.yml.",
                            "  * Run",
                            "    cp debian/copyright.template debian/copyright && cme update dpkg-copyright",
                            "  * Use v14 debhelper-compat mode.",
                            "  * Move debian/findutils.NEWS to debian/NEWS.  apt-listchanges does not",
                            "    handle differing NEWS entries in binary packages built from the same",
                            "    source well.",
                            "  * Add debian/NEWS entry.",
                            ""
                        ],
                        "package": "findutils",
                        "version": "4.10.0+git20260625-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Sat, 27 Jun 2026 14:23:50 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "fuse3",
                "from_version": {
                    "source_package_name": "fuse3",
                    "source_package_version": "3.18.2-2",
                    "version": "3.18.2-2"
                },
                "to_version": {
                    "source_package_name": "fuse3",
                    "source_package_version": "3.18.3-1",
                    "version": "3.18.3-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "fuse3",
                        "version": "3.18.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sun, 13 Sep 2026 08:42:13 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gcc-16-base",
                "from_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.1.0-2ubuntu1",
                    "version": "16.1.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-2ubuntu1",
                    "version": "16.2.0-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158577
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Wed, 02 Sep 2026 10:52:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260902 from the gcc-16 branch.",
                            "    - Fix PR middle-end/127098, PR tree-optimization/127105,",
                            "      PR tree-optimization/127100, PR target/120681 (PPC),",
                            "      PR target/120528 (PPC), PR target/99293 (PPC), PR target/117487 (PPC),",
                            "      PR ada/125984, PR ipa/127023, PR target/126873 (RISCV),",
                            "      PR rtl-optimization/126426, PR target/127004 (AVR), PR middle-end/126939,",
                            "      PR target/126787 (x86), PR target/126513 (PPC),",
                            "      PR target/124629 (AArch64), PR tree-optimization/126925,",
                            "      PR tree-optimization/126650, PR tree-optimization/126926,",
                            "      PR tree-optimization/126534, PR target/126454 (RISCV),",
                            "      PR target/126334 (RISCV), PR target/126550 (RISCV),",
                            "      PR target/126676 (x86), PR target/126320 (x86), PR target/126450 (x86),",
                            "      PR target/126529 (x86), PR ada/127026, PR ada/127026, PR ada/126928,",
                            "      PR ada/126907, PR c++/127046, PR c++/124888, PR c++/126335,",
                            "      PR c++/124794, PR c++/126546, PR c++/124811, PR c++/126918,",
                            "      PR c++/126867, PR c++/126752, PR c++/126093, PR c++/126483,",
                            "      PR c++/126754, PR c++/126783, PR c++/124794, PR c++/125069,",
                            "      PR c++/124806, PR fortran/98573, PR fortran/105594, PR fortran/88632,",
                            "      PR fortran/104630, PR fortran/126872, PR fortran/110626,",
                            "      PR fortran/104048, PR target/125803 (PPC), PR libstdc++/118665,",
                            "      PR libstdc++/123510, PR libstdc++/122981, PR libstdc++/127006,",
                            "      PR libstdc++/126731, PR libstdc++/125981, PR libstdc++/126452,",
                            "      PR libstdc++/126849.",
                            "  * Only enable LRA by default on m68k for snapshot builds. Closes: #1143971.",
                            "  * Don't apply the SH LRA patches for snapshot builds. Closes: #1146439.",
                            "  * Disable usage stats for the build.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 02 Sep 2026 11:07:42 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 09 Aug 2026 06:21:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * GCC 16.2.0 release.",
                            "    - Fix PR target/126581 (x86), PR tree-optimization/126504,",
                            "      PR tree-optimization/126503, PR middle-end/126497,",
                            "      PR tree-optimization/126490, PR tree-optimization/126464,",
                            "      PR tree-optimization/126476, PR tree-optimization/126464,",
                            "      PR middle-end/126084, PR tree-optimization/126471, PR target/126446,",
                            "      PR middle-end/126410, PR tree-optimization/126457,",
                            "      PR tree-optimization/126404, PR tree-optimization/126404,",
                            "      PR target/126438 (PPC), PR target/126450 (x86), PR middle-end/126447,",
                            "      PR middle-end/126405, PR rtl-optimization/126184,",
                            "      PR rtl-optimization/126184, PR target/126429 (x86),",
                            "      PR tree-optimization/125396, PR tree-optimization/125290,",
                            "      PR target/126320 (x86), PR middle-end/126341, PR target/123625 (AArch64),",
                            "      PR target/121957 (AArch64), PR rtl-optimization/125209,",
                            "      PR middle-end/124637, PR tree-optimization/126171,",
                            "      PR tree-optimization/126225, PR tree-optimization/124663, PR ipa/125207,",
                            "      PR target/119210 (AArch64), PR target/105116, PR driver/1240,",
                            "      PR ada/126553, PR ada/126379, PR ada/126482, PR algol68/126330,",
                            "      PR c++/126309, PR c++/126508, PR c++/126420, PR c++/126423,",
                            "      PR c++/126343, PR c++/126406, PR c++/119343, PR c++/126209,",
                            "      PR c++/126310, PR c++/126280, PR c++/126215, PR driver/124058,",
                            "      PR fortran/125866, PR fortran/126386, PR fortran/126303,",
                            "      PR fortran/97592, PR fortran/125998, PR sanitizer/126307,",
                            "      PR libstdc++/122197, PR libstdc++/124854, PR libstdc++/116110,",
                            "      PR libstdc++/124853, PR libstdc++/116110, PR libstdc++/124852,",
                            "      PR libstdc++/124852, PR libstdc++/124851, PR libstdc++/123165.",
                            "  * Update to git 20260809 from the gcc-16 branch.",
                            "    - Fix PR target/126484 (MIPS), PR tree-optimization/126576,",
                            "      PR tree-optimization/126547, PR tree-optimization/126549,",
                            "      PR tree-optimization/126564, PR tree-optimization/126601,",
                            "      PR target/124948, PR tree-optimization/126464, PR preprocessor/125048,",
                            "      PR libstdc++/125200, PR c++/125591, PR c++/125601, PR c++/125680,",
                            "      PR c++/125541, PR fortran/126205, PR target/126667 (S390),",
                            "      PR fortran/125263.",
                            "",
                            "  [ Matthias Klose ]",
                            "  * Update libgcc-s, libcc1, libasan and libgcobol symbols files.",
                            "  * d/rules2: Use rva23u64 with zifencei extension for Ubuntu (Vladimir Petko).",
                            "    LP: #2158577.",
                            "  * d/rules: Reformat riscv64 extensions for Debian.",
                            "  * Configure with --enable-checking=release on every architecture.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * d/rules2: Use rva20u64 with zifencei extension for Debian.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2158577
                        ],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 09 Aug 2026 06:10:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 19 Jul 2026 14:16:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260719 from the gcc-16 branch.",
                            "    - Fix PR tree-optimization/126262, PR tree-optimization/126257,",
                            "      PR middle-end/126084, PR tree-optimization/120201,",
                            "      PR tree-optimization/126194, PR tree-optimization/126150,",
                            "      PR tree-optimization/125953, PR middle-end/125875,",
                            "      PR tree-optimization/125786, PR tree-optimization/125668,",
                            "      PR tree-optimization/125296, PR tree-optimization/126008,",
                            "      PR tree-optimization/125730, PR tree-optimization/125040,",
                            "      PR ipa/125121, PR ipa/124128, PR target/126054 (S390),",
                            "      PR target/126148 (x86), PR tree-optimization/125597,",
                            "      PR tree-optimization/125597, PR tree-optimization/125597,",
                            "      PR target/126081 (or1k), PR target/126049 (RISCV),",
                            "      PR target/126098 (x86), PR target/67459 (SH), PR target/122948 (SH),",
                            "      PR target/125972 (S390), PR rtl-optimization/125173,",
                            "      PR target/124908 (AArch64), PR target/125838 (AArch64),",
                            "      PR target/125883 (x86), PR target/125818 (AArch64),",
                            "      PR target/125469 (x86), PR target/125469 (x86), PR target/125949 (x86),",
                            "      PR target/125992 (S390), PR middle-end/125977, PR target/125628 (MIPS),",
                            "      PR target/125478 (RISCV), PR target/106895 (PPC), PR target/122665 (PPC),",
                            "      PR target/125670 (RISCV), PR middle-end/125621,",
                            "      PR target/125148 (AArch64), PR tree-optimization/125431,",
                            "      PR target/125795 (AArch64), PR tree-optimization/125501,",
                            "      PR tree-optimization/125776, PR tree-optimization/125774,",
                            "      PR target/120144 (MIPS), PR ipa/125699, PR tree-optimization/125419,",
                            "      PR tree-optimization/125652, PR tree-optimization/125686,",
                            "      PR tree-optimization/125646, PR tree-optimization/125553,",
                            "      PR tree-optimization/125545, PR tree-optimization/125502,",
                            "      PR tree-optimization/125477, PR target/124948, PR c/125072, PR c/125935,",
                            "      PR c/125604, PR c/123569, PR c/125252, PR c/124303, PR c/124985,",
                            "      PR c++/126057, PR c++/126036, PR c++/126007, PR c++/125674, PR c++/91155,",
                            "      PR c++/126066, PR c++/125901, PR c++/126031, PR c++/121552, PR c++/124584,",
                            "      PR c++/121094, PR c++/117259, PR c++/123536, PR c++/125900, PR c++/125334,",
                            "      PR c++/125768, PR c++/125939, PR c++/125745, PR c++/125408, PR c++/124978,",
                            "      PR c++/115314, PR c++/125889, PR c++/125764, PR c++/125759, PR c++/65271,",
                            "      PR c++/125770, PR fortran/126234, PR fortran/125172, PR fortran/126210,",
                            "      PR fortran/126170, PR fortran/126127, PR fortran/103367,",
                            "      PR fortran/126018, PR fortran/125051, PR fortran/125902,",
                            "      PR fortran/125902, PR fortran/60576, PR fortran/125430,",
                            "      PR fortran/125527, PR fortran/125535, PR fortran/125650,",
                            "      PR fortran/125481, PR fortran/125527, PR fortran/125528,",
                            "      PR fortran/125529, PR fortran/125530, PR fortran/125531,",
                            "      PR fortran/125534, PR fortran/125535, PR lto/125257, PR libgcc/123976,",
                            "      PR target/125752 (AVR), PR libfortran/126116, PR libstdc++/126111,",
                            "      PR libstdc++/125956, PR libstdc++/118158, PR libstdc++/125228,",
                            "      PR libstdc++/125890.",
                            "  * Let the ada build fail on an alihash mismatch, if fail_on_alihash_mismatch",
                            "    is enabled.",
                            "  * Enable Modula-2 on powerpc and ppc64. Closes: #1141560, #1141596.",
                            "  * Enable LRA by default on m68k for snapshot builds (Adrian Glaubitz).",
                            "    Addresses: #1142039.",
                            "  * Disable running tests on Debian/riscv64 for meaningful build times.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 19 Jul 2026 13:28:39 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gettext-base",
                "from_version": {
                    "source_package_name": "gettext",
                    "source_package_version": "0.23.2-1",
                    "version": "0.23.2-1"
                },
                "to_version": {
                    "source_package_name": "gettext",
                    "source_package_version": "1.0-3",
                    "version": "1.0-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Change python3 build-dependency to be python3:any for cross-builds.",
                            "    Thanks to Helmut Grohne. Closes: #1141301.",
                            ""
                        ],
                        "package": "gettext",
                        "version": "1.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Santiago Vila <sanvila@debian.org>",
                        "date": "Thu, 02 Jul 2026 20:55:00 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip test-getaddrinfo. Closes: #1141154.",
                            "  * Do not pass XFAIL_TESTS to dh_auto_test anymore.",
                            "  * Drop unused lintian override.",
                            ""
                        ],
                        "package": "gettext",
                        "version": "1.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Santiago Vila <sanvila@debian.org>",
                        "date": "Tue, 30 Jun 2026 18:20:00 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release. Closes: #1101483.",
                            "  * Drop old patches, not needed anymore.",
                            "  * Enable all tests again.",
                            "  * Add python3 to Recommends, required by new program spit.",
                            "  * Update some lintian overrides.",
                            ""
                        ],
                        "package": "gettext",
                        "version": "1.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Santiago Vila <sanvila@debian.org>",
                        "date": "Tue, 16 Jun 2026 16:40:00 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Apply patch from Bruno Haible to allow building with glibc 2.43.",
                            "  * Skip test-pr_xid_continue and test-pr_xid_start (libunistring 1.4).",
                            "  * Refresh signing key.",
                            "  * Update standards-version.",
                            ""
                        ],
                        "package": "gettext",
                        "version": "0.26-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Santiago Vila <sanvila@debian.org>",
                        "date": "Thu, 21 May 2026 20:45:00 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Temporarily disable tests broken by libunistring 1.4.",
                            "  * Drop references to kfreebsd-any (lintian error).",
                            "  * Update standards-version.",
                            ""
                        ],
                        "package": "gettext",
                        "version": "0.23.2-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Santiago Vila <sanvila@debian.org>",
                        "date": "Sun, 22 Mar 2026 10:55:00 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gir1.2-girepository-3.0",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.88.1-2",
                    "version": "2.88.1-2"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.90.0-1",
                    "version": "2.90.0-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.90.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Thu, 10 Sep 2026 12:07:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Re-upload with orig tarball, no source changes",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 19:33:06 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes a main-loop regression in 2.89.3 (mutter#4994 upstream)",
                            "  * d/patches: Drop patches that were part of the upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 18:52:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Fri, 21 Aug 2026 16:37:11 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from unstable",
                            "    - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "      d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "      Add patches from upstream (to be released in 2.89.4) to address",
                            "      an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "      and fix a related test failure on minimal systems",
                            "      (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            "  * d/p/workarounds: Mark memory-monitor-psi tests as flaky",
                            "    (Mitigates: #1143197, #1143241)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-4",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 21:28:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon McVittie ]",
                            "  * Merge packaging from unstable",
                            "    - d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "      by ensuring that user-session-migration gets removed rather than",
                            "      making libglib2.0-0t64 be reinstalled",
                            "  * Drop patches added by 2.88.3-2, already part of 2.89.x",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 06 Aug 2026 14:23:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate",
                            "    previous changelog entry",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * debian/libglib2.0-0t64.symbols: Add new symbols",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 15:55:39 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes possible integer underflow when parsing D-Bus introspection XML",
                            "      (CVE-2026-58016, Closes: #1141316)",
                            "    - Fixes resource exhaustion if a malicious client can contact a GDBusServer",
                            "      (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p: Refresh patches",
                            "  * d/libglib2.0-0t64.symbols: Add new symbol",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.2-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Fri, 24 Jul 2026 18:58:44 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "    d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "    Add patches from upstream (to be released in 2.89.4) to address",
                            "    an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "    and fix a related test failure on minimal systems",
                            "    (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 10:10:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport patches from 2.89.0 to harden D-Bus introspection parsing",
                            "    - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,",
                            "      d/p/tests-Improve-D-Bus-introspection-test-paths.patch,",
                            "      d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,",
                            "      d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:",
                            "      Avoid a possible integer underflow if parsing malformed D-Bus",
                            "      introspection XML sent by a malicious service",
                            "      (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)",
                            "  * d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "    by ensuring that user-session-migration gets removed rather than",
                            "    making libglib2.0-0t64 be reinstalled",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:22:30 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "    - Fixes resource exhaustion if a malicious client can contact a",
                            "      GDBusServer (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/control, d/gbp.conf: Use debian/forky branch",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:13:54 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "  * d/watch: Only watch for stable (even-numbered) branches",
                            "  * d/gbp.conf: Use upstream/2.88.x branch.",
                            "    Initial 2.89.x versions have been released upstream.",
                            "  * d/control: Move Build-Profiles from libglib2.0-0t64 back to",
                            "    libglib2.0-tests. This was mistakenly moved by `cme fix dpkg`",
                            "    in the previous upload.",
                            "  * Ignore another Lintian false positive in the test data",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Thu, 25 Jun 2026 19:05:13 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gir1.2-glib-2.0",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.88.1-2",
                    "version": "2.88.1-2"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.90.0-1",
                    "version": "2.90.0-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.90.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Thu, 10 Sep 2026 12:07:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Re-upload with orig tarball, no source changes",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 19:33:06 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes a main-loop regression in 2.89.3 (mutter#4994 upstream)",
                            "  * d/patches: Drop patches that were part of the upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 18:52:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Fri, 21 Aug 2026 16:37:11 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from unstable",
                            "    - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "      d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "      Add patches from upstream (to be released in 2.89.4) to address",
                            "      an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "      and fix a related test failure on minimal systems",
                            "      (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            "  * d/p/workarounds: Mark memory-monitor-psi tests as flaky",
                            "    (Mitigates: #1143197, #1143241)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-4",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 21:28:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon McVittie ]",
                            "  * Merge packaging from unstable",
                            "    - d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "      by ensuring that user-session-migration gets removed rather than",
                            "      making libglib2.0-0t64 be reinstalled",
                            "  * Drop patches added by 2.88.3-2, already part of 2.89.x",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 06 Aug 2026 14:23:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate",
                            "    previous changelog entry",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * debian/libglib2.0-0t64.symbols: Add new symbols",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 15:55:39 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes possible integer underflow when parsing D-Bus introspection XML",
                            "      (CVE-2026-58016, Closes: #1141316)",
                            "    - Fixes resource exhaustion if a malicious client can contact a GDBusServer",
                            "      (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p: Refresh patches",
                            "  * d/libglib2.0-0t64.symbols: Add new symbol",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.2-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Fri, 24 Jul 2026 18:58:44 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "    d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "    Add patches from upstream (to be released in 2.89.4) to address",
                            "    an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "    and fix a related test failure on minimal systems",
                            "    (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 10:10:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport patches from 2.89.0 to harden D-Bus introspection parsing",
                            "    - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,",
                            "      d/p/tests-Improve-D-Bus-introspection-test-paths.patch,",
                            "      d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,",
                            "      d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:",
                            "      Avoid a possible integer underflow if parsing malformed D-Bus",
                            "      introspection XML sent by a malicious service",
                            "      (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)",
                            "  * d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "    by ensuring that user-session-migration gets removed rather than",
                            "    making libglib2.0-0t64 be reinstalled",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:22:30 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "    - Fixes resource exhaustion if a malicious client can contact a",
                            "      GDBusServer (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/control, d/gbp.conf: Use debian/forky branch",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:13:54 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "  * d/watch: Only watch for stable (even-numbered) branches",
                            "  * d/gbp.conf: Use upstream/2.88.x branch.",
                            "    Initial 2.89.x versions have been released upstream.",
                            "  * d/control: Move Build-Profiles from libglib2.0-0t64 back to",
                            "    libglib2.0-tests. This was mistakenly moved by `cme fix dpkg`",
                            "    in the previous upload.",
                            "  * Ignore another Lintian false positive in the test data",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Thu, 25 Jun 2026 19:05:13 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gnu-coreutils",
                "from_version": {
                    "source_package_name": "coreutils",
                    "source_package_version": "9.7-3ubuntu2",
                    "version": "9.7-3ubuntu2"
                },
                "to_version": {
                    "source_package_name": "coreutils",
                    "source_package_version": "9.10-1ubuntu2",
                    "version": "9.10-1ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-56391",
                        "url": "https://ubuntu.com/security/CVE-2026-56391",
                        "cve_description": "GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.  When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.   This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-24 09:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153293
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-56391",
                                "url": "https://ubuntu.com/security/CVE-2026-56391",
                                "cve_description": "GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.  When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.   This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-24 09:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: out‑of‑bounds read in uniq",
                            "    - debian/patches/CVE-2026-56391.patch: uniq: fix read overrun with -w in",
                            "      src/uniq.c, tests/uniq/uniq.pl.",
                            "    - CVE-2026-56391",
                            ""
                        ],
                        "package": "coreutils",
                        "version": "9.10-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 11:06:22 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable. Remaining changes:",
                            "    - Rename the binary package to gnu-coreutils and build with 'gnu' prefix",
                            "    - Run the autopkgtest against both Rust and GNU versions.",
                            "      Disable the failing nanosecond test case for stat for Rust, and",
                            "      re-enable it for the GNU version only.  Some specific care had to be",
                            "      taken around swapping the default provider: The coreutils-from-uutils",
                            "      are Protected: yes, so we need to remove them inside the test script.",
                            "    - d/rules:",
                            "     +  Allow cross-build and enable tests when not cross-building",
                            "    - d/p/72_id_checkngroups.patch: refreshed",
                            "    - debian/patches/80_fedora_sysinfo.dpatch",
                            "      + make 'uname -i -p' return the real processor/hardware, instead of",
                            "        unknown. Patch cherry-picked from Fedora 12 (original:",
                            "        coreutils-4.5.3-sysinfo.patch, from the coreutils-7.6-5.src.rpm).",
                            "    - debian/patches/99_float_endian_detection: Fix detection of floating",
                            "      point endianness.",
                            "    - d/p/treat-devtmpfs-and-squashfs-as-dummy-filesystems.patch:",
                            "      + Avoid displaying snaps in output from df and other tools, by excluding",
                            "        display of squashfs filesystems.",
                            "      + Exclude devtmpfs filesystems in output from df and other tools since",
                            "        it is a dummy filesystem.",
                            "      (refreshed)",
                            "    - d/p/cp-n.diff: skip tests/cp/cp-i.sh upstream test",
                            "      The behavior of cp -n is different in Debian than in upstream, and this",
                            "      test assumes upstream behavior of -n, and how it interacts with -i.",
                            "      (refreshed)",
                            "  * Dropped (upstreamed) changes:",
                            "    - d/p/lp2137373-skip-dirent-inode-sorting-for-lustre.patch:",
                            "      Fix slow performance of 'du' on large directories (>= 10K files) on",
                            "      Lustre filesystems by skipping inode sorting. The default behaviour of",
                            "      sorting dirents by inode numbers negatively impacts performance on",
                            "      Lustre because it interferes with Lustre's ability to prefetch file",
                            "      metadata via statahead. (LP: 2137373)",
                            "  * Rename two debian/coreutils -> debian/gnu-coreutils forgotten files",
                            "  * (Closes LP: #2153293)",
                            ""
                        ],
                        "package": "coreutils",
                        "version": "9.10-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153293
                        ],
                        "author": "Pierre-Elliott Bécue <peb@debian.org>",
                        "date": "Mon, 20 Jul 2026 23:29:40 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            "    - cksum now supports sha3",
                            "  * update to policy 4.7.3 (minor changes)",
                            ""
                        ],
                        "package": "coreutils",
                        "version": "9.10-1",
                        "urgency": "low",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Stone <mstone@debian.org>",
                        "date": "Thu, 26 Feb 2026 16:59:53 -0500"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gzip",
                "from_version": {
                    "source_package_name": "gzip",
                    "source_package_version": "1.14-1~exp2ubuntu2",
                    "version": "1.14-1~exp2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "gzip",
                    "source_package_version": "1.14-1~exp2ubuntu3",
                    "version": "1.14-1~exp2ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-41991",
                        "url": "https://ubuntu.com/security/CVE-2026-41991",
                        "cve_description": "GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.  This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-29 12:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-41992",
                        "url": "https://ubuntu.com/security/CVE-2026-41992",
                        "cve_description": "GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.  This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-29 12:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-41991",
                                "url": "https://ubuntu.com/security/CVE-2026-41991",
                                "cve_description": "GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.  This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-29 12:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-41992",
                                "url": "https://ubuntu.com/security/CVE-2026-41992",
                                "cve_description": "GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.  This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-29 12:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: insecure temp file handling",
                            "    - debian/patches/CVE-2026-41991.patch: gzexe: use -C if lacking mktemp in",
                            "      gzexe.in, zdiff.in.",
                            "    - CVE-2026-41991",
                            "  * SECURITY UPDATE: overflow in LZH decompression logic",
                            "    - debian/patches/CVE-2026-41992.patch: gzip: don’t mishandle .lzh after .Z",
                            "      in unlzh.c.",
                            "    - CVE-2026-41992",
                            ""
                        ],
                        "package": "gzip",
                        "version": "1.14-1~exp2ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Fri, 03 Jul 2026 07:50:04 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "iproute2",
                "from_version": {
                    "source_package_name": "iproute2",
                    "source_package_version": "6.19.0-1ubuntu1",
                    "version": "6.19.0-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "iproute2",
                    "source_package_version": "6.19.0-1ubuntu2",
                    "version": "6.19.0-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2147525
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Modify tc/tbf and tc/htb to allow 64 bit burst parameter (LP: #2147525)",
                            "    - /d/p/lp2147525-1-tc-tbf-enable-64-bit-burst.patch",
                            "    - /d/p/lp2147525-2-tc-htb-enable-64-bit-burst.patch",
                            ""
                        ],
                        "package": "iproute2",
                        "version": "6.19.0-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2147525
                        ],
                        "author": "Ioana Lazea <ioana.lazea@canonical.com>",
                        "date": "Fri, 24 Apr 2026 11:42:05 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "kbd",
                "from_version": {
                    "source_package_name": "kbd",
                    "source_package_version": "2.7.1-2ubuntu2",
                    "version": "2.7.1-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "kbd",
                    "source_package_version": "2.9.0-1ubuntu1",
                    "version": "2.9.0-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153310
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153310). Remaining changes:",
                            "    - Add setfont, kbd_mode, and loadkeys to initramfs for console-setup.",
                            "    - Change loadkeys to find any console not in raw mode when invoked",
                            "      without an explicit console parameter, in case the foreground console",
                            "      is in raw mode.",
                            "    - Use ckbcomp to get the keyboard layout if other data files are not",
                            "      available.",
                            "    - debian/control: Depend on console-setup | console-setup-mini, since",
                            "      console-setup-mini also Depends on kbd now through console-setup-linux.",
                            "  * Dropped changes:",
                            "    - Add setvtrgb to kbd-udeb. Ubuntu does not build udebs any more.",
                            ""
                        ],
                        "package": "kbd",
                        "version": "2.9.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153310
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Wed, 15 Jul 2026 13:02:07 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "",
                            "  [ Andreas Henriksson ]",
                            "  * New upstream release.",
                            "  * Drop debian/patches/ppc-keycode0-test.patch, fixed upstream.",
                            "  * Drop debian/patches/Support-KT_DEAD2-diacritics.patch, fixed upstream.",
                            "",
                            "  [ Michael Biebl ]",
                            "  * kbd-udeb: Move binaries to canonical location in /usr. (Closes: #1122352)",
                            ""
                        ],
                        "package": "kbd",
                        "version": "2.9.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Henriksson <andreas@fatal.se>",
                        "date": "Sun, 14 Dec 2025 10:38:41 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "keyboard-configuration",
                "from_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.248ubuntu2",
                    "version": "1.248ubuntu2"
                },
                "to_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.248ubuntu3",
                    "version": "1.248ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild to pick up xkeyboard-config 2.48-1",
                            ""
                        ],
                        "package": "console-setup",
                        "version": "1.248ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Rik Mills <rikmills@kde.org>",
                        "date": "Mon, 14 Sep 2026 12:24:26 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "kmod",
                "from_version": {
                    "source_package_name": "kmod",
                    "source_package_version": "34.2-2ubuntu2",
                    "version": "34.2-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "kmod",
                    "source_package_version": "34.2-2ubuntu3",
                    "version": "34.2-2ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "kmod",
                        "version": "34.2-2ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 14:28:11 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libapparmor1",
                "from_version": {
                    "source_package_name": "apparmor",
                    "source_package_version": "5.0.1-0ubuntu1",
                    "version": "5.0.1-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "apparmor",
                    "source_package_version": "6.0.0~alpha1-0ubuntu1",
                    "version": "6.0.0~alpha1-0ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2152079
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * debian/control: add iwyu, pytest, pytest-xdist to Build-Depends",
                            "  * Drop patches that were applied upstream:",
                            "    - d/p/u/0001-parser-add-more-reserved-mediation-classes.patch",
                            "  * Refresh patches for new release:",
                            "    - d/p/u/0007-Set-parser-network.h-ip_conds-ptrs-to-null-in-its-fr.patch",
                            "  * Update patches for new release:",
                            "    - d/p/u/profiles-use-coreutils-tunable.patch",
                            "    - d/p/u/profiles_add_more_consoles_workaround.patch",
                            "    - d/p/u/profiles_disable_free.patch",
                            "  * Add patches to install a confining loupe profile:",
                            "    - d/p/u/0001-profiles-add-a-glycin-tunable.patch",
                            "    - d/p/u/0002-profiles-begin-adding-abstractions-for-the-XDG-Deskt.patch",
                            "    - d/p/u/0003-profiles-rewrite-the-loupe-profile.patch",
                            "  * debian/apparmor.install: add glycin tunables",
                            ""
                        ],
                        "package": "apparmor",
                        "version": "6.0.0~alpha1-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ryan Lee <ryan.lee@canonical.com>",
                        "date": "Thu, 20 Aug 2026 12:05:00 -0700"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Update patches to apply to new release:",
                            "    - d/p/u/profiles_disable_curl.patch",
                            "  * Add patch to fix transmission-gtk file chooser (LP: #2152079):",
                            "    - d/p/u/profiles-add-file-chooser-rules-to-abstractions-trans.patch",
                            ""
                        ],
                        "package": "apparmor",
                        "version": "5.0.2-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2152079
                        ],
                        "author": "Ryan Lee <ryan.lee@canonical.com>",
                        "date": "Mon, 13 Jul 2026 10:43:46 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libapt-pkg7.0",
                "from_version": {
                    "source_package_name": "apt",
                    "source_package_version": "3.2.0",
                    "version": "3.2.0"
                },
                "to_version": {
                    "source_package_name": "apt",
                    "source_package_version": "3.3.3",
                    "version": "3.3.3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158000,
                    2150631
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  This release introduces initial interactive help output for apt(8)",
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * cmdline: add declarative option help printer",
                            "  * mirror: Scale fan-out with the square root of the number of files",
                            "",
                            "  [ Simon Johnsson ]",
                            "  * cmdline: add command-specific help texts",
                            "",
                            "  [ Zara Grigoryan ]",
                            "  * cmdline: render declarative options in command help",
                            "  * cmdline: mark option descriptions for translation",
                            "  * cmdline: refine command-specific help rendering",
                            "",
                            "  [ Andriy Pysyk ]",
                            "  * Fix fuzzy entries in Ukrainian translation for APT 3.3.2 + terminology consistency improvements",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Fri, 14 Aug 2026 17:51:56 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * Document and test combined `build-dep --arch-only --indep-only`",
                            "  * ftparchive: fix heap overflow in ContentsExtract::DoItem",
                            "  * deb: guard against unsigned underflow when trimming control newlines",
                            "  * gpgv: don't advance past the null terminator in PushEntryWithKeyID",
                            "  * ftparchive: replace ContentsExtract's manual buffer with std::vector<char>",
                            "  * test: Limit valgrind to 1024 open files",
                            "  * hashes: Fix lingering OpenSSL error (Closes: #1140227)",
                            "  * test: use `gnurm` where available",
                            "  * Convert command-line option-parsing to declarative format",
                            "  * Fix crash when an aux file request is redirected",
                            "  * Reply to aux requests with the original URI if redirected",
                            "  * debian/apt-daily.service: Add timeouts.",
                            "    30 mins for apt-daily.service, 12 hours for apt-daily-upgrade.service",
                            "    should be sufficient. (LP: #2158000)",
                            "",
                            "  [ наб ]",
                            "  * apt-transport-https(1): document host-specific SSLCert, SSLKey, Verify-Host with host:: instead of ::host",
                            "",
                            "  [ David Kalnischkies ]",
                            "  * aptwebserver: Refuse client immediately on TLS handshake",
                            "",
                            "  [ Américo Monteiro ]",
                            "  * Portuguese manpages translation update (Closes: #1133965)",
                            "",
                            "  [ Frans Spiesschaert ]",
                            "  * Dutch program translation update (Closes: #1135221)",
                            "  * Dutch manpages translation update (Closes: #1135222)",
                            "",
                            "  [ Remus-Gabriel Chelu ]",
                            "  * Romanian program translation update (Closes: #1139336)",
                            "",
                            "  [ Mark Atwood ]",
                            "  * hashes: include <span> for std::span",
                            "  * hashes: don't crash on an unavailable digest",
                            "  * test: exercise hashes with a disabled digest",
                            "",
                            "  [ dongshengyuan ]",
                            "  * Fix installing a deb with colon in path",
                            "",
                            "  [ Simon Johnsson ]",
                            "  * apt-pkg: rename \"OpenPGP signature verification failed\" to \"Signature verification failed\"",
                            "",
                            "  [ Andreas Noteng ]",
                            "  * Norwegian Bokmål (nb) translation update",
                            "",
                            "  [ Temuri Doghonadze ]",
                            "  * po: Add Georgian translation",
                            "",
                            "  [ Andriy Pysyk ]",
                            "  * Update Ukrainian translation for 3.3.1",
                            "",
                            "  [ Mikhail Khachayants ]",
                            "  * srvrec: reject res_query answers bigger than our buffer",
                            "",
                            "  [ Ramesh Adhikari ]",
                            "  * tagfile: fix unbounded backward scan in Fill()'s trailing-newline check",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2158000
                        ],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 22:43:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * solver3: Follow installed Suggests earlier",
                            "  * Fix `noexcept` as pointed out by gcc",
                            "  * Fix wrongful std::make_unique conversion",
                            "  * Fix regression in dirstream (Closes: #1136441)",
                            "",
                            "  [ Varun Varma ]",
                            "  * Warn if auth.conf is unreadable (LP: #2150631)",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2150631
                        ],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Sun, 17 May 2026 21:21:50 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Anders Kaseorg ]",
                            "  * Fix Phased-Update-Percentage probability mistake",
                            "",
                            "  [ Simon Johnsson ]",
                            "  * Scale history-list to screen width",
                            "  * Optimize ShortenCommand",
                            "  * Change GetKindString to not use .data() call",
                            "",
                            "  [ Julian Andres Klode ]",
                            "  * Drop warning about unstable CLI interface.",
                            "    A specific CLI version can now be requested using the --cli-version",
                            "    flag, and old versions can be deprecated on a reasonable cadence.",
                            "    Therefore, a warning is no longer necessary.",
                            "  * hashes: Use std::span instead of std::basic_string_view",
                            "  * sources.list(5): Document Contact/Bugs/Description fields.",
                            "    Thanks to josch for the suggestion",
                            "  * Require sqv for builds on supported archs and !pkg.apt.nosqv",
                            "",
                            "  [ Zheyu Shen ]",
                            "  * fix apt patterns parsing bug for pre-depends",
                            "",
                            "  [ Herman Semenoff ]",
                            "  * apt: funcs called with a string literal consisting of a single character",
                            "  * apt-pkg/acquire: use range based for loop C++17",
                            "  * apt: push to emplace C++11 if possible",
                            "  * apt: modernize to make_unique C++17",
                            "  * apt-pkg: methods: fixed many minor memleaks",
                            "",
                            "  [ наб ]",
                            "  * sources.list(5): th[r]ough typo",
                            "",
                            "  [ Sebastian Krzyszkowiak ]",
                            "  * acquire-item: Fix up the error message on committing aborted transaction",
                            "  * pkgAcqMetaClearSig: Abort transaction when pkgAcquire::Run has been cancelled",
                            "    (Closes: #1078608)",
                            "  * pkgAcqMetaBase: Commit InRelease after other transaction items",
                            "    (Closes: #1078608)",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Fix bug reference",
                            ""
                        ],
                        "package": "apt",
                        "version": "3.3.0",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Fri, 01 May 2026 18:40:52 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libatomic1",
                "from_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.1.0-2ubuntu1",
                    "version": "16.1.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-2ubuntu1",
                    "version": "16.2.0-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158577
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Wed, 02 Sep 2026 10:52:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260902 from the gcc-16 branch.",
                            "    - Fix PR middle-end/127098, PR tree-optimization/127105,",
                            "      PR tree-optimization/127100, PR target/120681 (PPC),",
                            "      PR target/120528 (PPC), PR target/99293 (PPC), PR target/117487 (PPC),",
                            "      PR ada/125984, PR ipa/127023, PR target/126873 (RISCV),",
                            "      PR rtl-optimization/126426, PR target/127004 (AVR), PR middle-end/126939,",
                            "      PR target/126787 (x86), PR target/126513 (PPC),",
                            "      PR target/124629 (AArch64), PR tree-optimization/126925,",
                            "      PR tree-optimization/126650, PR tree-optimization/126926,",
                            "      PR tree-optimization/126534, PR target/126454 (RISCV),",
                            "      PR target/126334 (RISCV), PR target/126550 (RISCV),",
                            "      PR target/126676 (x86), PR target/126320 (x86), PR target/126450 (x86),",
                            "      PR target/126529 (x86), PR ada/127026, PR ada/127026, PR ada/126928,",
                            "      PR ada/126907, PR c++/127046, PR c++/124888, PR c++/126335,",
                            "      PR c++/124794, PR c++/126546, PR c++/124811, PR c++/126918,",
                            "      PR c++/126867, PR c++/126752, PR c++/126093, PR c++/126483,",
                            "      PR c++/126754, PR c++/126783, PR c++/124794, PR c++/125069,",
                            "      PR c++/124806, PR fortran/98573, PR fortran/105594, PR fortran/88632,",
                            "      PR fortran/104630, PR fortran/126872, PR fortran/110626,",
                            "      PR fortran/104048, PR target/125803 (PPC), PR libstdc++/118665,",
                            "      PR libstdc++/123510, PR libstdc++/122981, PR libstdc++/127006,",
                            "      PR libstdc++/126731, PR libstdc++/125981, PR libstdc++/126452,",
                            "      PR libstdc++/126849.",
                            "  * Only enable LRA by default on m68k for snapshot builds. Closes: #1143971.",
                            "  * Don't apply the SH LRA patches for snapshot builds. Closes: #1146439.",
                            "  * Disable usage stats for the build.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 02 Sep 2026 11:07:42 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 09 Aug 2026 06:21:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * GCC 16.2.0 release.",
                            "    - Fix PR target/126581 (x86), PR tree-optimization/126504,",
                            "      PR tree-optimization/126503, PR middle-end/126497,",
                            "      PR tree-optimization/126490, PR tree-optimization/126464,",
                            "      PR tree-optimization/126476, PR tree-optimization/126464,",
                            "      PR middle-end/126084, PR tree-optimization/126471, PR target/126446,",
                            "      PR middle-end/126410, PR tree-optimization/126457,",
                            "      PR tree-optimization/126404, PR tree-optimization/126404,",
                            "      PR target/126438 (PPC), PR target/126450 (x86), PR middle-end/126447,",
                            "      PR middle-end/126405, PR rtl-optimization/126184,",
                            "      PR rtl-optimization/126184, PR target/126429 (x86),",
                            "      PR tree-optimization/125396, PR tree-optimization/125290,",
                            "      PR target/126320 (x86), PR middle-end/126341, PR target/123625 (AArch64),",
                            "      PR target/121957 (AArch64), PR rtl-optimization/125209,",
                            "      PR middle-end/124637, PR tree-optimization/126171,",
                            "      PR tree-optimization/126225, PR tree-optimization/124663, PR ipa/125207,",
                            "      PR target/119210 (AArch64), PR target/105116, PR driver/1240,",
                            "      PR ada/126553, PR ada/126379, PR ada/126482, PR algol68/126330,",
                            "      PR c++/126309, PR c++/126508, PR c++/126420, PR c++/126423,",
                            "      PR c++/126343, PR c++/126406, PR c++/119343, PR c++/126209,",
                            "      PR c++/126310, PR c++/126280, PR c++/126215, PR driver/124058,",
                            "      PR fortran/125866, PR fortran/126386, PR fortran/126303,",
                            "      PR fortran/97592, PR fortran/125998, PR sanitizer/126307,",
                            "      PR libstdc++/122197, PR libstdc++/124854, PR libstdc++/116110,",
                            "      PR libstdc++/124853, PR libstdc++/116110, PR libstdc++/124852,",
                            "      PR libstdc++/124852, PR libstdc++/124851, PR libstdc++/123165.",
                            "  * Update to git 20260809 from the gcc-16 branch.",
                            "    - Fix PR target/126484 (MIPS), PR tree-optimization/126576,",
                            "      PR tree-optimization/126547, PR tree-optimization/126549,",
                            "      PR tree-optimization/126564, PR tree-optimization/126601,",
                            "      PR target/124948, PR tree-optimization/126464, PR preprocessor/125048,",
                            "      PR libstdc++/125200, PR c++/125591, PR c++/125601, PR c++/125680,",
                            "      PR c++/125541, PR fortran/126205, PR target/126667 (S390),",
                            "      PR fortran/125263.",
                            "",
                            "  [ Matthias Klose ]",
                            "  * Update libgcc-s, libcc1, libasan and libgcobol symbols files.",
                            "  * d/rules2: Use rva23u64 with zifencei extension for Ubuntu (Vladimir Petko).",
                            "    LP: #2158577.",
                            "  * d/rules: Reformat riscv64 extensions for Debian.",
                            "  * Configure with --enable-checking=release on every architecture.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * d/rules2: Use rva20u64 with zifencei extension for Debian.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2158577
                        ],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 09 Aug 2026 06:10:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 19 Jul 2026 14:16:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260719 from the gcc-16 branch.",
                            "    - Fix PR tree-optimization/126262, PR tree-optimization/126257,",
                            "      PR middle-end/126084, PR tree-optimization/120201,",
                            "      PR tree-optimization/126194, PR tree-optimization/126150,",
                            "      PR tree-optimization/125953, PR middle-end/125875,",
                            "      PR tree-optimization/125786, PR tree-optimization/125668,",
                            "      PR tree-optimization/125296, PR tree-optimization/126008,",
                            "      PR tree-optimization/125730, PR tree-optimization/125040,",
                            "      PR ipa/125121, PR ipa/124128, PR target/126054 (S390),",
                            "      PR target/126148 (x86), PR tree-optimization/125597,",
                            "      PR tree-optimization/125597, PR tree-optimization/125597,",
                            "      PR target/126081 (or1k), PR target/126049 (RISCV),",
                            "      PR target/126098 (x86), PR target/67459 (SH), PR target/122948 (SH),",
                            "      PR target/125972 (S390), PR rtl-optimization/125173,",
                            "      PR target/124908 (AArch64), PR target/125838 (AArch64),",
                            "      PR target/125883 (x86), PR target/125818 (AArch64),",
                            "      PR target/125469 (x86), PR target/125469 (x86), PR target/125949 (x86),",
                            "      PR target/125992 (S390), PR middle-end/125977, PR target/125628 (MIPS),",
                            "      PR target/125478 (RISCV), PR target/106895 (PPC), PR target/122665 (PPC),",
                            "      PR target/125670 (RISCV), PR middle-end/125621,",
                            "      PR target/125148 (AArch64), PR tree-optimization/125431,",
                            "      PR target/125795 (AArch64), PR tree-optimization/125501,",
                            "      PR tree-optimization/125776, PR tree-optimization/125774,",
                            "      PR target/120144 (MIPS), PR ipa/125699, PR tree-optimization/125419,",
                            "      PR tree-optimization/125652, PR tree-optimization/125686,",
                            "      PR tree-optimization/125646, PR tree-optimization/125553,",
                            "      PR tree-optimization/125545, PR tree-optimization/125502,",
                            "      PR tree-optimization/125477, PR target/124948, PR c/125072, PR c/125935,",
                            "      PR c/125604, PR c/123569, PR c/125252, PR c/124303, PR c/124985,",
                            "      PR c++/126057, PR c++/126036, PR c++/126007, PR c++/125674, PR c++/91155,",
                            "      PR c++/126066, PR c++/125901, PR c++/126031, PR c++/121552, PR c++/124584,",
                            "      PR c++/121094, PR c++/117259, PR c++/123536, PR c++/125900, PR c++/125334,",
                            "      PR c++/125768, PR c++/125939, PR c++/125745, PR c++/125408, PR c++/124978,",
                            "      PR c++/115314, PR c++/125889, PR c++/125764, PR c++/125759, PR c++/65271,",
                            "      PR c++/125770, PR fortran/126234, PR fortran/125172, PR fortran/126210,",
                            "      PR fortran/126170, PR fortran/126127, PR fortran/103367,",
                            "      PR fortran/126018, PR fortran/125051, PR fortran/125902,",
                            "      PR fortran/125902, PR fortran/60576, PR fortran/125430,",
                            "      PR fortran/125527, PR fortran/125535, PR fortran/125650,",
                            "      PR fortran/125481, PR fortran/125527, PR fortran/125528,",
                            "      PR fortran/125529, PR fortran/125530, PR fortran/125531,",
                            "      PR fortran/125534, PR fortran/125535, PR lto/125257, PR libgcc/123976,",
                            "      PR target/125752 (AVR), PR libfortran/126116, PR libstdc++/126111,",
                            "      PR libstdc++/125956, PR libstdc++/118158, PR libstdc++/125228,",
                            "      PR libstdc++/125890.",
                            "  * Let the ada build fail on an alihash mismatch, if fail_on_alihash_mismatch",
                            "    is enabled.",
                            "  * Enable Modula-2 on powerpc and ppc64. Closes: #1141560, #1141596.",
                            "  * Enable LRA by default on m68k for snapshot builds (Adrian Glaubitz).",
                            "    Addresses: #1142039.",
                            "  * Disable running tests on Debian/riscv64 for meaningful build times.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 19 Jul 2026 13:28:39 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libaudit-common",
                "from_version": {
                    "source_package_name": "audit",
                    "source_package_version": "1:4.1.2-1build1",
                    "version": "1:4.1.2-1build1"
                },
                "to_version": {
                    "source_package_name": "audit",
                    "source_package_version": "1:4.1.2-1ubuntu1",
                    "version": "1:4.1.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1117804
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix AppArmor AVC events not appearing in `ausearch` (LP: #1117804)",
                            "    - d/p/lp1117804-audit-ausearch-do-not-require-tclass.patch",
                            ""
                        ],
                        "package": "audit",
                        "version": "1:4.1.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1117804
                        ],
                        "author": "Alex Ramírez <alex.ramirez@canonical.com>",
                        "date": "Tue, 14 Jul 2026 17:20:31 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libaudit1",
                "from_version": {
                    "source_package_name": "audit",
                    "source_package_version": "1:4.1.2-1build1",
                    "version": "1:4.1.2-1build1"
                },
                "to_version": {
                    "source_package_name": "audit",
                    "source_package_version": "1:4.1.2-1ubuntu1",
                    "version": "1:4.1.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1117804
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix AppArmor AVC events not appearing in `ausearch` (LP: #1117804)",
                            "    - d/p/lp1117804-audit-ausearch-do-not-require-tclass.patch",
                            ""
                        ],
                        "package": "audit",
                        "version": "1:4.1.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1117804
                        ],
                        "author": "Alex Ramírez <alex.ramirez@canonical.com>",
                        "date": "Tue, 14 Jul 2026 17:20:31 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libbrotli1",
                "from_version": {
                    "source_package_name": "brotli",
                    "source_package_version": "1.2.0-3build1",
                    "version": "1.2.0-3build1"
                },
                "to_version": {
                    "source_package_name": "brotli",
                    "source_package_version": "1.2.0-4",
                    "version": "1.2.0-4"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Maximiliano Curia ]",
                            "  * Avoid using qemu whenever we try to build against arm64 (Closes: #1144507)",
                            "",
                            "  [ Tomasz Buchert ]",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "brotli",
                        "version": "1.2.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Tomasz Buchert <tomasz@debian.org>",
                        "date": "Sat, 22 Aug 2026 16:27:53 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc-bin",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2",
                    "version": "2.43-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.44-1ubuntu1",
                    "version": "2.44-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6791",
                        "url": "https://ubuntu.com/security/CVE-2026-6791",
                        "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-10 19:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163528
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from Debian experimental (LP: #2163528)",
                            "    Delta dropped:",
                            "    - Revert \"debian/rules.d/build.mk: add a makefile function to filter out",
                            "      dpkg build flags incompatible with glibc and define CFLAGS from dpkg",
                            "       build flags. Closes: #1129746.\"",
                            "    - fix ftbfs: backport OPEN_TREE conditional define (LP #2145679)",
                            "      [fixed upstream in 2.44]",
                            "    - debian/patches/CVE-2026-4046.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5435.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5450.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-5928.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-6238-*.patch",
                            "      [fixed in 2.43-3]",
                            "  * Delta added:",
                            "    - filter -flto=auto from dpkg-buildflags to fix build",
                            "    - fix tst-spawn-chdir with coreutils-rs due to invalid link name",
                            "    - xfail tst-nscd-basic tstptrguard-static-dlopen (LP #2164576)",
                            "    - d/tests: fix gcc dependency cross conflict on i386 autopkgtest",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163528
                        ],
                        "author": "Simon Poirier <simon.poirier@canonical.com>",
                        "date": "Tue, 11 Aug 2026 18:48:32 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * New upstream release:",
                            "    - debian/patches/localedata/sort-UTF8-first.diff: rebased.",
                            "    - debian/patches/hurd-i386/local-enable-ldconfig.diff: rebased.",
                            "    - debian/patches/hurd-i386/tg-libc_rwlock_recursive.diff: dropped,",
                            "      obsolete.",
                            "    - debian/patches/hurd-i386/git-fork-gdb.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-sig-mmx-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-cancel-sig.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-mach_send_eintr.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-itimer-lock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-posix-timers.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-alarm.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-libio-mtsafe.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-timedrwlock-unlock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sigtimedwait-timeout.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-MSG_EXAMINE.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-interrupt-EINTR.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SEM_FAILED.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-tst-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-path_mounted.diff: upstreamed.",
                            "    - debian/patches/any/local-nss-overflow.diff: upstreamed.",
                            "    - debian/patches/any/local-ldconfig-multiarch.diff: refreshed.",
                            "    - debian/symbols.wildcards: add 2.44.",
                            "    - debian/sysdeps/arm64.mk: stop passing --enable-memory-tagging to",
                            "      configure, support for it was removed upstream.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/submitted-net.diff: rebased.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 15:02:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6791",
                                "url": "https://ubuntu.com/security/CVE-2026-6791",
                                "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-10 19:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/testsuite-xfail-debian.mk: Update hurd results.",
                            "  * debian/patches/hurd-i386/submitted-path_mounted.diff: Renamed to",
                            "    git-path_mounted.diff.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - debian/patches/hurd-i386/local-disable-ioctls.diff: rebased.",
                            "    - debian/patches/hurd-i386/submitted-AF_LINK.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/submitted-AF_ROUTE.diff: upstreamed.",
                            "    - Fix a buffer overread in ns_sprintrrf with corrupted RDATA field",
                            "      (CVE-2026-6238).  Closes: #1135231.",
                            "    - Fix an out-of-bounds write in ns_sprintrrf when printing TSIG records",
                            "      (CVE-2026-5435).  Closes: #1135230.",
                            "    - Fix stack overflow in wordexp tilde expansion (CVE-2026-6791).",
                            "    - Cache cpuid results in ld.so for Intel CPUs.",
                            "    - Restore optimized memchr for POWER10.",
                            "  * debian/control.in/libc, debian/rules.d/debhelper.mk: drop the libc6-dev",
                            "    dependency on rpcsvc-proto.",
                            "  * debian/watch: set Git-Mode to shallow.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 14:19:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: assertion failure via IBM1390 or IBM1399 charsets",
                            "    - debian/patches/CVE-2026-4046.patch: Use pending character state in",
                            "      IBM1390, IBM1399 character sets in iconvdata/Makefile,",
                            "      iconvdata/ibm1364.c, iconvdata/tst-bug33980.c.",
                            "    - CVE-2026-4046",
                            "  * SECURITY UPDATE: out-of-bounds write in deprecated debugging function",
                            "    - debian/patches/CVE-2026-5435.patch: resolv: More types as unknown in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - CVE-2026-5435",
                            "  * SECURITY UPDATE: one byte heap buffer overflow in scanf %mc",
                            "    - debian/patches/CVE-2026-5450.patch: stdio-common: Fix buffer overflow in",
                            "      scanf %mc [BZ #34008] in stdio-common/Makefile, stdio-common/tst-vfscanf-",
                            "      bz34008.c, stdio-common/vfscanf-internal.c.",
                            "    - CVE-2026-5450",
                            "  * SECURITY UPDATE: crash or info disclosure in ungetwc function",
                            "    - debian/patches/CVE-2026-5928.patch: libio: Fix ungetwc operating on byte",
                            "      stream in libio/Makefile, libio/bug-wgenops-bz33998.c, libio/wgenops.c.",
                            "    - CVE-2026-5928",
                            "  * SECURITY UPDATE: crash in deprecated debugging functions",
                            "    - debian/patches/CVE-2026-6238-pre1.patch: resolv: Declare __p_class_syms,",
                            "      __p_type_syms for internal use in include/resolv.h, resolv/res_debug.c.",
                            "    - debian/patches/CVE-2026-6238-pre2.patch: resolv: Fix ns_sprintrrf",
                            "      formatting of class, type values in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre3.patch: resolv: Improve formatting of",
                            "      unknown records in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre4.patch: resolv: Check for inet_ntop",
                            "      failure in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-1.patch: resolv: Fix buffer overreads in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-2.patch: resolv: Add test case tst-",
                            "      ns_sprintrr in resolv/Makefile, resolv/tst-ns_sprintrr.c.",
                            "    - CVE-2026-6238",
                            "  * Disable failing tests because of rust-coreutils (LP: 2161727)",
                            "    - debian/testsuite-xfail-debian.mk: added tst-spawn-chdir and",
                            "      tst-spawn-chdir-pidfd.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-2ubuntu2.3",
                        "urgency": "medium",
                        "distributions": "resolute-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Wed, 22 Jul 2026 13:24:47 -0400"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix buffer overflow in scanf %mc (CVE-2026-5450).  Closes: #1134543.",
                            "    - Fix ungetwc operating on byte stream (CVE-2026-5928).  Closes: #1134544.",
                            "    - Save/restore VFP registers inPLT trampolines on arm.  Closes: #1133139.",
                            "    - Suppress iconv intermediate errors with //TRANSLIT.",
                            "    - debian/patches/hurd-i386/git-run-iconv-test.sh.diff: rebased.",
                            "  * debian/rules.d/build.mk: append extra_cflags to CFLAGS and ASFLAGS.",
                            "  * debian/control.in/libc: stop suggesting libnss-nisplus.",
                            "  * debian/debhelper.in/libc-bin.lintian-overrides: add a",
                            "    statically-linked-binary override for the ldconfig binary.",
                            "  * debian/control.in/main: build-depends on libselinux-dev instead of",
                            "    libselinux1-dev.",
                            "",
                            "  [ Miao Wang ]",
                            "  * debian/libc6.symbols.loong64: add.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: Add SO_TIMESTAMP macro.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 18 Jun 2026 21:48:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/sysdeps/mips*.mk: revert change to match the dpkg architecture",
                            "    name.",
                            "  * debian/rules.d/build.mk, debian/sysdeps/mips*.mk: add a way to define the",
                            "    debian architecture corresponding to a multilib build. Use it when it",
                            "    doesn't match the name of the pass and package like on mips*.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix build against linux 7.0 headers.  Closes: #1135405.",
                            "",
                            "  [ liu jianqiang ]",
                            "  * debian/debhelper.in/locales.config: handle leading spaces in",
                            "    /etc/locale.gen configuration.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 07 May 2026 00:25:31 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix random failure of tst-link-map-contiguous-ldso.",
                            "    - Fix tst-rseq with Linux 7.0.",
                            "    - Fix a possible crash due to an assertion failure when converting inputs",
                            "      from the IBM139x character sets (CVE-2026-4046).  Closes: #1132499.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-MSG_EXAMINE.diff: alterations to MSG_EXAMINE",
                            "    interface.",
                            "  * debian/patches/hurd-i386/git-interrupt-EINTR.diff: Interrupted RPC returning",
                            "    EINTR when server has actually changed state.",
                            "  * debian/patches/hurd-i386/git-SEM_FAILED.diff: Fix SEM_FAILED type.",
                            "  * debian/patches/hurd-i386/git-tst-fix.diff: Fix test build.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-15",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Sun, 19 Apr 2026 15:41:41 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc-gconv-modules-extra",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2",
                    "version": "2.43-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.44-1ubuntu1",
                    "version": "2.44-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6791",
                        "url": "https://ubuntu.com/security/CVE-2026-6791",
                        "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-10 19:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163528
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from Debian experimental (LP: #2163528)",
                            "    Delta dropped:",
                            "    - Revert \"debian/rules.d/build.mk: add a makefile function to filter out",
                            "      dpkg build flags incompatible with glibc and define CFLAGS from dpkg",
                            "       build flags. Closes: #1129746.\"",
                            "    - fix ftbfs: backport OPEN_TREE conditional define (LP #2145679)",
                            "      [fixed upstream in 2.44]",
                            "    - debian/patches/CVE-2026-4046.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5435.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5450.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-5928.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-6238-*.patch",
                            "      [fixed in 2.43-3]",
                            "  * Delta added:",
                            "    - filter -flto=auto from dpkg-buildflags to fix build",
                            "    - fix tst-spawn-chdir with coreutils-rs due to invalid link name",
                            "    - xfail tst-nscd-basic tstptrguard-static-dlopen (LP #2164576)",
                            "    - d/tests: fix gcc dependency cross conflict on i386 autopkgtest",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163528
                        ],
                        "author": "Simon Poirier <simon.poirier@canonical.com>",
                        "date": "Tue, 11 Aug 2026 18:48:32 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * New upstream release:",
                            "    - debian/patches/localedata/sort-UTF8-first.diff: rebased.",
                            "    - debian/patches/hurd-i386/local-enable-ldconfig.diff: rebased.",
                            "    - debian/patches/hurd-i386/tg-libc_rwlock_recursive.diff: dropped,",
                            "      obsolete.",
                            "    - debian/patches/hurd-i386/git-fork-gdb.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-sig-mmx-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-cancel-sig.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-mach_send_eintr.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-itimer-lock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-posix-timers.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-alarm.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-libio-mtsafe.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-timedrwlock-unlock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sigtimedwait-timeout.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-MSG_EXAMINE.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-interrupt-EINTR.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SEM_FAILED.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-tst-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-path_mounted.diff: upstreamed.",
                            "    - debian/patches/any/local-nss-overflow.diff: upstreamed.",
                            "    - debian/patches/any/local-ldconfig-multiarch.diff: refreshed.",
                            "    - debian/symbols.wildcards: add 2.44.",
                            "    - debian/sysdeps/arm64.mk: stop passing --enable-memory-tagging to",
                            "      configure, support for it was removed upstream.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/submitted-net.diff: rebased.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 15:02:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6791",
                                "url": "https://ubuntu.com/security/CVE-2026-6791",
                                "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-10 19:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/testsuite-xfail-debian.mk: Update hurd results.",
                            "  * debian/patches/hurd-i386/submitted-path_mounted.diff: Renamed to",
                            "    git-path_mounted.diff.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - debian/patches/hurd-i386/local-disable-ioctls.diff: rebased.",
                            "    - debian/patches/hurd-i386/submitted-AF_LINK.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/submitted-AF_ROUTE.diff: upstreamed.",
                            "    - Fix a buffer overread in ns_sprintrrf with corrupted RDATA field",
                            "      (CVE-2026-6238).  Closes: #1135231.",
                            "    - Fix an out-of-bounds write in ns_sprintrrf when printing TSIG records",
                            "      (CVE-2026-5435).  Closes: #1135230.",
                            "    - Fix stack overflow in wordexp tilde expansion (CVE-2026-6791).",
                            "    - Cache cpuid results in ld.so for Intel CPUs.",
                            "    - Restore optimized memchr for POWER10.",
                            "  * debian/control.in/libc, debian/rules.d/debhelper.mk: drop the libc6-dev",
                            "    dependency on rpcsvc-proto.",
                            "  * debian/watch: set Git-Mode to shallow.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 14:19:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: assertion failure via IBM1390 or IBM1399 charsets",
                            "    - debian/patches/CVE-2026-4046.patch: Use pending character state in",
                            "      IBM1390, IBM1399 character sets in iconvdata/Makefile,",
                            "      iconvdata/ibm1364.c, iconvdata/tst-bug33980.c.",
                            "    - CVE-2026-4046",
                            "  * SECURITY UPDATE: out-of-bounds write in deprecated debugging function",
                            "    - debian/patches/CVE-2026-5435.patch: resolv: More types as unknown in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - CVE-2026-5435",
                            "  * SECURITY UPDATE: one byte heap buffer overflow in scanf %mc",
                            "    - debian/patches/CVE-2026-5450.patch: stdio-common: Fix buffer overflow in",
                            "      scanf %mc [BZ #34008] in stdio-common/Makefile, stdio-common/tst-vfscanf-",
                            "      bz34008.c, stdio-common/vfscanf-internal.c.",
                            "    - CVE-2026-5450",
                            "  * SECURITY UPDATE: crash or info disclosure in ungetwc function",
                            "    - debian/patches/CVE-2026-5928.patch: libio: Fix ungetwc operating on byte",
                            "      stream in libio/Makefile, libio/bug-wgenops-bz33998.c, libio/wgenops.c.",
                            "    - CVE-2026-5928",
                            "  * SECURITY UPDATE: crash in deprecated debugging functions",
                            "    - debian/patches/CVE-2026-6238-pre1.patch: resolv: Declare __p_class_syms,",
                            "      __p_type_syms for internal use in include/resolv.h, resolv/res_debug.c.",
                            "    - debian/patches/CVE-2026-6238-pre2.patch: resolv: Fix ns_sprintrrf",
                            "      formatting of class, type values in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre3.patch: resolv: Improve formatting of",
                            "      unknown records in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre4.patch: resolv: Check for inet_ntop",
                            "      failure in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-1.patch: resolv: Fix buffer overreads in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-2.patch: resolv: Add test case tst-",
                            "      ns_sprintrr in resolv/Makefile, resolv/tst-ns_sprintrr.c.",
                            "    - CVE-2026-6238",
                            "  * Disable failing tests because of rust-coreutils (LP: 2161727)",
                            "    - debian/testsuite-xfail-debian.mk: added tst-spawn-chdir and",
                            "      tst-spawn-chdir-pidfd.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-2ubuntu2.3",
                        "urgency": "medium",
                        "distributions": "resolute-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Wed, 22 Jul 2026 13:24:47 -0400"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix buffer overflow in scanf %mc (CVE-2026-5450).  Closes: #1134543.",
                            "    - Fix ungetwc operating on byte stream (CVE-2026-5928).  Closes: #1134544.",
                            "    - Save/restore VFP registers inPLT trampolines on arm.  Closes: #1133139.",
                            "    - Suppress iconv intermediate errors with //TRANSLIT.",
                            "    - debian/patches/hurd-i386/git-run-iconv-test.sh.diff: rebased.",
                            "  * debian/rules.d/build.mk: append extra_cflags to CFLAGS and ASFLAGS.",
                            "  * debian/control.in/libc: stop suggesting libnss-nisplus.",
                            "  * debian/debhelper.in/libc-bin.lintian-overrides: add a",
                            "    statically-linked-binary override for the ldconfig binary.",
                            "  * debian/control.in/main: build-depends on libselinux-dev instead of",
                            "    libselinux1-dev.",
                            "",
                            "  [ Miao Wang ]",
                            "  * debian/libc6.symbols.loong64: add.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: Add SO_TIMESTAMP macro.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 18 Jun 2026 21:48:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/sysdeps/mips*.mk: revert change to match the dpkg architecture",
                            "    name.",
                            "  * debian/rules.d/build.mk, debian/sysdeps/mips*.mk: add a way to define the",
                            "    debian architecture corresponding to a multilib build. Use it when it",
                            "    doesn't match the name of the pass and package like on mips*.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix build against linux 7.0 headers.  Closes: #1135405.",
                            "",
                            "  [ liu jianqiang ]",
                            "  * debian/debhelper.in/locales.config: handle leading spaces in",
                            "    /etc/locale.gen configuration.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 07 May 2026 00:25:31 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix random failure of tst-link-map-contiguous-ldso.",
                            "    - Fix tst-rseq with Linux 7.0.",
                            "    - Fix a possible crash due to an assertion failure when converting inputs",
                            "      from the IBM139x character sets (CVE-2026-4046).  Closes: #1132499.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-MSG_EXAMINE.diff: alterations to MSG_EXAMINE",
                            "    interface.",
                            "  * debian/patches/hurd-i386/git-interrupt-EINTR.diff: Interrupted RPC returning",
                            "    EINTR when server has actually changed state.",
                            "  * debian/patches/hurd-i386/git-SEM_FAILED.diff: Fix SEM_FAILED type.",
                            "  * debian/patches/hurd-i386/git-tst-fix.diff: Fix test build.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-15",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Sun, 19 Apr 2026 15:41:41 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc6",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2",
                    "version": "2.43-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.44-1ubuntu1",
                    "version": "2.44-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6791",
                        "url": "https://ubuntu.com/security/CVE-2026-6791",
                        "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-10 19:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163528
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from Debian experimental (LP: #2163528)",
                            "    Delta dropped:",
                            "    - Revert \"debian/rules.d/build.mk: add a makefile function to filter out",
                            "      dpkg build flags incompatible with glibc and define CFLAGS from dpkg",
                            "       build flags. Closes: #1129746.\"",
                            "    - fix ftbfs: backport OPEN_TREE conditional define (LP #2145679)",
                            "      [fixed upstream in 2.44]",
                            "    - debian/patches/CVE-2026-4046.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5435.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5450.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-5928.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-6238-*.patch",
                            "      [fixed in 2.43-3]",
                            "  * Delta added:",
                            "    - filter -flto=auto from dpkg-buildflags to fix build",
                            "    - fix tst-spawn-chdir with coreutils-rs due to invalid link name",
                            "    - xfail tst-nscd-basic tstptrguard-static-dlopen (LP #2164576)",
                            "    - d/tests: fix gcc dependency cross conflict on i386 autopkgtest",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163528
                        ],
                        "author": "Simon Poirier <simon.poirier@canonical.com>",
                        "date": "Tue, 11 Aug 2026 18:48:32 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * New upstream release:",
                            "    - debian/patches/localedata/sort-UTF8-first.diff: rebased.",
                            "    - debian/patches/hurd-i386/local-enable-ldconfig.diff: rebased.",
                            "    - debian/patches/hurd-i386/tg-libc_rwlock_recursive.diff: dropped,",
                            "      obsolete.",
                            "    - debian/patches/hurd-i386/git-fork-gdb.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-sig-mmx-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-cancel-sig.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-mach_send_eintr.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-itimer-lock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-posix-timers.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-alarm.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-libio-mtsafe.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-timedrwlock-unlock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sigtimedwait-timeout.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-MSG_EXAMINE.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-interrupt-EINTR.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SEM_FAILED.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-tst-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-path_mounted.diff: upstreamed.",
                            "    - debian/patches/any/local-nss-overflow.diff: upstreamed.",
                            "    - debian/patches/any/local-ldconfig-multiarch.diff: refreshed.",
                            "    - debian/symbols.wildcards: add 2.44.",
                            "    - debian/sysdeps/arm64.mk: stop passing --enable-memory-tagging to",
                            "      configure, support for it was removed upstream.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/submitted-net.diff: rebased.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 15:02:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6791",
                                "url": "https://ubuntu.com/security/CVE-2026-6791",
                                "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-10 19:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/testsuite-xfail-debian.mk: Update hurd results.",
                            "  * debian/patches/hurd-i386/submitted-path_mounted.diff: Renamed to",
                            "    git-path_mounted.diff.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - debian/patches/hurd-i386/local-disable-ioctls.diff: rebased.",
                            "    - debian/patches/hurd-i386/submitted-AF_LINK.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/submitted-AF_ROUTE.diff: upstreamed.",
                            "    - Fix a buffer overread in ns_sprintrrf with corrupted RDATA field",
                            "      (CVE-2026-6238).  Closes: #1135231.",
                            "    - Fix an out-of-bounds write in ns_sprintrrf when printing TSIG records",
                            "      (CVE-2026-5435).  Closes: #1135230.",
                            "    - Fix stack overflow in wordexp tilde expansion (CVE-2026-6791).",
                            "    - Cache cpuid results in ld.so for Intel CPUs.",
                            "    - Restore optimized memchr for POWER10.",
                            "  * debian/control.in/libc, debian/rules.d/debhelper.mk: drop the libc6-dev",
                            "    dependency on rpcsvc-proto.",
                            "  * debian/watch: set Git-Mode to shallow.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 14:19:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: assertion failure via IBM1390 or IBM1399 charsets",
                            "    - debian/patches/CVE-2026-4046.patch: Use pending character state in",
                            "      IBM1390, IBM1399 character sets in iconvdata/Makefile,",
                            "      iconvdata/ibm1364.c, iconvdata/tst-bug33980.c.",
                            "    - CVE-2026-4046",
                            "  * SECURITY UPDATE: out-of-bounds write in deprecated debugging function",
                            "    - debian/patches/CVE-2026-5435.patch: resolv: More types as unknown in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - CVE-2026-5435",
                            "  * SECURITY UPDATE: one byte heap buffer overflow in scanf %mc",
                            "    - debian/patches/CVE-2026-5450.patch: stdio-common: Fix buffer overflow in",
                            "      scanf %mc [BZ #34008] in stdio-common/Makefile, stdio-common/tst-vfscanf-",
                            "      bz34008.c, stdio-common/vfscanf-internal.c.",
                            "    - CVE-2026-5450",
                            "  * SECURITY UPDATE: crash or info disclosure in ungetwc function",
                            "    - debian/patches/CVE-2026-5928.patch: libio: Fix ungetwc operating on byte",
                            "      stream in libio/Makefile, libio/bug-wgenops-bz33998.c, libio/wgenops.c.",
                            "    - CVE-2026-5928",
                            "  * SECURITY UPDATE: crash in deprecated debugging functions",
                            "    - debian/patches/CVE-2026-6238-pre1.patch: resolv: Declare __p_class_syms,",
                            "      __p_type_syms for internal use in include/resolv.h, resolv/res_debug.c.",
                            "    - debian/patches/CVE-2026-6238-pre2.patch: resolv: Fix ns_sprintrrf",
                            "      formatting of class, type values in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre3.patch: resolv: Improve formatting of",
                            "      unknown records in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-pre4.patch: resolv: Check for inet_ntop",
                            "      failure in ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-1.patch: resolv: Fix buffer overreads in",
                            "      ns_sprintrrf in resolv/ns_print.c.",
                            "    - debian/patches/CVE-2026-6238-2.patch: resolv: Add test case tst-",
                            "      ns_sprintrr in resolv/Makefile, resolv/tst-ns_sprintrr.c.",
                            "    - CVE-2026-6238",
                            "  * Disable failing tests because of rust-coreutils (LP: 2161727)",
                            "    - debian/testsuite-xfail-debian.mk: added tst-spawn-chdir and",
                            "      tst-spawn-chdir-pidfd.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-2ubuntu2.3",
                        "urgency": "medium",
                        "distributions": "resolute-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Wed, 22 Jul 2026 13:24:47 -0400"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix buffer overflow in scanf %mc (CVE-2026-5450).  Closes: #1134543.",
                            "    - Fix ungetwc operating on byte stream (CVE-2026-5928).  Closes: #1134544.",
                            "    - Save/restore VFP registers inPLT trampolines on arm.  Closes: #1133139.",
                            "    - Suppress iconv intermediate errors with //TRANSLIT.",
                            "    - debian/patches/hurd-i386/git-run-iconv-test.sh.diff: rebased.",
                            "  * debian/rules.d/build.mk: append extra_cflags to CFLAGS and ASFLAGS.",
                            "  * debian/control.in/libc: stop suggesting libnss-nisplus.",
                            "  * debian/debhelper.in/libc-bin.lintian-overrides: add a",
                            "    statically-linked-binary override for the ldconfig binary.",
                            "  * debian/control.in/main: build-depends on libselinux-dev instead of",
                            "    libselinux1-dev.",
                            "",
                            "  [ Miao Wang ]",
                            "  * debian/libc6.symbols.loong64: add.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: Add SO_TIMESTAMP macro.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 18 Jun 2026 21:48:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/sysdeps/mips*.mk: revert change to match the dpkg architecture",
                            "    name.",
                            "  * debian/rules.d/build.mk, debian/sysdeps/mips*.mk: add a way to define the",
                            "    debian architecture corresponding to a multilib build. Use it when it",
                            "    doesn't match the name of the pass and package like on mips*.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix build against linux 7.0 headers.  Closes: #1135405.",
                            "",
                            "  [ liu jianqiang ]",
                            "  * debian/debhelper.in/locales.config: handle leading spaces in",
                            "    /etc/locale.gen configuration.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 07 May 2026 00:25:31 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix random failure of tst-link-map-contiguous-ldso.",
                            "    - Fix tst-rseq with Linux 7.0.",
                            "    - Fix a possible crash due to an assertion failure when converting inputs",
                            "      from the IBM139x character sets (CVE-2026-4046).  Closes: #1132499.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-MSG_EXAMINE.diff: alterations to MSG_EXAMINE",
                            "    interface.",
                            "  * debian/patches/hurd-i386/git-interrupt-EINTR.diff: Interrupted RPC returning",
                            "    EINTR when server has actually changed state.",
                            "  * debian/patches/hurd-i386/git-SEM_FAILED.diff: Fix SEM_FAILED type.",
                            "  * debian/patches/hurd-i386/git-tst-fix.diff: Fix test build.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-15",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Sun, 19 Apr 2026 15:41:41 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libcap2",
                "from_version": {
                    "source_package_name": "libcap2",
                    "source_package_version": "1:2.75-10ubuntu2",
                    "version": "1:2.75-10ubuntu2"
                },
                "to_version": {
                    "source_package_name": "libcap2",
                    "source_package_version": "1:2.78-1ubuntu1",
                    "version": "1:2.78-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4878",
                        "url": "https://ubuntu.com/security/CVE-2026-4878",
                        "cve_description": "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-09 16:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable. Remaining changes:",
                            "    - d/rules: strip -Wl,-Bsymbolic-functions from LDFLAGS (LP #2003892)",
                            ""
                        ],
                        "package": "libcap2",
                        "version": "1:2.78-1ubuntu1",
                        "urgency": "low",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Gianfranco Costamagna <locutusofborg@debian.org>",
                        "date": "Tue, 28 Jul 2026 23:02:14 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4878",
                                "url": "https://ubuntu.com/security/CVE-2026-4878",
                                "cve_description": "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-09 16:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream version 2.78",
                            "    - Fixes CVE-2026-4878",
                            "    - Refresh patches",
                            "  * Bump Standards-Version to 4.7.4 (no changes needed)",
                            "  * autopkgtest: Re-add needs-root (not implied by isolation-machine)",
                            ""
                        ],
                        "package": "libcap2",
                        "version": "1:2.78-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Christian Kastner <ckk@debian.org>",
                        "date": "Mon, 06 Apr 2026 22:01:03 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 2.77",
                            "    - Drop patches included upstream",
                            "    - Refresh patches",
                            "  * Bump Standards-Version to 4.7.3",
                            "    - Drop Priority and R-R-R, default since trixie",
                            "  * Install new section 7 man page",
                            "  * Change section of Go package to golang",
                            "  * autopkogtest: 'executables' test needs isolation-machine",
                            ""
                        ],
                        "package": "libcap2",
                        "version": "1:2.77-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Christian Kastner <ckk@debian.org>",
                        "date": "Thu, 02 Apr 2026 13:16:21 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libcap2-bin",
                "from_version": {
                    "source_package_name": "libcap2",
                    "source_package_version": "1:2.75-10ubuntu2",
                    "version": "1:2.75-10ubuntu2"
                },
                "to_version": {
                    "source_package_name": "libcap2",
                    "source_package_version": "1:2.78-1ubuntu1",
                    "version": "1:2.78-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4878",
                        "url": "https://ubuntu.com/security/CVE-2026-4878",
                        "cve_description": "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-09 16:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable. Remaining changes:",
                            "    - d/rules: strip -Wl,-Bsymbolic-functions from LDFLAGS (LP #2003892)",
                            ""
                        ],
                        "package": "libcap2",
                        "version": "1:2.78-1ubuntu1",
                        "urgency": "low",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Gianfranco Costamagna <locutusofborg@debian.org>",
                        "date": "Tue, 28 Jul 2026 23:02:14 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4878",
                                "url": "https://ubuntu.com/security/CVE-2026-4878",
                                "cve_description": "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-09 16:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream version 2.78",
                            "    - Fixes CVE-2026-4878",
                            "    - Refresh patches",
                            "  * Bump Standards-Version to 4.7.4 (no changes needed)",
                            "  * autopkgtest: Re-add needs-root (not implied by isolation-machine)",
                            ""
                        ],
                        "package": "libcap2",
                        "version": "1:2.78-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Christian Kastner <ckk@debian.org>",
                        "date": "Mon, 06 Apr 2026 22:01:03 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 2.77",
                            "    - Drop patches included upstream",
                            "    - Refresh patches",
                            "  * Bump Standards-Version to 4.7.3",
                            "    - Drop Priority and R-R-R, default since trixie",
                            "  * Install new section 7 man page",
                            "  * Change section of Go package to golang",
                            "  * autopkogtest: 'executables' test needs isolation-machine",
                            ""
                        ],
                        "package": "libcap2",
                        "version": "1:2.77-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Christian Kastner <ckk@debian.org>",
                        "date": "Thu, 02 Apr 2026 13:16:21 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libcrypt1",
                "from_version": {
                    "source_package_name": "libxcrypt",
                    "source_package_version": "1:4.5.1-1",
                    "version": "1:4.5.1-1"
                },
                "to_version": {
                    "source_package_name": "libxcrypt",
                    "source_package_version": "1:4.5.2+20251210-1",
                    "version": "1:4.5.2+20251210-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream snapshot.",
                            ""
                        ],
                        "package": "libxcrypt",
                        "version": "1:4.5.2+20251210-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marco d'Itri <md@linux.it>",
                        "date": "Sun, 09 Aug 2026 00:52:53 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libelf1t64",
                "from_version": {
                    "source_package_name": "elfutils",
                    "source_package_version": "0.195-1",
                    "version": "0.195-1"
                },
                "to_version": {
                    "source_package_name": "elfutils",
                    "source_package_version": "0.196-1",
                    "version": "0.196-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Update symbols files.",
                            ""
                        ],
                        "package": "elfutils",
                        "version": "0.196-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 08:17:36 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libexpat1",
                "from_version": {
                    "source_package_name": "expat",
                    "source_package_version": "2.8.1-1",
                    "version": "2.8.1-1"
                },
                "to_version": {
                    "source_package_name": "expat",
                    "source_package_version": "2.8.3-1",
                    "version": "2.8.3-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-72522",
                        "url": "https://ubuntu.com/security/CVE-2026-72522",
                        "cve_description": "libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-10 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56131",
                        "url": "https://ubuntu.com/security/CVE-2026-56131",
                        "cve_description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-19 06:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56132",
                        "url": "https://ubuntu.com/security/CVE-2026-56132",
                        "cve_description": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-19 06:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-50219",
                        "url": "https://ubuntu.com/security/CVE-2026-50219",
                        "cve_description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-04 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56403",
                        "url": "https://ubuntu.com/security/CVE-2026-56403",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56404",
                        "url": "https://ubuntu.com/security/CVE-2026-56404",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in addBinding.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56405",
                        "url": "https://ubuntu.com/security/CVE-2026-56405",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56406",
                        "url": "https://ubuntu.com/security/CVE-2026-56406",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56407",
                        "url": "https://ubuntu.com/security/CVE-2026-56407",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56408",
                        "url": "https://ubuntu.com/security/CVE-2026-56408",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in copyString.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56409",
                        "url": "https://ubuntu.com/security/CVE-2026-56409",
                        "cve_description": "xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56410",
                        "url": "https://ubuntu.com/security/CVE-2026-56410",
                        "cve_description": "xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56411",
                        "url": "https://ubuntu.com/security/CVE-2026-56411",
                        "cve_description": "xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 17:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56412",
                        "url": "https://ubuntu.com/security/CVE-2026-56412",
                        "cve_description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 17:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-72522",
                                "url": "https://ubuntu.com/security/CVE-2026-72522",
                                "cve_description": "libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-10 04:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release:",
                            "    - fixes CVE-2026-72522: out of bounds read and resultant infinite loop",
                            "      (closes: #1144064).",
                            ""
                        ],
                        "package": "expat",
                        "version": "2.8.3-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Tue, 11 Aug 2026 06:52:38 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-56131",
                                "url": "https://ubuntu.com/security/CVE-2026-56131",
                                "cve_description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-19 06:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56132",
                                "url": "https://ubuntu.com/security/CVE-2026-56132",
                                "cve_description": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-19 06:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-50219",
                                "url": "https://ubuntu.com/security/CVE-2026-50219",
                                "cve_description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-04 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56403",
                                "url": "https://ubuntu.com/security/CVE-2026-56403",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56404",
                                "url": "https://ubuntu.com/security/CVE-2026-56404",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in addBinding.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56405",
                                "url": "https://ubuntu.com/security/CVE-2026-56405",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56406",
                                "url": "https://ubuntu.com/security/CVE-2026-56406",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56407",
                                "url": "https://ubuntu.com/security/CVE-2026-56407",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56408",
                                "url": "https://ubuntu.com/security/CVE-2026-56408",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in copyString.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56409",
                                "url": "https://ubuntu.com/security/CVE-2026-56409",
                                "cve_description": "xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56410",
                                "url": "https://ubuntu.com/security/CVE-2026-56410",
                                "cve_description": "xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56411",
                                "url": "https://ubuntu.com/security/CVE-2026-56411",
                                "cve_description": "xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 17:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56412",
                                "url": "https://ubuntu.com/security/CVE-2026-56412",
                                "cve_description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 17:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1138862, #1140387, #1140388, #1140557):",
                            "    - fixes CVE-2026-56131: protect XML_ResumeParser() from being called from",
                            "      a handler,",
                            "    - fixes CVE-2026-56132: fix out-of-bound scaffolding index store in",
                            "      doProlog(),",
                            "    - fixes CVE-2026-50219: disallow calls to some functions to guard Expat",
                            "      bindings from memory corruption,",
                            "    - fixes CVE-2026-56403: integer overflow in storeAtts(),",
                            "    - fixes CVE-2026-56404: integer overflow in addBinding(),",
                            "    - fixes CVE-2026-56405: integer overflow in getAttributeId(),",
                            "    - fixes CVE-2026-56406: integer overflow in XML_ParseBuffer(),",
                            "    - fixes CVE-2026-56407: integer overflow in textLen handling,",
                            "    - fixes CVE-2026-56408: integer overflow in copyString(),",
                            "    - fixes CVE-2026-56409: integer overflow in output path join in xmlwf,",
                            "    - fixes CVE-2026-56410: integer overflow in resolveSystemId() in xmlwf,",
                            "    - fixes CVE-2026-56411: Integer overflow in notation list allocation",
                            "      in xmlwf,",
                            "    - fixes CVE-2026-56412: guard XML_TOK_DATA_CHARS handler calls",
                            "      in doCdataSection().",
                            ""
                        ],
                        "package": "expat",
                        "version": "2.8.2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Thu, 25 Jun 2026 19:44:46 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libffi8",
                "from_version": {
                    "source_package_name": "libffi",
                    "source_package_version": "3.5.2-4",
                    "version": "3.5.2-4"
                },
                "to_version": {
                    "source_package_name": "libffi",
                    "source_package_version": "3.8.0-2",
                    "version": "3.8.0-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Correct symbols file for LIBFFI_CALL_PLAN_8.[45] versioned symbols.",
                            ""
                        ],
                        "package": "libffi",
                        "version": "3.8.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sat, 15 Aug 2026 16:05:11 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Update symbols file.",
                            ""
                        ],
                        "package": "libffi",
                        "version": "3.8.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 13 Aug 2026 01:57:42 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Conditionalize new symbols on architectures.",
                            ""
                        ],
                        "package": "libffi",
                        "version": "3.7.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Mon, 13 Jul 2026 14:13:24 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Update symbols file.",
                            "  * Bump standards version.",
                            ""
                        ],
                        "package": "libffi",
                        "version": "3.7.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:27:02 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libfido2-1",
                "from_version": {
                    "source_package_name": "libfido2",
                    "source_package_version": "1.17.0-1",
                    "version": "1.17.0-1"
                },
                "to_version": {
                    "source_package_name": "libfido2",
                    "source_package_version": "1.17.0-2build1",
                    "version": "1.17.0-2build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "libfido2",
                        "version": "1.17.0-2build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:58:54 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "  * Use watch v5",
                            "  * Drop Priority: optional",
                            "  * Standards-Version: 4.7.4",
                            "  * Use compat 14",
                            "  * Move to pkg-security team maintainer",
                            "  * Expand fido2-tool Description, dropping overrides",
                            "  * Ship examples too",
                            "  * Improve d/copyright",
                            ""
                        ],
                        "package": "libfido2",
                        "version": "1.17.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon Josefsson <simon@josefsson.org>",
                        "date": "Wed, 22 Jul 2026 17:20:14 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libfreetype6",
                "from_version": {
                    "source_package_name": "freetype",
                    "source_package_version": "2.14.3+dfsg-1",
                    "version": "2.14.3+dfsg-1"
                },
                "to_version": {
                    "source_package_name": "freetype",
                    "source_package_version": "2.14.3+dfsg-2",
                    "version": "2.14.3+dfsg-2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-50811",
                        "url": "https://ubuntu.com/security/CVE-2026-50811",
                        "cve_description": "An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 23:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-50811",
                                "url": "https://ubuntu.com/security/CVE-2026-50811",
                                "cve_description": "An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 23:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * debian/patches: Fix CVE-2026-50811 (Closes: #1141704).",
                            "  * Remove debian/freetype2-doc.lintian-overrides.",
                            ""
                        ],
                        "package": "freetype",
                        "version": "2.14.3+dfsg-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Hugh McMaster <hmc@debian.org>",
                        "date": "Fri, 24 Jul 2026 21:55:56 +1000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libfuse3-4",
                "from_version": {
                    "source_package_name": "fuse3",
                    "source_package_version": "3.18.2-2",
                    "version": "3.18.2-2"
                },
                "to_version": {
                    "source_package_name": "fuse3",
                    "source_package_version": "3.18.3-1",
                    "version": "3.18.3-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "fuse3",
                        "version": "3.18.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sun, 13 Sep 2026 08:42:13 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgcc-s1",
                "from_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.1.0-2ubuntu1",
                    "version": "16.1.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-2ubuntu1",
                    "version": "16.2.0-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158577
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Wed, 02 Sep 2026 10:52:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260902 from the gcc-16 branch.",
                            "    - Fix PR middle-end/127098, PR tree-optimization/127105,",
                            "      PR tree-optimization/127100, PR target/120681 (PPC),",
                            "      PR target/120528 (PPC), PR target/99293 (PPC), PR target/117487 (PPC),",
                            "      PR ada/125984, PR ipa/127023, PR target/126873 (RISCV),",
                            "      PR rtl-optimization/126426, PR target/127004 (AVR), PR middle-end/126939,",
                            "      PR target/126787 (x86), PR target/126513 (PPC),",
                            "      PR target/124629 (AArch64), PR tree-optimization/126925,",
                            "      PR tree-optimization/126650, PR tree-optimization/126926,",
                            "      PR tree-optimization/126534, PR target/126454 (RISCV),",
                            "      PR target/126334 (RISCV), PR target/126550 (RISCV),",
                            "      PR target/126676 (x86), PR target/126320 (x86), PR target/126450 (x86),",
                            "      PR target/126529 (x86), PR ada/127026, PR ada/127026, PR ada/126928,",
                            "      PR ada/126907, PR c++/127046, PR c++/124888, PR c++/126335,",
                            "      PR c++/124794, PR c++/126546, PR c++/124811, PR c++/126918,",
                            "      PR c++/126867, PR c++/126752, PR c++/126093, PR c++/126483,",
                            "      PR c++/126754, PR c++/126783, PR c++/124794, PR c++/125069,",
                            "      PR c++/124806, PR fortran/98573, PR fortran/105594, PR fortran/88632,",
                            "      PR fortran/104630, PR fortran/126872, PR fortran/110626,",
                            "      PR fortran/104048, PR target/125803 (PPC), PR libstdc++/118665,",
                            "      PR libstdc++/123510, PR libstdc++/122981, PR libstdc++/127006,",
                            "      PR libstdc++/126731, PR libstdc++/125981, PR libstdc++/126452,",
                            "      PR libstdc++/126849.",
                            "  * Only enable LRA by default on m68k for snapshot builds. Closes: #1143971.",
                            "  * Don't apply the SH LRA patches for snapshot builds. Closes: #1146439.",
                            "  * Disable usage stats for the build.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 02 Sep 2026 11:07:42 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 09 Aug 2026 06:21:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * GCC 16.2.0 release.",
                            "    - Fix PR target/126581 (x86), PR tree-optimization/126504,",
                            "      PR tree-optimization/126503, PR middle-end/126497,",
                            "      PR tree-optimization/126490, PR tree-optimization/126464,",
                            "      PR tree-optimization/126476, PR tree-optimization/126464,",
                            "      PR middle-end/126084, PR tree-optimization/126471, PR target/126446,",
                            "      PR middle-end/126410, PR tree-optimization/126457,",
                            "      PR tree-optimization/126404, PR tree-optimization/126404,",
                            "      PR target/126438 (PPC), PR target/126450 (x86), PR middle-end/126447,",
                            "      PR middle-end/126405, PR rtl-optimization/126184,",
                            "      PR rtl-optimization/126184, PR target/126429 (x86),",
                            "      PR tree-optimization/125396, PR tree-optimization/125290,",
                            "      PR target/126320 (x86), PR middle-end/126341, PR target/123625 (AArch64),",
                            "      PR target/121957 (AArch64), PR rtl-optimization/125209,",
                            "      PR middle-end/124637, PR tree-optimization/126171,",
                            "      PR tree-optimization/126225, PR tree-optimization/124663, PR ipa/125207,",
                            "      PR target/119210 (AArch64), PR target/105116, PR driver/1240,",
                            "      PR ada/126553, PR ada/126379, PR ada/126482, PR algol68/126330,",
                            "      PR c++/126309, PR c++/126508, PR c++/126420, PR c++/126423,",
                            "      PR c++/126343, PR c++/126406, PR c++/119343, PR c++/126209,",
                            "      PR c++/126310, PR c++/126280, PR c++/126215, PR driver/124058,",
                            "      PR fortran/125866, PR fortran/126386, PR fortran/126303,",
                            "      PR fortran/97592, PR fortran/125998, PR sanitizer/126307,",
                            "      PR libstdc++/122197, PR libstdc++/124854, PR libstdc++/116110,",
                            "      PR libstdc++/124853, PR libstdc++/116110, PR libstdc++/124852,",
                            "      PR libstdc++/124852, PR libstdc++/124851, PR libstdc++/123165.",
                            "  * Update to git 20260809 from the gcc-16 branch.",
                            "    - Fix PR target/126484 (MIPS), PR tree-optimization/126576,",
                            "      PR tree-optimization/126547, PR tree-optimization/126549,",
                            "      PR tree-optimization/126564, PR tree-optimization/126601,",
                            "      PR target/124948, PR tree-optimization/126464, PR preprocessor/125048,",
                            "      PR libstdc++/125200, PR c++/125591, PR c++/125601, PR c++/125680,",
                            "      PR c++/125541, PR fortran/126205, PR target/126667 (S390),",
                            "      PR fortran/125263.",
                            "",
                            "  [ Matthias Klose ]",
                            "  * Update libgcc-s, libcc1, libasan and libgcobol symbols files.",
                            "  * d/rules2: Use rva23u64 with zifencei extension for Ubuntu (Vladimir Petko).",
                            "    LP: #2158577.",
                            "  * d/rules: Reformat riscv64 extensions for Debian.",
                            "  * Configure with --enable-checking=release on every architecture.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * d/rules2: Use rva20u64 with zifencei extension for Debian.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2158577
                        ],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 09 Aug 2026 06:10:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 19 Jul 2026 14:16:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260719 from the gcc-16 branch.",
                            "    - Fix PR tree-optimization/126262, PR tree-optimization/126257,",
                            "      PR middle-end/126084, PR tree-optimization/120201,",
                            "      PR tree-optimization/126194, PR tree-optimization/126150,",
                            "      PR tree-optimization/125953, PR middle-end/125875,",
                            "      PR tree-optimization/125786, PR tree-optimization/125668,",
                            "      PR tree-optimization/125296, PR tree-optimization/126008,",
                            "      PR tree-optimization/125730, PR tree-optimization/125040,",
                            "      PR ipa/125121, PR ipa/124128, PR target/126054 (S390),",
                            "      PR target/126148 (x86), PR tree-optimization/125597,",
                            "      PR tree-optimization/125597, PR tree-optimization/125597,",
                            "      PR target/126081 (or1k), PR target/126049 (RISCV),",
                            "      PR target/126098 (x86), PR target/67459 (SH), PR target/122948 (SH),",
                            "      PR target/125972 (S390), PR rtl-optimization/125173,",
                            "      PR target/124908 (AArch64), PR target/125838 (AArch64),",
                            "      PR target/125883 (x86), PR target/125818 (AArch64),",
                            "      PR target/125469 (x86), PR target/125469 (x86), PR target/125949 (x86),",
                            "      PR target/125992 (S390), PR middle-end/125977, PR target/125628 (MIPS),",
                            "      PR target/125478 (RISCV), PR target/106895 (PPC), PR target/122665 (PPC),",
                            "      PR target/125670 (RISCV), PR middle-end/125621,",
                            "      PR target/125148 (AArch64), PR tree-optimization/125431,",
                            "      PR target/125795 (AArch64), PR tree-optimization/125501,",
                            "      PR tree-optimization/125776, PR tree-optimization/125774,",
                            "      PR target/120144 (MIPS), PR ipa/125699, PR tree-optimization/125419,",
                            "      PR tree-optimization/125652, PR tree-optimization/125686,",
                            "      PR tree-optimization/125646, PR tree-optimization/125553,",
                            "      PR tree-optimization/125545, PR tree-optimization/125502,",
                            "      PR tree-optimization/125477, PR target/124948, PR c/125072, PR c/125935,",
                            "      PR c/125604, PR c/123569, PR c/125252, PR c/124303, PR c/124985,",
                            "      PR c++/126057, PR c++/126036, PR c++/126007, PR c++/125674, PR c++/91155,",
                            "      PR c++/126066, PR c++/125901, PR c++/126031, PR c++/121552, PR c++/124584,",
                            "      PR c++/121094, PR c++/117259, PR c++/123536, PR c++/125900, PR c++/125334,",
                            "      PR c++/125768, PR c++/125939, PR c++/125745, PR c++/125408, PR c++/124978,",
                            "      PR c++/115314, PR c++/125889, PR c++/125764, PR c++/125759, PR c++/65271,",
                            "      PR c++/125770, PR fortran/126234, PR fortran/125172, PR fortran/126210,",
                            "      PR fortran/126170, PR fortran/126127, PR fortran/103367,",
                            "      PR fortran/126018, PR fortran/125051, PR fortran/125902,",
                            "      PR fortran/125902, PR fortran/60576, PR fortran/125430,",
                            "      PR fortran/125527, PR fortran/125535, PR fortran/125650,",
                            "      PR fortran/125481, PR fortran/125527, PR fortran/125528,",
                            "      PR fortran/125529, PR fortran/125530, PR fortran/125531,",
                            "      PR fortran/125534, PR fortran/125535, PR lto/125257, PR libgcc/123976,",
                            "      PR target/125752 (AVR), PR libfortran/126116, PR libstdc++/126111,",
                            "      PR libstdc++/125956, PR libstdc++/118158, PR libstdc++/125228,",
                            "      PR libstdc++/125890.",
                            "  * Let the ada build fail on an alihash mismatch, if fail_on_alihash_mismatch",
                            "    is enabled.",
                            "  * Enable Modula-2 on powerpc and ppc64. Closes: #1141560, #1141596.",
                            "  * Enable LRA by default on m68k for snapshot builds (Adrian Glaubitz).",
                            "    Addresses: #1142039.",
                            "  * Disable running tests on Debian/riscv64 for meaningful build times.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 19 Jul 2026 13:28:39 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgirepository-2.0-0",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.88.1-2",
                    "version": "2.88.1-2"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.90.0-1",
                    "version": "2.90.0-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.90.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Thu, 10 Sep 2026 12:07:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Re-upload with orig tarball, no source changes",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 19:33:06 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes a main-loop regression in 2.89.3 (mutter#4994 upstream)",
                            "  * d/patches: Drop patches that were part of the upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 18:52:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Fri, 21 Aug 2026 16:37:11 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from unstable",
                            "    - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "      d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "      Add patches from upstream (to be released in 2.89.4) to address",
                            "      an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "      and fix a related test failure on minimal systems",
                            "      (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            "  * d/p/workarounds: Mark memory-monitor-psi tests as flaky",
                            "    (Mitigates: #1143197, #1143241)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-4",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 21:28:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon McVittie ]",
                            "  * Merge packaging from unstable",
                            "    - d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "      by ensuring that user-session-migration gets removed rather than",
                            "      making libglib2.0-0t64 be reinstalled",
                            "  * Drop patches added by 2.88.3-2, already part of 2.89.x",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 06 Aug 2026 14:23:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate",
                            "    previous changelog entry",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * debian/libglib2.0-0t64.symbols: Add new symbols",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 15:55:39 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes possible integer underflow when parsing D-Bus introspection XML",
                            "      (CVE-2026-58016, Closes: #1141316)",
                            "    - Fixes resource exhaustion if a malicious client can contact a GDBusServer",
                            "      (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p: Refresh patches",
                            "  * d/libglib2.0-0t64.symbols: Add new symbol",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.2-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Fri, 24 Jul 2026 18:58:44 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "    d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "    Add patches from upstream (to be released in 2.89.4) to address",
                            "    an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "    and fix a related test failure on minimal systems",
                            "    (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 10:10:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport patches from 2.89.0 to harden D-Bus introspection parsing",
                            "    - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,",
                            "      d/p/tests-Improve-D-Bus-introspection-test-paths.patch,",
                            "      d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,",
                            "      d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:",
                            "      Avoid a possible integer underflow if parsing malformed D-Bus",
                            "      introspection XML sent by a malicious service",
                            "      (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)",
                            "  * d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "    by ensuring that user-session-migration gets removed rather than",
                            "    making libglib2.0-0t64 be reinstalled",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:22:30 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "    - Fixes resource exhaustion if a malicious client can contact a",
                            "      GDBusServer (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/control, d/gbp.conf: Use debian/forky branch",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:13:54 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "  * d/watch: Only watch for stable (even-numbered) branches",
                            "  * d/gbp.conf: Use upstream/2.88.x branch.",
                            "    Initial 2.89.x versions have been released upstream.",
                            "  * d/control: Move Build-Profiles from libglib2.0-0t64 back to",
                            "    libglib2.0-tests. This was mistakenly moved by `cme fix dpkg`",
                            "    in the previous upload.",
                            "  * Ignore another Lintian false positive in the test data",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Thu, 25 Jun 2026 19:05:13 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libglib2.0-0t64",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.88.1-2",
                    "version": "2.88.1-2"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.90.0-1",
                    "version": "2.90.0-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.90.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Thu, 10 Sep 2026 12:07:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Re-upload with orig tarball, no source changes",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 19:33:06 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes a main-loop regression in 2.89.3 (mutter#4994 upstream)",
                            "  * d/patches: Drop patches that were part of the upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 18:52:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Fri, 21 Aug 2026 16:37:11 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from unstable",
                            "    - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "      d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "      Add patches from upstream (to be released in 2.89.4) to address",
                            "      an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "      and fix a related test failure on minimal systems",
                            "      (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            "  * d/p/workarounds: Mark memory-monitor-psi tests as flaky",
                            "    (Mitigates: #1143197, #1143241)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-4",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 21:28:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon McVittie ]",
                            "  * Merge packaging from unstable",
                            "    - d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "      by ensuring that user-session-migration gets removed rather than",
                            "      making libglib2.0-0t64 be reinstalled",
                            "  * Drop patches added by 2.88.3-2, already part of 2.89.x",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 06 Aug 2026 14:23:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate",
                            "    previous changelog entry",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * debian/libglib2.0-0t64.symbols: Add new symbols",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 30 Jul 2026 15:55:39 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes possible integer underflow when parsing D-Bus introspection XML",
                            "      (CVE-2026-58016, Closes: #1141316)",
                            "    - Fixes resource exhaustion if a malicious client can contact a GDBusServer",
                            "      (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p: Refresh patches",
                            "  * d/libglib2.0-0t64.symbols: Add new symbol",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.2-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Fri, 24 Jul 2026 18:58:44 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,",
                            "    d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:",
                            "    Add patches from upstream (to be released in 2.89.4) to address",
                            "    an out-of-bounds write if parsing a crafted XDG MIME magic file,",
                            "    and fix a related test failure on minimal systems",
                            "    (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Wed, 12 Aug 2026 10:10:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport patches from 2.89.0 to harden D-Bus introspection parsing",
                            "    - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,",
                            "      d/p/tests-Improve-D-Bus-introspection-test-paths.patch,",
                            "      d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,",
                            "      d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:",
                            "      Avoid a possible integer underflow if parsing malformed D-Bus",
                            "      introspection XML sent by a malicious service",
                            "      (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)",
                            "  * d/tests/1065022-futureproofing: Make the test pass more reliably,",
                            "    by ensuring that user-session-migration gets removed rather than",
                            "    making libglib2.0-0t64 be reinstalled",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:22:30 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "    - Fixes resource exhaustion if a malicious client can contact a",
                            "      GDBusServer (CVE-2026-15588, Closes: #1142835)",
                            "  * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:",
                            "    Add patch from upstream to fix autopkgtest regression",
                            "  * d/control, d/gbp.conf: Use debian/forky branch",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Fri, 31 Jul 2026 21:13:54 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream stable release",
                            "  * d/watch: Only watch for stable (even-numbered) branches",
                            "  * d/gbp.conf: Use upstream/2.88.x branch.",
                            "    Initial 2.89.x versions have been released upstream.",
                            "  * d/control: Move Build-Profiles from libglib2.0-0t64 back to",
                            "    libglib2.0-tests. This was mistakenly moved by `cme fix dpkg`",
                            "    in the previous upload.",
                            "  * Ignore another Lintian false positive in the test data",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.88.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Thu, 25 Jun 2026 19:05:13 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgnutls30t64",
                "from_version": {
                    "source_package_name": "gnutls28",
                    "source_package_version": "3.8.12-2ubuntu1.1",
                    "version": "3.8.12-2ubuntu1.1"
                },
                "to_version": {
                    "source_package_name": "gnutls28",
                    "source_package_version": "3.8.13-1ubuntu1",
                    "version": "3.8.13-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-33846",
                        "url": "https://ubuntu.com/security/CVE-2026-33846",
                        "cve_description": "A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-04 10:15:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42009",
                        "url": "https://ubuntu.com/security/CVE-2026-42009",
                        "cve_description": "A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-18 13:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-33845",
                        "url": "https://ubuntu.com/security/CVE-2026-33845",
                        "cve_description": "A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-3832",
                        "url": "https://ubuntu.com/security/CVE-2026-3832",
                        "cve_description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-3833",
                        "url": "https://ubuntu.com/security/CVE-2026-3833",
                        "cve_description": "A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42011",
                        "url": "https://ubuntu.com/security/CVE-2026-42011",
                        "cve_description": "A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-07 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42010",
                        "url": "https://ubuntu.com/security/CVE-2026-42010",
                        "cve_description": "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-07 12:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5260",
                        "url": "https://ubuntu.com/security/CVE-2026-5260",
                        "cve_description": "A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42012",
                        "url": "https://ubuntu.com/security/CVE-2026-42012",
                        "cve_description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42013",
                        "url": "https://ubuntu.com/security/CVE-2026-42013",
                        "cve_description": "A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42014",
                        "url": "https://ubuntu.com/security/CVE-2026-42014",
                        "cve_description": "A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-16 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42015",
                        "url": "https://ubuntu.com/security/CVE-2026-42015",
                        "cve_description": "A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5419",
                        "url": "https://ubuntu.com/security/CVE-2026-5419",
                        "cve_description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-01 21:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2155651,
                    2150202
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-33846",
                                "url": "https://ubuntu.com/security/CVE-2026-33846",
                                "cve_description": "A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-04 10:15:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42009",
                                "url": "https://ubuntu.com/security/CVE-2026-42009",
                                "cve_description": "A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-18 13:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-33845",
                                "url": "https://ubuntu.com/security/CVE-2026-33845",
                                "cve_description": "A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-3832",
                                "url": "https://ubuntu.com/security/CVE-2026-3832",
                                "cve_description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-3833",
                                "url": "https://ubuntu.com/security/CVE-2026-3833",
                                "cve_description": "A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42011",
                                "url": "https://ubuntu.com/security/CVE-2026-42011",
                                "cve_description": "A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-07 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42010",
                                "url": "https://ubuntu.com/security/CVE-2026-42010",
                                "cve_description": "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-07 12:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5260",
                                "url": "https://ubuntu.com/security/CVE-2026-5260",
                                "cve_description": "A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42012",
                                "url": "https://ubuntu.com/security/CVE-2026-42012",
                                "cve_description": "A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42013",
                                "url": "https://ubuntu.com/security/CVE-2026-42013",
                                "cve_description": "A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42014",
                                "url": "https://ubuntu.com/security/CVE-2026-42014",
                                "cve_description": "A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-16 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42015",
                                "url": "https://ubuntu.com/security/CVE-2026-42015",
                                "cve_description": "A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5419",
                                "url": "https://ubuntu.com/security/CVE-2026-5419",
                                "cve_description": "A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-01 21:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2155651, LP: #2150202). Remaining changes:",
                            "    - d/p/9259100633b7: Enable CET support.",
                            "    - d/c/config: Forcefully disable TLS 1.0 and 1.1.",
                            "    - d/c/config: Forcefully disable DTLS 0.9 and 1.0.",
                            "    - d/rules: Set priority to only allow TLS1.2, DTLS1.2 and TLS1.3.",
                            "  * Drop Changes:",
                            "    - present upstream: d/p/CVE-2026-33846*.patch",
                            "    - present upstream: d/p/CVE-2026-42009-*.patch",
                            "    - present upstream: d/p/CVE-2026-33845*.patch",
                            "    - present upstream: d/p/CVE-2026-3832.patch",
                            "    - present upstream: d/p/CVE-2026-3833.patch",
                            "    - present upstream: d/p/CVE-2026-42011.patch",
                            "    - present upstream: d/p/CVE-2026-42010.patch",
                            "    - present upstream: d/p/CVE-2026-5260-*.patch",
                            "    - present upstream: d/p/CVE-2026-42012*.patch",
                            "    - present upstream: d/p/CVE-2026-42013*.patch",
                            "    - present upstream: d/p/CVE-2026-42014.patch",
                            "    - present upstream: d/p/CVE-2026-42015.patch",
                            "    - present upstream: d/p/CVE-2026-5419*.patch",
                            "    - d/p/crypto-config.patch",
                            "  * New Changes:",
                            "    - d/p/fix_test-getaddrinfo.patch: Avoid failure in CI due to unreachable DNS server.",
                            ""
                        ],
                        "package": "gnutls28",
                        "version": "3.8.13-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2155651,
                            2150202
                        ],
                        "author": "Ghadi Elie Rahme <ghadi.rahme@canonical.com>",
                        "date": "Wed, 17 Jun 2026 19:36:03 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream bugfix/security release.",
                            "  * Unfuzz patches.",
                            "  * Update copyright info.",
                            "  * Update symbol file.",
                            ""
                        ],
                        "package": "gnutls28",
                        "version": "3.8.13-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Fri, 01 May 2026 07:19:11 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop OpenSSL wrapper library again.",
                            ""
                        ],
                        "package": "gnutls28",
                        "version": "3.8.12-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Sat, 21 Feb 2026 13:31:21 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgssapi-krb5-2",
                "from_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-2ubuntu4",
                    "version": "1.22.1-2ubuntu4"
                },
                "to_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-3ubuntu2",
                    "version": "1.22.1-3ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-11850",
                        "url": "https://ubuntu.com/security/CVE-2026-11850",
                        "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-11 10:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40355",
                        "url": "https://ubuntu.com/security/CVE-2026-40355",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40356",
                        "url": "https://ubuntu.com/security/CVE-2026-40356",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153198,
                    2155018
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:57:38 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153198, LP: #2155018). Remaining changes:",
                            "    - d/t/util: add test cleanup and log function",
                            "    - d/t/util: Prepend includedir /etc/krb5.conf.d/ for the configuration file",
                            "      created in create_realm.",
                            "    - d/t/includedir-ordering: Add new test.",
                            "    - Fix FTBFS test t_otp.py (LP #2142451):",
                            "      + d/p/set-fork-start-method-t-otpy.patch: Python 3.14 changes the default",
                            "        start method of multiprocessing to 'forkserver'. This introduces issues",
                            "        in the test t_otp.py that does not use a main block. Set the start",
                            "        method to force 'fork' instead.",
                            "    - d/p/default-enctype-list.patch: do not default to weak encryption",
                            "      algorithms (LP #2144909)",
                            "    - d/NEWS: explain weak algorithms are no longer default options",
                            "  * Dropped:",
                            "    - d/p/fix-strchr-conformance-to-c23.patch: Fix FTBFS with glibc2.43",
                            "      (LP #2142893)",
                            "      [In 1.22.1-3]",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153198,
                            2155018
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Mon, 29 Jun 2026 15:44:10 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11850",
                                "url": "https://ubuntu.com/security/CVE-2026-11850",
                                "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-11 10:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Emmanuel Arias ]",
                            "  * CVE-2026-11850: Prevent read overrun in libkdb_ldap (Closes: #1139821).",
                            "",
                            "  [ Sam Hartman ]",
                            "  * Fix C23 use of strchr, Closes: #1128877",
                            "  * Remove lintian tag that ldap plugin is linked against libc6; no longer needed",
                            "  * Upstream patch for OpenSSL 4.0 compatibility, Closes: #1138466",
                            "  * Upstream commit f5bbfa4 to use openssl facilities to verify certificates; needed to avoid discarding const qualifier from Openssl 4.0 patch",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sam Hartman <hartmans@debian.org>",
                        "date": "Fri, 19 Jun 2026 08:30:16 -0600"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-40355",
                                "url": "https://ubuntu.com/security/CVE-2026-40355",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-40356",
                                "url": "https://ubuntu.com/security/CVE-2026-40356",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Non-maintainer upload.",
                            "  * Fix two NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)",
                            "    (Closes: #1135317)",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-2.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Salvatore Bonaccorso <carnil@debian.org>",
                        "date": "Sun, 10 May 2026 09:08:30 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libjs-sphinxdoc",
                "from_version": {
                    "source_package_name": "sphinx",
                    "source_package_version": "9.1.0-4",
                    "version": "9.1.0-4"
                },
                "to_version": {
                    "source_package_name": "sphinx",
                    "source_package_version": "9.1.0-6",
                    "version": "9.1.0-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Require texlive-latex-base >= 2026.20260711. Thanks to Hilmar Preuße",
                            "    for the hint!",
                            ""
                        ],
                        "package": "sphinx",
                        "version": "9.1.0-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Dmitry Shachnev <mitya57@debian.org>",
                        "date": "Sat, 18 Jul 2026 20:21:54 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Dmitry Shachnev ]",
                            "  * Replace snowball-3.1.0.diff with the version that was applied upstream.",
                            "  * Add a patch to bump Docutils upper limit to 0.24.",
                            "  * Backport upstream patch to fix LaTeX builds with June 2026 TeX Live",
                            "    (closes: #1142055).",
                            "  * Copy sphinx/locale to the test directory before running tests.",
                            "    This fixes tests when sphinx-common is not installed, e.g. for nodoc.",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * Salsa CI: test the nocheck & nodoc profiles.",
                            "  * Salsa CI: disable two jobs that are useless for packages only building",
                            "    for \"all\" architecture.",
                            ""
                        ],
                        "package": "sphinx",
                        "version": "9.1.0-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Dmitry Shachnev <mitya57@debian.org>",
                        "date": "Fri, 17 Jul 2026 09:59:49 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libk5crypto3",
                "from_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-2ubuntu4",
                    "version": "1.22.1-2ubuntu4"
                },
                "to_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-3ubuntu2",
                    "version": "1.22.1-3ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-11850",
                        "url": "https://ubuntu.com/security/CVE-2026-11850",
                        "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-11 10:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40355",
                        "url": "https://ubuntu.com/security/CVE-2026-40355",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40356",
                        "url": "https://ubuntu.com/security/CVE-2026-40356",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153198,
                    2155018
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:57:38 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153198, LP: #2155018). Remaining changes:",
                            "    - d/t/util: add test cleanup and log function",
                            "    - d/t/util: Prepend includedir /etc/krb5.conf.d/ for the configuration file",
                            "      created in create_realm.",
                            "    - d/t/includedir-ordering: Add new test.",
                            "    - Fix FTBFS test t_otp.py (LP #2142451):",
                            "      + d/p/set-fork-start-method-t-otpy.patch: Python 3.14 changes the default",
                            "        start method of multiprocessing to 'forkserver'. This introduces issues",
                            "        in the test t_otp.py that does not use a main block. Set the start",
                            "        method to force 'fork' instead.",
                            "    - d/p/default-enctype-list.patch: do not default to weak encryption",
                            "      algorithms (LP #2144909)",
                            "    - d/NEWS: explain weak algorithms are no longer default options",
                            "  * Dropped:",
                            "    - d/p/fix-strchr-conformance-to-c23.patch: Fix FTBFS with glibc2.43",
                            "      (LP #2142893)",
                            "      [In 1.22.1-3]",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153198,
                            2155018
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Mon, 29 Jun 2026 15:44:10 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11850",
                                "url": "https://ubuntu.com/security/CVE-2026-11850",
                                "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-11 10:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Emmanuel Arias ]",
                            "  * CVE-2026-11850: Prevent read overrun in libkdb_ldap (Closes: #1139821).",
                            "",
                            "  [ Sam Hartman ]",
                            "  * Fix C23 use of strchr, Closes: #1128877",
                            "  * Remove lintian tag that ldap plugin is linked against libc6; no longer needed",
                            "  * Upstream patch for OpenSSL 4.0 compatibility, Closes: #1138466",
                            "  * Upstream commit f5bbfa4 to use openssl facilities to verify certificates; needed to avoid discarding const qualifier from Openssl 4.0 patch",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sam Hartman <hartmans@debian.org>",
                        "date": "Fri, 19 Jun 2026 08:30:16 -0600"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-40355",
                                "url": "https://ubuntu.com/security/CVE-2026-40355",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-40356",
                                "url": "https://ubuntu.com/security/CVE-2026-40356",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Non-maintainer upload.",
                            "  * Fix two NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)",
                            "    (Closes: #1135317)",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-2.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Salvatore Bonaccorso <carnil@debian.org>",
                        "date": "Sun, 10 May 2026 09:08:30 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libkmod2",
                "from_version": {
                    "source_package_name": "kmod",
                    "source_package_version": "34.2-2ubuntu2",
                    "version": "34.2-2ubuntu2"
                },
                "to_version": {
                    "source_package_name": "kmod",
                    "source_package_version": "34.2-2ubuntu3",
                    "version": "34.2-2ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "kmod",
                        "version": "34.2-2ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 14:28:11 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libkrb5-3",
                "from_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-2ubuntu4",
                    "version": "1.22.1-2ubuntu4"
                },
                "to_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-3ubuntu2",
                    "version": "1.22.1-3ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-11850",
                        "url": "https://ubuntu.com/security/CVE-2026-11850",
                        "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-11 10:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40355",
                        "url": "https://ubuntu.com/security/CVE-2026-40355",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40356",
                        "url": "https://ubuntu.com/security/CVE-2026-40356",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153198,
                    2155018
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:57:38 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153198, LP: #2155018). Remaining changes:",
                            "    - d/t/util: add test cleanup and log function",
                            "    - d/t/util: Prepend includedir /etc/krb5.conf.d/ for the configuration file",
                            "      created in create_realm.",
                            "    - d/t/includedir-ordering: Add new test.",
                            "    - Fix FTBFS test t_otp.py (LP #2142451):",
                            "      + d/p/set-fork-start-method-t-otpy.patch: Python 3.14 changes the default",
                            "        start method of multiprocessing to 'forkserver'. This introduces issues",
                            "        in the test t_otp.py that does not use a main block. Set the start",
                            "        method to force 'fork' instead.",
                            "    - d/p/default-enctype-list.patch: do not default to weak encryption",
                            "      algorithms (LP #2144909)",
                            "    - d/NEWS: explain weak algorithms are no longer default options",
                            "  * Dropped:",
                            "    - d/p/fix-strchr-conformance-to-c23.patch: Fix FTBFS with glibc2.43",
                            "      (LP #2142893)",
                            "      [In 1.22.1-3]",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153198,
                            2155018
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Mon, 29 Jun 2026 15:44:10 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11850",
                                "url": "https://ubuntu.com/security/CVE-2026-11850",
                                "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-11 10:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Emmanuel Arias ]",
                            "  * CVE-2026-11850: Prevent read overrun in libkdb_ldap (Closes: #1139821).",
                            "",
                            "  [ Sam Hartman ]",
                            "  * Fix C23 use of strchr, Closes: #1128877",
                            "  * Remove lintian tag that ldap plugin is linked against libc6; no longer needed",
                            "  * Upstream patch for OpenSSL 4.0 compatibility, Closes: #1138466",
                            "  * Upstream commit f5bbfa4 to use openssl facilities to verify certificates; needed to avoid discarding const qualifier from Openssl 4.0 patch",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sam Hartman <hartmans@debian.org>",
                        "date": "Fri, 19 Jun 2026 08:30:16 -0600"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-40355",
                                "url": "https://ubuntu.com/security/CVE-2026-40355",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-40356",
                                "url": "https://ubuntu.com/security/CVE-2026-40356",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Non-maintainer upload.",
                            "  * Fix two NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)",
                            "    (Closes: #1135317)",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-2.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Salvatore Bonaccorso <carnil@debian.org>",
                        "date": "Sun, 10 May 2026 09:08:30 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libkrb5support0",
                "from_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-2ubuntu4",
                    "version": "1.22.1-2ubuntu4"
                },
                "to_version": {
                    "source_package_name": "krb5",
                    "source_package_version": "1.22.1-3ubuntu2",
                    "version": "1.22.1-3ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-11850",
                        "url": "https://ubuntu.com/security/CVE-2026-11850",
                        "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-11 10:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40355",
                        "url": "https://ubuntu.com/security/CVE-2026-40355",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-40356",
                        "url": "https://ubuntu.com/security/CVE-2026-40356",
                        "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153198,
                    2155018
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:57:38 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153198, LP: #2155018). Remaining changes:",
                            "    - d/t/util: add test cleanup and log function",
                            "    - d/t/util: Prepend includedir /etc/krb5.conf.d/ for the configuration file",
                            "      created in create_realm.",
                            "    - d/t/includedir-ordering: Add new test.",
                            "    - Fix FTBFS test t_otp.py (LP #2142451):",
                            "      + d/p/set-fork-start-method-t-otpy.patch: Python 3.14 changes the default",
                            "        start method of multiprocessing to 'forkserver'. This introduces issues",
                            "        in the test t_otp.py that does not use a main block. Set the start",
                            "        method to force 'fork' instead.",
                            "    - d/p/default-enctype-list.patch: do not default to weak encryption",
                            "      algorithms (LP #2144909)",
                            "    - d/NEWS: explain weak algorithms are no longer default options",
                            "  * Dropped:",
                            "    - d/p/fix-strchr-conformance-to-c23.patch: Fix FTBFS with glibc2.43",
                            "      (LP #2142893)",
                            "      [In 1.22.1-3]",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153198,
                            2155018
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Mon, 29 Jun 2026 15:44:10 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11850",
                                "url": "https://ubuntu.com/security/CVE-2026-11850",
                                "cve_description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-11 10:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Emmanuel Arias ]",
                            "  * CVE-2026-11850: Prevent read overrun in libkdb_ldap (Closes: #1139821).",
                            "",
                            "  [ Sam Hartman ]",
                            "  * Fix C23 use of strchr, Closes: #1128877",
                            "  * Remove lintian tag that ldap plugin is linked against libc6; no longer needed",
                            "  * Upstream patch for OpenSSL 4.0 compatibility, Closes: #1138466",
                            "  * Upstream commit f5bbfa4 to use openssl facilities to verify certificates; needed to avoid discarding const qualifier from Openssl 4.0 patch",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sam Hartman <hartmans@debian.org>",
                        "date": "Fri, 19 Jun 2026 08:30:16 -0600"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-40355",
                                "url": "https://ubuntu.com/security/CVE-2026-40355",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-40356",
                                "url": "https://ubuntu.com/security/CVE-2026-40356",
                                "cve_description": "In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Non-maintainer upload.",
                            "  * Fix two NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)",
                            "    (Closes: #1135317)",
                            ""
                        ],
                        "package": "krb5",
                        "version": "1.22.1-2.1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Salvatore Bonaccorso <carnil@debian.org>",
                        "date": "Sun, 10 May 2026 09:08:30 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "liblocale-gettext-perl",
                "from_version": {
                    "source_package_name": "liblocale-gettext-perl",
                    "source_package_version": "1.07-10",
                    "version": "1.07-10"
                },
                "to_version": {
                    "source_package_name": "liblocale-gettext-perl",
                    "source_package_version": "1.07-10build1",
                    "version": "1.07-10build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "liblocale-gettext-perl",
                        "version": "1.07-10build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Wed, 19 Aug 2026 13:48:00 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libncursesw6",
                "from_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20251231-1",
                    "version": "6.6+20251231-1"
                },
                "to_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20260608-2",
                    "version": "6.6+20260608-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Thu, 02 Jul 2026 17:00:27 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream patchlevel.",
                            "    - Add ech to screen terminfo (Closes: #707308).",
                            "  * Update symbols files.",
                            "  * Update upstream signing key.",
                            "  * Convert the watch files to version 5.",
                            "  * Update years in debian/copyright.",
                            "  * Upgrade Standards-Version to 4.7.4, no changes needed.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-1",
                        "urgency": "low",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Wed, 10 Jun 2026 17:50:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libnetplan1",
                "from_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.1-1ubuntu1",
                    "version": "1.2.1-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.2-1",
                    "version": "1.2.2-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153219,
                    2145061,
                    2147446,
                    2071747,
                    2139598,
                    2138802
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153219). Remaining changes:",
                            "    - Skip test_link_offloading to allow for a green baseline (LP 2126938)",
                            "      + d/p/lp-2126938-skip-test-link-offloading.patch",
                            "  * Dropped:",
                            "    - d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "      3.14 by handling BlockingIOError in addition to TypeError (LP 2138802)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "      execute udev rules before starting sriov apply service (LP 2139598)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "      (LP 2071747)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "      Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "      units. (LP 2145061)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "      networkd to apply dhcp labels to addresses (LP 2147446).",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "      permissions for files not managed by netplan in integration tests.",
                            "      [Included in Debian 1.2.1-1]",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153219
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Thu, 21 May 2026 16:24:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "    Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "    units. (LP: #2145061)",
                            "  * d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "    networkd to apply dhcp labels to addresses (LP: #2147446).",
                            "  * d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "    permissions for files not managed by netplan in integration tests.",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu5",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2145061,
                            2147446
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Wed, 08 Apr 2026 16:47:32 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "    (LP: #2071747)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2071747
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Fri, 20 Mar 2026 16:09:27 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "    execute udev rules before starting sriov apply service (LP: #2139598)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2139598
                        ],
                        "author": "Robert Malz <robert.malz@canonical.com>",
                        "date": "Tue, 03 Mar 2026 12:44:43 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "    3.14 by handling BlockingIOError in addition to TypeError (LP: #2138802)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2138802
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Fri, 20 Feb 2026 11:25:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip test_link_offloading to allow for a green baseline (LP: 2126938)",
                            "    - d/p/lp-2126938-skip-test-link-offloading.patch",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Lukas Märdian <slyon@ubuntu.com>",
                        "date": "Tue, 13 Jan 2026 17:58:24 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "libp11-kit0",
                "from_version": {
                    "source_package_name": "p11-kit",
                    "source_package_version": "0.26.4-1",
                    "version": "0.26.4-1"
                },
                "to_version": {
                    "source_package_name": "p11-kit",
                    "source_package_version": "0.26.5-1",
                    "version": "0.26.5-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-18938",
                        "url": "https://ubuntu.com/security/CVE-2026-18938",
                        "cve_description": "A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-07 09:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-18938",
                                "url": "https://ubuntu.com/security/CVE-2026-18938",
                                "cve_description": "A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-07 09:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "    + rpc: guard against overflow when decoding nested attributes",
                            "      (CVE-2026-18938) Closes: #1144476",
                            ""
                        ],
                        "package": "p11-kit",
                        "version": "0.26.5-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Metzler <ametzler@debian.org>",
                        "date": "Sat, 15 Aug 2026 17:51:12 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpam-modules",
                "from_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu3",
                    "version": "1.7.0-5ubuntu3"
                },
                "to_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu4",
                    "version": "1.7.0-5ubuntu4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-54411",
                        "url": "https://ubuntu.com/security/CVE-2026-54411",
                        "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-14 18:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-54411",
                                "url": "https://ubuntu.com/security/CVE-2026-54411",
                                "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-14 18:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: password recovery via timing discrepancy in pam_userdb",
                            "    module string comparisons",
                            "    - debian/patches/CVE-2026-54411.patch: pam_userdb: fix password comparison",
                            "      timing leak in libpam/include/pam_inline.h,",
                            "      modules/pam_userdb/pam_userdb.c.",
                            "    - CVE-2026-54411",
                            ""
                        ],
                        "package": "pam",
                        "version": "1.7.0-5ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Thu, 16 Jul 2026 09:34:12 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpam-modules-bin",
                "from_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu3",
                    "version": "1.7.0-5ubuntu3"
                },
                "to_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu4",
                    "version": "1.7.0-5ubuntu4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-54411",
                        "url": "https://ubuntu.com/security/CVE-2026-54411",
                        "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-14 18:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-54411",
                                "url": "https://ubuntu.com/security/CVE-2026-54411",
                                "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-14 18:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: password recovery via timing discrepancy in pam_userdb",
                            "    module string comparisons",
                            "    - debian/patches/CVE-2026-54411.patch: pam_userdb: fix password comparison",
                            "      timing leak in libpam/include/pam_inline.h,",
                            "      modules/pam_userdb/pam_userdb.c.",
                            "    - CVE-2026-54411",
                            ""
                        ],
                        "package": "pam",
                        "version": "1.7.0-5ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Thu, 16 Jul 2026 09:34:12 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpam-runtime",
                "from_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu3",
                    "version": "1.7.0-5ubuntu3"
                },
                "to_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu4",
                    "version": "1.7.0-5ubuntu4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-54411",
                        "url": "https://ubuntu.com/security/CVE-2026-54411",
                        "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-14 18:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-54411",
                                "url": "https://ubuntu.com/security/CVE-2026-54411",
                                "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-14 18:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: password recovery via timing discrepancy in pam_userdb",
                            "    module string comparisons",
                            "    - debian/patches/CVE-2026-54411.patch: pam_userdb: fix password comparison",
                            "      timing leak in libpam/include/pam_inline.h,",
                            "      modules/pam_userdb/pam_userdb.c.",
                            "    - CVE-2026-54411",
                            ""
                        ],
                        "package": "pam",
                        "version": "1.7.0-5ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Thu, 16 Jul 2026 09:34:12 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpam-systemd",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpam0g",
                "from_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu3",
                    "version": "1.7.0-5ubuntu3"
                },
                "to_version": {
                    "source_package_name": "pam",
                    "source_package_version": "1.7.0-5ubuntu4",
                    "version": "1.7.0-5ubuntu4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-54411",
                        "url": "https://ubuntu.com/security/CVE-2026-54411",
                        "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-14 18:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-54411",
                                "url": "https://ubuntu.com/security/CVE-2026-54411",
                                "cve_description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-14 18:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: password recovery via timing discrepancy in pam_userdb",
                            "    module string comparisons",
                            "    - debian/patches/CVE-2026-54411.patch: pam_userdb: fix password comparison",
                            "      timing leak in libpam/include/pam_inline.h,",
                            "      modules/pam_userdb/pam_userdb.c.",
                            "    - CVE-2026-54411",
                            ""
                        ],
                        "package": "pam",
                        "version": "1.7.0-5ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Thu, 16 Jul 2026 09:34:12 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpsl5t64",
                "from_version": {
                    "source_package_name": "libpsl",
                    "source_package_version": "0.23.0-1",
                    "version": "0.23.0-1"
                },
                "to_version": {
                    "source_package_name": "libpsl",
                    "source_package_version": "0.23.3-1",
                    "version": "0.23.3-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 0.23.3",
                            ""
                        ],
                        "package": "libpsl",
                        "version": "0.23.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Florian Ernst <florian@debian.org>",
                        "date": "Mon, 17 Aug 2026 15:23:22 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 0.23.2",
                            ""
                        ],
                        "package": "libpsl",
                        "version": "0.23.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Florian Ernst <florian@debian.org>",
                        "date": "Tue, 11 Aug 2026 19:42:40 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 0.23.1",
                            "    - Make the build reproducible (Closes: #1142126, thanks to",
                            "      Chris Lamb <lamby@debian.org> for the Initial patch)",
                            "  * [757c770] d/patches/0003-rename-cdata-in-docs-as-well.patch:",
                            "    obsolete, now upstream",
                            ""
                        ],
                        "package": "libpsl",
                        "version": "0.23.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Florian Ernst <florian@debian.org>",
                        "date": "Sun, 02 Aug 2026 07:25:39 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpython3-stdlib",
                "from_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.3-0ubuntu2",
                    "version": "3.14.3-0ubuntu2"
                },
                "to_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.7-3",
                    "version": "3.14.7-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Remove a missed Python 3.13 dependency.",
                            "  * Update README.Debian.",
                            "",
                            "  [ Simon McVittie ]",
                            "  * policy: Expand the section about package names. (Closes: #791635)",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Thu, 27 Aug 2026 11:09:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Bump to version 3.14.7.",
                            "  * Remove Python 3.13 as a supported version.",
                            "  * Remove references to IronPython and Jython in the package descriptions.",
                            "  * Bump standards version.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 26 Aug 2026 16:45:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            "  * Bump to version 3.14.6.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Sat, 27 Jun 2026 09:14:35 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpython3.14-minimal",
                "from_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.6-1",
                    "version": "3.14.6-1"
                },
                "to_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.7-4ubuntu1",
                    "version": "3.14.7-4ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert the module-install-* autopkg tests to run with setuptools v78.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:51:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-13.",
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Re-enable the module-install-* autopkgtests, updated for setuptools 80.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:30:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-05.",
                            "  * Disable the module-install-* autopkg tests for now.",
                            "  * Update symbols file.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sat, 05 Sep 2026 07:55:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-01.",
                            "    - Reworks the test_typing stack test. Closes: #1146095.",
                            "  * Apply the OpenSSL 4.0 patches from the 3.15 branch. Closes: #1137595.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 11:47:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Python 3.14.7 release.",
                            "  * Drop the the min-pyrepl patch, handled by an upstream backport.",
                            "  * Refresh patches.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 11 Aug 2026 10:48:35 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpython3.14-stdlib",
                "from_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.6-1",
                    "version": "3.14.6-1"
                },
                "to_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.7-4ubuntu1",
                    "version": "3.14.7-4ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert the module-install-* autopkg tests to run with setuptools v78.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:51:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-13.",
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Re-enable the module-install-* autopkgtests, updated for setuptools 80.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:30:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-05.",
                            "  * Disable the module-install-* autopkg tests for now.",
                            "  * Update symbols file.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sat, 05 Sep 2026 07:55:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-01.",
                            "    - Reworks the test_typing stack test. Closes: #1146095.",
                            "  * Apply the OpenSSL 4.0 patches from the 3.15 branch. Closes: #1137595.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 11:47:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Python 3.14.7 release.",
                            "  * Drop the the min-pyrepl patch, handled by an upstream backport.",
                            "  * Refresh patches.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 11 Aug 2026 10:48:35 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libseccomp2",
                "from_version": {
                    "source_package_name": "libseccomp",
                    "source_package_version": "2.6.0-2ubuntu5",
                    "version": "2.6.0-2ubuntu5"
                },
                "to_version": {
                    "source_package_name": "libseccomp",
                    "source_package_version": "2.6.1-1ubuntu1",
                    "version": "2.6.1-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable. Remaining changes:",
                            "    - Add autopkgtests",
                            "  * Dropped changes, no longer needed:",
                            "    - d/t/testsuite-live-python3: skip on Ubuntu armhf LXD (LP 2051118)",
                            "      [ This test is already marked isolation-machine ]",
                            ""
                        ],
                        "package": "libseccomp",
                        "version": "2.6.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Mon, 13 Jul 2026 07:34:33 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Drop patches that have been applied upstream:",
                            "    - tests_remove_the_fuzzer_from_test_62-sim-arch_transactions.patch",
                            "    - hash_fix_strict_aliasing_UB_in_MurMur_hash_implementation.patch",
                            "    - api_fix_seccomp_export_bpf_mem_out-of-bounds_read.patch",
                            ""
                        ],
                        "package": "libseccomp",
                        "version": "2.6.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Felix Geyer <fgeyer@debian.org>",
                        "date": "Thu, 09 Jul 2026 22:49:20 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libselinux1",
                "from_version": {
                    "source_package_name": "libselinux",
                    "source_package_version": "3.10-1",
                    "version": "3.10-1"
                },
                "to_version": {
                    "source_package_name": "libselinux",
                    "source_package_version": "3.11-2",
                    "version": "3.11-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move tmpfiles.d from libselinux1 to selinux-utils (Closes: #1140305)",
                            "",
                            "  [ Christian Göttsche ]",
                            "  * d/patches: add patches to please non-release architectures",
                            ""
                        ],
                        "package": "libselinux",
                        "version": "3.11-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Christian Göttsche <cgzones@googlemail.com>",
                        "date": "Sat, 11 Jul 2026 11:58:50 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 3.11",
                            "",
                            "  * d/patches: rebase and drop upstream applied patches",
                            "  * d/control:",
                            "    - bump Standards-Version to 4.7.4 (no further changes)",
                            "    - update homepage",
                            "    - bump libsepol build-dep version",
                            "    - bump to debhelper compat level 14",
                            "    - add python3-build as build-dep",
                            "    - add Replaces to libselinux-dev to ease transition",
                            "  * d/tests/control: switch to modern pkgconf dependency",
                            "  * d/selinux_compile_fcontexts: misc tweaks",
                            "  * d/rules: fix build during python transition",
                            ""
                        ],
                        "package": "libselinux",
                        "version": "3.11-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Christian Göttsche <cgzones@googlemail.com>",
                        "date": "Tue, 07 Jul 2026 21:03:26 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsemanage-common",
                "from_version": {
                    "source_package_name": "libsemanage",
                    "source_package_version": "3.10-1",
                    "version": "3.10-1"
                },
                "to_version": {
                    "source_package_name": "libsemanage",
                    "source_package_version": "3.11-1",
                    "version": "3.11-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Christian Göttsche ]",
                            "  * New upstream version 3.11",
                            "",
                            "  * d/patches: rebase",
                            "  * d/gitlab-ci.yml: drop obsolete build-twice job",
                            "  * d/control:",
                            "    - update homepage",
                            "    - bump Standards-Version to 4.7.4 (no further changes)",
                            "    - drop fields Priority and R^3 with default values",
                            "    - bump SELinux userland build-dep versions",
                            "    - bump to debhelper compat 14",
                            "    - add libaudit-dev to libsemanage-dev build-deps",
                            "    - drop unused substitution variables",
                            "  * d/clean: drop obsolete entries",
                            "",
                            "  [ Russell Coker ]",
                            "  * Uploading Christian's git committed code because it works well, is better",
                            "    than what's currently in Debian, and allows new versions of other",
                            "    packages to get into Debian.",
                            ""
                        ],
                        "package": "libsemanage",
                        "version": "3.11-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Russell Coker <russell@coker.com.au>",
                        "date": "Sat, 11 Jul 2026 11:45:36 +1000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsemanage2",
                "from_version": {
                    "source_package_name": "libsemanage",
                    "source_package_version": "3.10-1",
                    "version": "3.10-1"
                },
                "to_version": {
                    "source_package_name": "libsemanage",
                    "source_package_version": "3.11-1",
                    "version": "3.11-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Christian Göttsche ]",
                            "  * New upstream version 3.11",
                            "",
                            "  * d/patches: rebase",
                            "  * d/gitlab-ci.yml: drop obsolete build-twice job",
                            "  * d/control:",
                            "    - update homepage",
                            "    - bump Standards-Version to 4.7.4 (no further changes)",
                            "    - drop fields Priority and R^3 with default values",
                            "    - bump SELinux userland build-dep versions",
                            "    - bump to debhelper compat 14",
                            "    - add libaudit-dev to libsemanage-dev build-deps",
                            "    - drop unused substitution variables",
                            "  * d/clean: drop obsolete entries",
                            "",
                            "  [ Russell Coker ]",
                            "  * Uploading Christian's git committed code because it works well, is better",
                            "    than what's currently in Debian, and allows new versions of other",
                            "    packages to get into Debian.",
                            ""
                        ],
                        "package": "libsemanage",
                        "version": "3.11-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Russell Coker <russell@coker.com.au>",
                        "date": "Sat, 11 Jul 2026 11:45:36 +1000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsqlite3-0",
                "from_version": {
                    "source_package_name": "sqlite3",
                    "source_package_version": "3.46.1-9",
                    "version": "3.46.1-9"
                },
                "to_version": {
                    "source_package_name": "sqlite3",
                    "source_package_version": "3.53.4-2",
                    "version": "3.53.4-2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-50813",
                        "url": "https://ubuntu.com/security/CVE-2026-50813",
                        "cve_description": "An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11822",
                        "url": "https://ubuntu.com/security/CVE-2026-11822",
                        "cve_description": "SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 20:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11824",
                        "url": "https://ubuntu.com/security/CVE-2026-11824",
                        "cve_description": "SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 20:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-50813",
                                "url": "https://ubuntu.com/security/CVE-2026-50813",
                                "cve_description": "An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport upstream security fix for CVE-2026-50813: buffer overread in the",
                            "    session module.",
                            ""
                        ],
                        "package": "sqlite3",
                        "version": "3.53.4-2",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sat, 01 Aug 2026 12:03:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "sqlite3",
                        "version": "3.53.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sun, 26 Jul 2026 17:45:11 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Helmut Grohne <helmut@subdivi.de> ]",
                            "  * Fix FTCBFS (closes: #1140712):",
                            "    + The new TCL-based configure requires option values to be separated with",
                            "      equal signs.",
                            "    + Build a host architecture lemon.",
                            "    + Use a host architecture pkg-config for a host compilation step.",
                            "",
                            "  [ Laszlo Boszormenyi (GCS) ]",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "sqlite3",
                        "version": "3.53.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sat, 27 Jun 2026 11:28:50 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-11822",
                                "url": "https://ubuntu.com/security/CVE-2026-11822",
                                "cve_description": "SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 20:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11824",
                                "url": "https://ubuntu.com/security/CVE-2026-11824",
                                "cve_description": "SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 20:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1139960):",
                            "    - fixes CVE-2026-11822: memory corruption vulnerabilities in the FTS5",
                            "      full-text search extension,",
                            "    - fixes CVE-2026-11824: heap-based buffer overflow vulnerability in the",
                            "      FTS5 full-text search extension.",
                            "  * Remove sqlite3JsonTableFunctions@Base, sqlite3TriggerStepSrc@Base and",
                            "    sqlite3VdbeCheckFk@Base symbols as no longer part of the library.",
                            "  * Update symbols file.",
                            "  * Update watch file.",
                            ""
                        ],
                        "package": "sqlite3",
                        "version": "3.53.2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sat, 13 Jun 2026 21:08:12 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libstdc++6",
                "from_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.1.0-2ubuntu1",
                    "version": "16.1.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-2ubuntu1",
                    "version": "16.2.0-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158577
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Wed, 02 Sep 2026 10:52:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260902 from the gcc-16 branch.",
                            "    - Fix PR middle-end/127098, PR tree-optimization/127105,",
                            "      PR tree-optimization/127100, PR target/120681 (PPC),",
                            "      PR target/120528 (PPC), PR target/99293 (PPC), PR target/117487 (PPC),",
                            "      PR ada/125984, PR ipa/127023, PR target/126873 (RISCV),",
                            "      PR rtl-optimization/126426, PR target/127004 (AVR), PR middle-end/126939,",
                            "      PR target/126787 (x86), PR target/126513 (PPC),",
                            "      PR target/124629 (AArch64), PR tree-optimization/126925,",
                            "      PR tree-optimization/126650, PR tree-optimization/126926,",
                            "      PR tree-optimization/126534, PR target/126454 (RISCV),",
                            "      PR target/126334 (RISCV), PR target/126550 (RISCV),",
                            "      PR target/126676 (x86), PR target/126320 (x86), PR target/126450 (x86),",
                            "      PR target/126529 (x86), PR ada/127026, PR ada/127026, PR ada/126928,",
                            "      PR ada/126907, PR c++/127046, PR c++/124888, PR c++/126335,",
                            "      PR c++/124794, PR c++/126546, PR c++/124811, PR c++/126918,",
                            "      PR c++/126867, PR c++/126752, PR c++/126093, PR c++/126483,",
                            "      PR c++/126754, PR c++/126783, PR c++/124794, PR c++/125069,",
                            "      PR c++/124806, PR fortran/98573, PR fortran/105594, PR fortran/88632,",
                            "      PR fortran/104630, PR fortran/126872, PR fortran/110626,",
                            "      PR fortran/104048, PR target/125803 (PPC), PR libstdc++/118665,",
                            "      PR libstdc++/123510, PR libstdc++/122981, PR libstdc++/127006,",
                            "      PR libstdc++/126731, PR libstdc++/125981, PR libstdc++/126452,",
                            "      PR libstdc++/126849.",
                            "  * Only enable LRA by default on m68k for snapshot builds. Closes: #1143971.",
                            "  * Don't apply the SH LRA patches for snapshot builds. Closes: #1146439.",
                            "  * Disable usage stats for the build.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 02 Sep 2026 11:07:42 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 09 Aug 2026 06:21:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * GCC 16.2.0 release.",
                            "    - Fix PR target/126581 (x86), PR tree-optimization/126504,",
                            "      PR tree-optimization/126503, PR middle-end/126497,",
                            "      PR tree-optimization/126490, PR tree-optimization/126464,",
                            "      PR tree-optimization/126476, PR tree-optimization/126464,",
                            "      PR middle-end/126084, PR tree-optimization/126471, PR target/126446,",
                            "      PR middle-end/126410, PR tree-optimization/126457,",
                            "      PR tree-optimization/126404, PR tree-optimization/126404,",
                            "      PR target/126438 (PPC), PR target/126450 (x86), PR middle-end/126447,",
                            "      PR middle-end/126405, PR rtl-optimization/126184,",
                            "      PR rtl-optimization/126184, PR target/126429 (x86),",
                            "      PR tree-optimization/125396, PR tree-optimization/125290,",
                            "      PR target/126320 (x86), PR middle-end/126341, PR target/123625 (AArch64),",
                            "      PR target/121957 (AArch64), PR rtl-optimization/125209,",
                            "      PR middle-end/124637, PR tree-optimization/126171,",
                            "      PR tree-optimization/126225, PR tree-optimization/124663, PR ipa/125207,",
                            "      PR target/119210 (AArch64), PR target/105116, PR driver/1240,",
                            "      PR ada/126553, PR ada/126379, PR ada/126482, PR algol68/126330,",
                            "      PR c++/126309, PR c++/126508, PR c++/126420, PR c++/126423,",
                            "      PR c++/126343, PR c++/126406, PR c++/119343, PR c++/126209,",
                            "      PR c++/126310, PR c++/126280, PR c++/126215, PR driver/124058,",
                            "      PR fortran/125866, PR fortran/126386, PR fortran/126303,",
                            "      PR fortran/97592, PR fortran/125998, PR sanitizer/126307,",
                            "      PR libstdc++/122197, PR libstdc++/124854, PR libstdc++/116110,",
                            "      PR libstdc++/124853, PR libstdc++/116110, PR libstdc++/124852,",
                            "      PR libstdc++/124852, PR libstdc++/124851, PR libstdc++/123165.",
                            "  * Update to git 20260809 from the gcc-16 branch.",
                            "    - Fix PR target/126484 (MIPS), PR tree-optimization/126576,",
                            "      PR tree-optimization/126547, PR tree-optimization/126549,",
                            "      PR tree-optimization/126564, PR tree-optimization/126601,",
                            "      PR target/124948, PR tree-optimization/126464, PR preprocessor/125048,",
                            "      PR libstdc++/125200, PR c++/125591, PR c++/125601, PR c++/125680,",
                            "      PR c++/125541, PR fortran/126205, PR target/126667 (S390),",
                            "      PR fortran/125263.",
                            "",
                            "  [ Matthias Klose ]",
                            "  * Update libgcc-s, libcc1, libasan and libgcobol symbols files.",
                            "  * d/rules2: Use rva23u64 with zifencei extension for Ubuntu (Vladimir Petko).",
                            "    LP: #2158577.",
                            "  * d/rules: Reformat riscv64 extensions for Debian.",
                            "  * Configure with --enable-checking=release on every architecture.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * d/rules2: Use rva20u64 with zifencei extension for Debian.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2158577
                        ],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 09 Aug 2026 06:10:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            "    - Work-around the 80GB chroot size on the Ubuntu buildds.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Sun, 19 Jul 2026 14:16:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260719 from the gcc-16 branch.",
                            "    - Fix PR tree-optimization/126262, PR tree-optimization/126257,",
                            "      PR middle-end/126084, PR tree-optimization/120201,",
                            "      PR tree-optimization/126194, PR tree-optimization/126150,",
                            "      PR tree-optimization/125953, PR middle-end/125875,",
                            "      PR tree-optimization/125786, PR tree-optimization/125668,",
                            "      PR tree-optimization/125296, PR tree-optimization/126008,",
                            "      PR tree-optimization/125730, PR tree-optimization/125040,",
                            "      PR ipa/125121, PR ipa/124128, PR target/126054 (S390),",
                            "      PR target/126148 (x86), PR tree-optimization/125597,",
                            "      PR tree-optimization/125597, PR tree-optimization/125597,",
                            "      PR target/126081 (or1k), PR target/126049 (RISCV),",
                            "      PR target/126098 (x86), PR target/67459 (SH), PR target/122948 (SH),",
                            "      PR target/125972 (S390), PR rtl-optimization/125173,",
                            "      PR target/124908 (AArch64), PR target/125838 (AArch64),",
                            "      PR target/125883 (x86), PR target/125818 (AArch64),",
                            "      PR target/125469 (x86), PR target/125469 (x86), PR target/125949 (x86),",
                            "      PR target/125992 (S390), PR middle-end/125977, PR target/125628 (MIPS),",
                            "      PR target/125478 (RISCV), PR target/106895 (PPC), PR target/122665 (PPC),",
                            "      PR target/125670 (RISCV), PR middle-end/125621,",
                            "      PR target/125148 (AArch64), PR tree-optimization/125431,",
                            "      PR target/125795 (AArch64), PR tree-optimization/125501,",
                            "      PR tree-optimization/125776, PR tree-optimization/125774,",
                            "      PR target/120144 (MIPS), PR ipa/125699, PR tree-optimization/125419,",
                            "      PR tree-optimization/125652, PR tree-optimization/125686,",
                            "      PR tree-optimization/125646, PR tree-optimization/125553,",
                            "      PR tree-optimization/125545, PR tree-optimization/125502,",
                            "      PR tree-optimization/125477, PR target/124948, PR c/125072, PR c/125935,",
                            "      PR c/125604, PR c/123569, PR c/125252, PR c/124303, PR c/124985,",
                            "      PR c++/126057, PR c++/126036, PR c++/126007, PR c++/125674, PR c++/91155,",
                            "      PR c++/126066, PR c++/125901, PR c++/126031, PR c++/121552, PR c++/124584,",
                            "      PR c++/121094, PR c++/117259, PR c++/123536, PR c++/125900, PR c++/125334,",
                            "      PR c++/125768, PR c++/125939, PR c++/125745, PR c++/125408, PR c++/124978,",
                            "      PR c++/115314, PR c++/125889, PR c++/125764, PR c++/125759, PR c++/65271,",
                            "      PR c++/125770, PR fortran/126234, PR fortran/125172, PR fortran/126210,",
                            "      PR fortran/126170, PR fortran/126127, PR fortran/103367,",
                            "      PR fortran/126018, PR fortran/125051, PR fortran/125902,",
                            "      PR fortran/125902, PR fortran/60576, PR fortran/125430,",
                            "      PR fortran/125527, PR fortran/125535, PR fortran/125650,",
                            "      PR fortran/125481, PR fortran/125527, PR fortran/125528,",
                            "      PR fortran/125529, PR fortran/125530, PR fortran/125531,",
                            "      PR fortran/125534, PR fortran/125535, PR lto/125257, PR libgcc/123976,",
                            "      PR target/125752 (AVR), PR libfortran/126116, PR libstdc++/126111,",
                            "      PR libstdc++/125956, PR libstdc++/118158, PR libstdc++/125228,",
                            "      PR libstdc++/125890.",
                            "  * Let the ada build fail on an alihash mismatch, if fail_on_alihash_mismatch",
                            "    is enabled.",
                            "  * Enable Modula-2 on powerpc and ppc64. Closes: #1141560, #1141596.",
                            "  * Enable LRA by default on m68k for snapshot builds (Adrian Glaubitz).",
                            "    Addresses: #1142039.",
                            "  * Disable running tests on Debian/riscv64 for meaningful build times.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.1.0-3",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 19 Jul 2026 13:28:39 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsystemd-shared",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsystemd0",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libtext-charwidth-perl",
                "from_version": {
                    "source_package_name": "libtext-charwidth-perl",
                    "source_package_version": "0.04-12",
                    "version": "0.04-12"
                },
                "to_version": {
                    "source_package_name": "libtext-charwidth-perl",
                    "source_package_version": "0.04-12build1",
                    "version": "0.04-12build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Rebuild against current perl",
                            ""
                        ],
                        "package": "libtext-charwidth-perl",
                        "version": "0.04-12build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <tjaalton@debian.org>",
                        "date": "Wed, 19 Aug 2026 10:14:13 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libtinfo6",
                "from_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20251231-1",
                    "version": "6.6+20251231-1"
                },
                "to_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20260608-2",
                    "version": "6.6+20260608-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Thu, 02 Jul 2026 17:00:27 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream patchlevel.",
                            "    - Add ech to screen terminfo (Closes: #707308).",
                            "  * Update symbols files.",
                            "  * Update upstream signing key.",
                            "  * Convert the watch files to version 5.",
                            "  * Update years in debian/copyright.",
                            "  * Upgrade Standards-Version to 4.7.4, no changes needed.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-1",
                        "urgency": "low",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Wed, 10 Jun 2026 17:50:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libudev1",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libzstd1",
                "from_version": {
                    "source_package_name": "libzstd",
                    "source_package_version": "1.5.7+dfsg-3",
                    "version": "1.5.7+dfsg-3"
                },
                "to_version": {
                    "source_package_name": "libzstd",
                    "source_package_version": "1.5.7+dfsg-4",
                    "version": "1.5.7+dfsg-4"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Declare compliance with Policy 4.7.4 with no changes.",
                            "  * Switch back to debhelper-compat now that debhelper 14 is out.",
                            ""
                        ],
                        "package": "libzstd",
                        "version": "1.5.7+dfsg-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Peter Pentchev <roam@debian.org>",
                        "date": "Sat, 01 Aug 2026 19:42:00 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-base",
                "from_version": {
                    "source_package_name": "linux-base",
                    "source_package_version": "4.15ubuntu5",
                    "version": "4.15ubuntu5"
                },
                "to_version": {
                    "source_package_name": "linux-base",
                    "source_package_version": "4.17ubuntu1",
                    "version": "4.17ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1877088,
                    1929255,
                    1928700,
                    1867820,
                    1881338,
                    1932582,
                    2018128,
                    2098735,
                    21465330,
                    1877088,
                    1929255,
                    1928700,
                    1867820,
                    1881338,
                    1932582,
                    2018128,
                    2098735,
                    21465330
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from debian unstable. Remaining changes:",
                            "    - Default to link_in_boot by default, on all architectures.",
                            "    - Add kernel postinst hook to update initrd softlinks to match the kernel",
                            "      version targets (LP: #1877088, #1929255).",
                            "    - Check for update-initramfs being installed before running the postinst",
                            "      hook which updates the softlinks (LP: #1928700).",
                            "    - Add linux-base-sgx package with SGX udev rules (LP: #1867820, #1881338,",
                            "      #1932582).",
                            "    - Add Apport package hook and links for kernel packages (LP: #2018128,",
                            "      #2098735, #21465330).",
                            "    - Change package maintainer to Ubuntu Kernel Team.",
                            "  * Update kernel links for Apport for Stonking.",
                            ""
                        ],
                        "package": "linux-base",
                        "version": "4.17ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1877088,
                            1929255,
                            1928700,
                            1867820,
                            1881338,
                            1932582,
                            2018128,
                            2098735,
                            21465330
                        ],
                        "author": "Juerg Haefliger <juerg.haefliger@canonical.com>",
                        "date": "Mon, 14 Sep 2026 08:58:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Also copy config file to /boot.",
                            "  * New hooks ignore all calls by unpackaged kernels. (closes: #1144902)",
                            ""
                        ],
                        "package": "linux-base",
                        "version": "4.17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Blank <waldi@debian.org>",
                        "date": "Wed, 02 Sep 2026 12:32:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from debian unstable. Remaining changes:",
                            "    - Default to link_in_boot by default, on all architectures.",
                            "    - Add kernel postinst hook to update initrd softlinks to match the kernel",
                            "      version targets (LP: #1877088, #1929255).",
                            "    - Check for update-initramfs being installed before running the postinst",
                            "      hook which updates the softlinks (LP: #1928700).",
                            "    - Add linux-base-sgx package with SGX udev rules (LP: #1867820, #1881338,",
                            "      #1932582).",
                            "    - Add Apport package hook and links for kernel packages (LP: #2018128,",
                            "      #2098735, #21465330).",
                            "    - Change package maintainer to Ubuntu Kernel Team.",
                            ""
                        ],
                        "package": "linux-base",
                        "version": "4.16ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1877088,
                            1929255,
                            1928700,
                            1867820,
                            1881338,
                            1932582,
                            2018128,
                            2098735,
                            21465330
                        ],
                        "author": "Juerg Haefliger <juerg.haefliger@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:44:02 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Simplify install file.",
                            "  * Add hooks to copy vmlinuz file to /boot.",
                            ""
                        ],
                        "package": "linux-base",
                        "version": "4.16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Blank <waldi@debian.org>",
                        "date": "Sun, 16 Aug 2026 14:33:17 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-image-virtual",
                "from_version": {
                    "source_package_name": "linux-meta",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": "linux-meta",
                    "source_package_version": "7.3.0-5.5+3",
                    "version": "7.3.0-5.5+3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1786013,
                    1786013,
                    1786013,
                    1786013,
                    1786013,
                    1786013
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Packaging] Obsolete out-of-tree usbio and vision dkms",
                            "    - [Packaging] Drop ipu6 from linux-image-generic provides",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.3.0-5.5+3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <tjaalton@debian.org>",
                        "date": "Thu, 17 Sep 2026 17:11:52 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Packaging] Drop obsolete transitionals",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.3.0-5.5+1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Thu, 17 Sep 2026 15:20:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.3.0-5.5",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.3.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 14 Sep 2026 11:39:17 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry; drop unstable suffix",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.3.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Canonical Kernel Team <kernel-team@lists.ubuntu.com>",
                        "date": "Mon, 14 Sep 2026 10:18:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.3.0-4.4",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.3.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 07 Sep 2026 12:34:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.3.0-3.3",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.3.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 07 Sep 2026 08:58:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.3.0-2.2",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.3.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 31 Aug 2026 11:50:47 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.3.0-1.1",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.3.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Fri, 28 Aug 2026 15:02:27 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] debian/dkms-versions -- resync from main package",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.3.0-0.0+1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Fri, 28 Aug 2026 11:58:26 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry: rename to linux-meta-unstable and bump to 7.3.0",
                            "    (major-version bootstrap for the unstable family)",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.3.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 25 Aug 2026 10:03:26 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-5.5",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 22:11:09 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry; drop unstable suffix",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ubuntu Kernel Team <kernel-team@lists.ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 22:10:08 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-4.4",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:50:12 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-3.3",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Packaging] Add IBM transitional packages",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Thu, 13 Aug 2026 21:42:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-2.2",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:30:30 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-1.1",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:08:22 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-0.0+1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:26 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry: rename to linux-meta-unstable and bump to 7.2.0",
                            "    (major-version bootstrap for the unstable family)",
                            ""
                        ],
                        "package": "linux-meta-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 13:14:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-5.5",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:39:50 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-4.4",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Sat, 06 Jun 2026 14:34:18 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-3.3",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Wed, 03 Jun 2026 20:13:31 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-2.2",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Wed, 03 Jun 2026 16:03:47 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-1.1",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:19:19 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:10:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.0.0-15.15",
                            ""
                        ],
                        "package": "linux-meta",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:05:08 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "login.defs",
                "from_version": {
                    "source_package_name": "shadow",
                    "source_package_version": "1:4.17.4-2ubuntu3",
                    "version": "1:4.17.4-2ubuntu3"
                },
                "to_version": {
                    "source_package_name": "shadow",
                    "source_package_version": "1:4.19.3-2ubuntu1",
                    "version": "1:4.19.3-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153355
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153355). Remaining changes:",
                            "    - d/p/: Enable private home directories by default",
                            "    - debian/{source_shadow.py,login.defs.install}: Add apport hook",
                            "    - d/p/1010_extrausers.patch: add libnss-extrausers support to passwd/usermod",
                            "    - d/p/1011_extrausers_toggle.patch: extrausers support for useradd/groupadd",
                            "    - d/p/1012_extrausers_chfn.patch: --extrausers support for chfn tool",
                            "    - d/p/1013_extrausers_deluser.patch: --extrausers support for userdel",
                            "    - d/p/1014_extrausers_delgroup.patch: --extrausers support for groupdel",
                            "    - d/p/1016_extrausers_gpasswd.patch: extrausers support for gpasswd",
                            "    - d/t/{control,numeric-username}: test that fully numeric names are rejected",
                            "    - d/t/smoke: Extend for extrausers support",
                            "    - Add some cursory tests for the extrausers features",
                            "    - d/p/lp2063200: fix useradd group validation with extrausers (LP 2063200)",
                            "    - d/p/: disallow pure numeric user and group names (LP 2076898)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.3-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153355
                        ],
                        "author": "Nadzeya Hutsko <nadzeya.hutsko@canonical.com>",
                        "date": "Mon, 01 Jun 2026 15:59:52 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix getsubids parsing of /etc/subgid.",
                            "    Thanks to Aurelien Jarno (Closes: #1132509)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 02 Apr 2026 19:44:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.19.3",
                            "  * Update Upstream signing keys",
                            "  * d/watch: enable pgpmode=auto",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Mon, 23 Feb 2026 09:54:37 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.19.2",
                            "  * Refresh patches, drop upstream-applied chkhask patches",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Sun, 25 Jan 2026 14:18:54 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import upstream patches to fix hash check (Closes: #1124835)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 08 Jan 2026 00:01:00 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * chpasswd: Disable broken hash check, bug #1124835",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Wed, 07 Jan 2026 11:11:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Disable logind integration on !linux",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Tue, 06 Jan 2026 02:38:50 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.19.0",
                            "  * Refresh patches",
                            "  * Drop upstream-applied patches",
                            "  * Add new build-dependency on libsystemd-dev [linux-any]",
                            "  * login.defs: Remove commented out USERDEL_CMD",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Tue, 06 Jan 2026 01:16:37 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Frans Spiesschaert ]",
                            "  * Update Dutch translations (Closes: #1115411)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.18.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Wed, 17 Sep 2025 00:46:09 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.18.0",
                            "  * Refresh patches",
                            "  * d/copyright: update for upstream-deleted code",
                            "  * Drop newly unnecessay Build-Depends: bison",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.18.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Tue, 26 Aug 2025 23:05:38 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "mokutil",
                "from_version": {
                    "source_package_name": "mokutil",
                    "source_package_version": "0.7.2-2",
                    "version": "0.7.2-2"
                },
                "to_version": {
                    "source_package_name": "mokutil",
                    "source_package_version": "0.7.2-2build1",
                    "version": "0.7.2-2build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "mokutil",
                        "version": "0.7.2-2build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 15:51:25 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ncurses-base",
                "from_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20251231-1",
                    "version": "6.6+20251231-1"
                },
                "to_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20260608-2",
                    "version": "6.6+20260608-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Thu, 02 Jul 2026 17:00:27 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream patchlevel.",
                            "    - Add ech to screen terminfo (Closes: #707308).",
                            "  * Update symbols files.",
                            "  * Update upstream signing key.",
                            "  * Convert the watch files to version 5.",
                            "  * Update years in debian/copyright.",
                            "  * Upgrade Standards-Version to 4.7.4, no changes needed.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-1",
                        "urgency": "low",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Wed, 10 Jun 2026 17:50:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ncurses-bin",
                "from_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20251231-1",
                    "version": "6.6+20251231-1"
                },
                "to_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20260608-2",
                    "version": "6.6+20260608-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Thu, 02 Jul 2026 17:00:27 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream patchlevel.",
                            "    - Add ech to screen terminfo (Closes: #707308).",
                            "  * Update symbols files.",
                            "  * Update upstream signing key.",
                            "  * Convert the watch files to version 5.",
                            "  * Update years in debian/copyright.",
                            "  * Upgrade Standards-Version to 4.7.4, no changes needed.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-1",
                        "urgency": "low",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Wed, 10 Jun 2026 17:50:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ncurses-term",
                "from_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20251231-1",
                    "version": "6.6+20251231-1"
                },
                "to_version": {
                    "source_package_name": "ncurses",
                    "source_package_version": "6.6+20260608-2",
                    "version": "6.6+20260608-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Thu, 02 Jul 2026 17:00:27 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream patchlevel.",
                            "    - Add ech to screen terminfo (Closes: #707308).",
                            "  * Update symbols files.",
                            "  * Update upstream signing key.",
                            "  * Convert the watch files to version 5.",
                            "  * Update years in debian/copyright.",
                            "  * Upgrade Standards-Version to 4.7.4, no changes needed.",
                            ""
                        ],
                        "package": "ncurses",
                        "version": "6.6+20260608-1",
                        "urgency": "low",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sven Joachim <svenjoac@gmx.de>",
                        "date": "Wed, 10 Jun 2026 17:50:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "netplan-generator",
                "from_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.1-1ubuntu1",
                    "version": "1.2.1-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.2-1",
                    "version": "1.2.2-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153219,
                    2145061,
                    2147446,
                    2071747,
                    2139598,
                    2138802
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153219). Remaining changes:",
                            "    - Skip test_link_offloading to allow for a green baseline (LP 2126938)",
                            "      + d/p/lp-2126938-skip-test-link-offloading.patch",
                            "  * Dropped:",
                            "    - d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "      3.14 by handling BlockingIOError in addition to TypeError (LP 2138802)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "      execute udev rules before starting sriov apply service (LP 2139598)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "      (LP 2071747)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "      Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "      units. (LP 2145061)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "      networkd to apply dhcp labels to addresses (LP 2147446).",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "      permissions for files not managed by netplan in integration tests.",
                            "      [Included in Debian 1.2.1-1]",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153219
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Thu, 21 May 2026 16:24:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "    Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "    units. (LP: #2145061)",
                            "  * d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "    networkd to apply dhcp labels to addresses (LP: #2147446).",
                            "  * d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "    permissions for files not managed by netplan in integration tests.",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu5",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2145061,
                            2147446
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Wed, 08 Apr 2026 16:47:32 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "    (LP: #2071747)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2071747
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Fri, 20 Mar 2026 16:09:27 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "    execute udev rules before starting sriov apply service (LP: #2139598)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2139598
                        ],
                        "author": "Robert Malz <robert.malz@canonical.com>",
                        "date": "Tue, 03 Mar 2026 12:44:43 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "    3.14 by handling BlockingIOError in addition to TypeError (LP: #2138802)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2138802
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Fri, 20 Feb 2026 11:25:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip test_link_offloading to allow for a green baseline (LP: 2126938)",
                            "    - d/p/lp-2126938-skip-test-link-offloading.patch",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Lukas Märdian <slyon@ubuntu.com>",
                        "date": "Tue, 13 Jan 2026 17:58:24 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "netplan.io",
                "from_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.1-1ubuntu1",
                    "version": "1.2.1-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.2-1",
                    "version": "1.2.2-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153219,
                    2145061,
                    2147446,
                    2071747,
                    2139598,
                    2138802
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153219). Remaining changes:",
                            "    - Skip test_link_offloading to allow for a green baseline (LP 2126938)",
                            "      + d/p/lp-2126938-skip-test-link-offloading.patch",
                            "  * Dropped:",
                            "    - d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "      3.14 by handling BlockingIOError in addition to TypeError (LP 2138802)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "      execute udev rules before starting sriov apply service (LP 2139598)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "      (LP 2071747)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "      Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "      units. (LP 2145061)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "      networkd to apply dhcp labels to addresses (LP 2147446).",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "      permissions for files not managed by netplan in integration tests.",
                            "      [Included in Debian 1.2.1-1]",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153219
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Thu, 21 May 2026 16:24:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "    Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "    units. (LP: #2145061)",
                            "  * d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "    networkd to apply dhcp labels to addresses (LP: #2147446).",
                            "  * d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "    permissions for files not managed by netplan in integration tests.",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu5",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2145061,
                            2147446
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Wed, 08 Apr 2026 16:47:32 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "    (LP: #2071747)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2071747
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Fri, 20 Mar 2026 16:09:27 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "    execute udev rules before starting sriov apply service (LP: #2139598)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2139598
                        ],
                        "author": "Robert Malz <robert.malz@canonical.com>",
                        "date": "Tue, 03 Mar 2026 12:44:43 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "    3.14 by handling BlockingIOError in addition to TypeError (LP: #2138802)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2138802
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Fri, 20 Feb 2026 11:25:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip test_link_offloading to allow for a green baseline (LP: 2126938)",
                            "    - d/p/lp-2126938-skip-test-link-offloading.patch",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Lukas Märdian <slyon@ubuntu.com>",
                        "date": "Tue, 13 Jan 2026 17:58:24 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "openssh-client",
                "from_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.3p1-4ubuntu1",
                    "version": "1:10.3p1-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.5p1-1ubuntu2",
                    "version": "1:10.5p1-1ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-73281",
                        "url": "https://ubuntu.com/security/CVE-2026-73281",
                        "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73282",
                        "url": "https://ubuntu.com/security/CVE-2026-73282",
                        "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73283",
                        "url": "https://ubuntu.com/security/CVE-2026-73283",
                        "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59995",
                        "url": "https://ubuntu.com/security/CVE-2026-59995",
                        "cve_description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59996",
                        "url": "https://ubuntu.com/security/CVE-2026-59996",
                        "cve_description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59997",
                        "url": "https://ubuntu.com/security/CVE-2026-59997",
                        "cve_description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59998",
                        "url": "https://ubuntu.com/security/CVE-2026-59998",
                        "cve_description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59999",
                        "url": "https://ubuntu.com/security/CVE-2026-59999",
                        "cve_description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60000",
                        "url": "https://ubuntu.com/security/CVE-2026-60000",
                        "cve_description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60001",
                        "url": "https://ubuntu.com/security/CVE-2026-60001",
                        "cve_description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60002",
                        "url": "https://ubuntu.com/security/CVE-2026-60002",
                        "cve_description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2150273,
                    2166924,
                    2166081,
                    2164936,
                    2165026,
                    2164221
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2150273-openssh-pam-upn: Fix PAM user mismatch with",
                            "    alternative UPN suffixes by comparing account UIDs instead of",
                            "    username strings (LP: #2150273)",
                            "  * d/t/password-auth-no-pam: create /run/sshd for the custom test",
                            "    service (LP: #2166924)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150273,
                            2166924
                        ],
                        "author": "Finn Rayk Gartner <finn.gartner@canonical.com>",
                        "date": "Wed, 09 Sep 2026 21:08:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2166081). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "      [Not needed since 1:10.5p1-1]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166081
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 01 Sep 2026 14:45:43 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-73281",
                                "url": "https://ubuntu.com/security/CVE-2026-73281",
                                "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73282",
                                "url": "https://ubuntu.com/security/CVE-2026-73282",
                                "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73283",
                                "url": "https://ubuntu.com/security/CVE-2026-73283",
                                "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1144192):",
                            "    - CVE-2026-73281: ssh-agent(1): fix an interaction between agent locking",
                            "      and the session-bind@openssh.com extension that is used to identify",
                            "      forwarded agents. These binding requests were refused when the agent",
                            "      was locked, with the result that operations that were intended to be",
                            "      limited to local use only could be performed remotely, including the",
                            "      ability to add PKCS#11 tokens and make use of keys that had",
                            "      destination restrictions applied.",
                            "    - CVE-2026-73282: ssh(1): avoid potential realloc use-after-free in the",
                            "      client if a remote forwarding is added via the local session",
                            "      multiplexing socket while a remote forwarding open request is pending",
                            "      with the server.",
                            "    - CVE-2026-73283: sshd(8): make the authorized_keys \"restrict\" keyword",
                            "      apply correctly to tunnel forwarding too (which is administratively",
                            "      disabled by default).",
                            "    - ssh-keygen(1): add ability to set or clear the touch-required and",
                            "      verify-required flags on FIDO private keys when resetting a private",
                            "      key's passphrase.",
                            "    - ssh(1): tweak ordering of certificates tried during pubkey",
                            "      authentication to prefer FIDO keys that do not require user presence",
                            "      (touch) first, and FIDO keys that require user verification via PIN or",
                            "      biometrics last. This effectively tries low-friction authenticators",
                            "      before higher friction ones.",
                            "    - ssh(1): add a \"ssh -Z user@host\" mode that prints the keys that will",
                            "      be tried for public key authentication in the order that they will be",
                            "      used.",
                            "    - sshd(8) use setproctitle(3) to identify sshd-session when it's acting",
                            "      as a post-authentication monitor.",
                            "    - ssh-keyscan(1): make reading the server banner a non-blocking",
                            "      operation to prevent a stuck server from blocking a many-host keyscan",
                            "      from proceeding.",
                            "    - sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the",
                            "      packet code as this provides context of the failing peer (address,",
                            "      port, user, etc).",
                            "    - sshd(8): when signing hostkey proofs for a client UpdateHostKeys",
                            "      request, allow each hostkey to perform at most one signature",
                            "      operation.",
                            "    - ssh-keygen(1): pass back errors from ed25519 key generation, which",
                            "      theoretically can fail.",
                            "    - sshd(8): move check of public key type against allowed algorithms to",
                            "      before parsing of the key sent by the peer. This removes at least some",
                            "      key parsing and verification paths from the pre-auth attack surface.",
                            "    - ssh-keygen(1): fix double frees (impossible to reach outside of a test",
                            "      harness), and also use freezero where possible.",
                            "    - sshd(8): fix ChannelTimeout and RekeyLimit not being applied in",
                            "      sshd_config Match blocks.",
                            "    - sshd(8): in sshd config dump mode, write all directives in mixed case",
                            "      for consistency.",
                            "    - sshd(8): re-allow PAMServiceName inside a Match block, which was",
                            "      incorrectly disabled during a refactoring in openssh-10.4.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 31 Aug 2026 20:53:27 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164936). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "  * Added:",
                            "    - d/openssh-server.ucf-md5sum: update for 1:10.4p1-5ubuntu1",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/ssh-gssapi: disable -e in cleanup()",
                            "      [Test no longer shipped in this source package]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-5ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164936
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Thu, 27 Aug 2026 09:37:48 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop GSS-API authentication and key exchange support, to reduce",
                            "    pre-authentication attack surface.  Users who need these features should",
                            "    install openssh-client-gssapi or openssh-server-gssapi instead.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 23 Aug 2026 17:39:55 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/rules: only act on files from bin:openssh-tests if it's being",
                            "    built (LP: #2165026)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165026
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 25 Aug 2026 09:19:48 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164221). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/t/ssh-gssapi: disable -e in cleanup()",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "  * Added:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164221
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:34:01 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add missing test dependencies.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 31 Jul 2026 17:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove most openssh-* dependencies from openssh-tests.",
                            "  * Add Slovak debconf translation (thanks, Damian Daniel; closes:",
                            "    #1142938).",
                            "  * Remove references to rsh/rcp/rlogin/rshd from package descriptions.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Tue, 28 Jul 2026 16:29:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Alexander Fisher ]",
                            "  * Build-Depends: add libcrypt-dev so crypt() is detected at build time,",
                            "    fixing password authentication with UsePAM=no (closes: #1142354).",
                            "  * debian/tests: add password-auth-no-pam regression test.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 19 Jul 2026 12:46:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-59995",
                                "url": "https://ubuntu.com/security/CVE-2026-59995",
                                "cve_description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59996",
                                "url": "https://ubuntu.com/security/CVE-2026-59996",
                                "cve_description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59997",
                                "url": "https://ubuntu.com/security/CVE-2026-59997",
                                "cve_description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59998",
                                "url": "https://ubuntu.com/security/CVE-2026-59998",
                                "cve_description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59999",
                                "url": "https://ubuntu.com/security/CVE-2026-59999",
                                "cve_description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60000",
                                "url": "https://ubuntu.com/security/CVE-2026-60000",
                                "cve_description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60001",
                                "url": "https://ubuntu.com/security/CVE-2026-60001",
                                "cve_description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60002",
                                "url": "https://ubuntu.com/security/CVE-2026-60002",
                                "cve_description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Sven Joachim ]",
                            "  * Make doc symlinks relative on upgrade from 1:10.3p1-5 (closes:",
                            "    #1141420).",
                            "",
                            "  [ Colin Watson ]",
                            "  * New upstream release:",
                            "    - CVE-2026-59995: sftp(1): when downloading files on the command-line",
                            "      using \"sftp host:/path .\", a malicious server could cause the file to",
                            "      be downloaded to an unexpected location. This issue was identified by",
                            "      the Swival Security Scanner.",
                            "    - CVE-2026-59996: scp(1): when copying files between two remote",
                            "      destinations, do not allow a malicious server to write files to the",
                            "      parent directory of the intended target directory. This issue was",
                            "      identified by the Swival Security Scanner.",
                            "    - CVE-2026-59997: sshd(8): when using the \"internal-sftp\" SFTP server",
                            "      implementation (this is not the default), long command lines were",
                            "      previously truncated silently after the 9th argument. If a",
                            "      security-relevant option was in the 10th or later position, it would",
                            "      be discarded. Reported by Steve Caffrey.",
                            "    - CVE-2026-59998: sshd(8): add a documentation note to mention that the",
                            "      GSSAPIStrictAcceptorCheck option is ineffective when the server is",
                            "      joined to a Windows Active Directory. Reported by Yarin Aharoni of",
                            "      Safebreach.",
                            "    - CVE-2026-59999: sshd(8): DisableForwarding=yes didn't override",
                            "      PermitTunnel=yes as it was documented to do. Note that PermitTunnel is",
                            "      not enabled by default. Reported independently by Huzaifa Sidhpurwala",
                            "      of Redhat and Marko Jevtic.",
                            "    - CVE-2026-60000: sshd(8): avoid a potential pre-authentication denial",
                            "      of service when GSSAPIAuthentication was enabled (this feature is off",
                            "      by default). This was not mitigated by MaxAuthTries, but would be",
                            "      penalised by PerSourcePenalties. This was reported by Manfred Kaiser",
                            "      of the milCERT AT (Austrian Ministry of Defence).",
                            "    - CVE-2026-60001: sshd(8): fix a number of cases where the minimum",
                            "      authentication delay was not being enforced. Reported by the Orange",
                            "      Cyberdefense Vulnerability Team.",
                            "    - CVE-2026-60002: ssh(1): fix a possible client-side use-after-free if",
                            "      the server changes its host key during a key reexchange. This was",
                            "      reported by Zhenpeng (Leo) Lin of Depthfirst.",
                            "    - All: add experimental support for a composite post-quantum signature",
                            "      scheme that combines ML-DSA 44 and Ed25519 as specified in",
                            "      draft-miller-sshm-mldsa44-ed25519-composite-sigs. This scheme is not",
                            "      enabled by default. To use it, you'll need to add it to",
                            "      HostKeyAlgorithms, PubkeyAcceptedAlgorithms, etc. Keys may be",
                            "      generated using \"ssh-keygen -t mldsa44-ed25519\".",
                            "    - ssh(1), sshd(8): replace the wildcard pattern matcher with an",
                            "      implementation based on an NFA. This avoids exponential worst-case",
                            "      behaviour for the old implementation.",
                            "    - ssh-agent(1): fix incorrect reply to \"query\" SSH_AGENTC_EXTENSION",
                            "      requests.",
                            "    - sshd(8): avoid sending observably different messages for valid vs",
                            "      invalid users in GSSAPIAuthentication (disabled by default).",
                            "    - ssh(1), sshd(8): fix several bugs that incorrectly classified bulk",
                            "      traffic as interactive.",
                            "    - ssh-keygen(1), ssh-add(1): skip unsupported key types when downloading",
                            "      resident keys from a FIDO token. Previously, downloads would abort",
                            "      when one was encountered.",
                            "    - ssh(1): fix a potential use-after-free on an error path if",
                            "      cipher_init() fails.",
                            "    - sshd(8): perform stricter encoding and validation of transport state",
                            "      passed between sshd privilege separation subprocesses. This somewhat",
                            "      further hardens the server against attacks on sshd-auth or",
                            "      sshd-session subprocesses.",
                            "    - ssh-agent(1): avoid possible runtime denial of service by enforcing",
                            "      some limits on the length of usernames in key use constraints.",
                            "    - sftp(1): fix two separate one-byte out-of-bounds reads, in",
                            "      SSH2_FXP_REALPATH and batch command processing.",
                            "    - sftp-server(8): disallow use of the copy-data extension to read and",
                            "      write to the same inode simultaneously.",
                            "    - ssh(1), sshd(8): avoid strlen(NULL) crash if an X11 channel was",
                            "      created before the x11-req SSH_MSG_CHANNEL_REQUEST was sent.",
                            "    - sftp(1), scp(1): avoid a situation where sftp_download() could get",
                            "      stuck in a loop if a broken server repeatedly returned zero length",
                            "      while reading a file.",
                            "    - ssh(1): avoid leaking DNS0x20 case-randomised names into names",
                            "      canonicalised using CanonicalizePermittedCNAMEs.",
                            "    - sftp-server(8): avoid truncation of pathnames passed to lstat() during",
                            "      SSH_FXP_REALPATH handling on systems where PATH_MAX is not the actual",
                            "      max.",
                            "    - ssh(1), sshd(8): correct arming of poll(2) event masks for some",
                            "      socket-type channels.",
                            "    - sshd(8): major refactor of sshd_config parsing and management code, to",
                            "      allow for more exact serialisation/deserialisation across privilege",
                            "      separation boundaries.",
                            "    - ssh-add(1): open connection to the agent only after getopt()",
                            "      processing has completed, to give options like \"-v\" a chance to",
                            "      display debug information about this operation.",
                            "    - sshd(8): differentiate between execution failures and a subsystem that",
                            "      was not found when logging why a subsystem failed to start.",
                            "    - All: use safer idioms for timegm(3) and mktime(3) error detection.",
                            "    - ssh(1), sshd(8): avoid accepting invalid cipher or MAC lists in config",
                            "      files or command-line arguments. This could cause runtime failures",
                            "      later.",
                            "    - ssh(1): fix NULL deref crash during pubkey auth when using a PEM style",
                            "      private key with no corresponding .pub key adjacent to it (closes:",
                            "      #1134814).",
                            "    - sshd(8): don't print an error message when trying to load a host",
                            "      private key when PKCS#11 keys are in use, as these don't need the",
                            "      private half on the filesystem.",
                            "    - All: don't use deprecated ERR_load_crypto_strings().",
                            "    - ssh(1): properly report errors during configuration default setting.",
                            "    - ssh(1): use correct directive name (Match instead of Host) in error",
                            "      message.",
                            "    - sftp(1): fix \"ls -ln\" which was not correctly showing numeric UID/GIDs",
                            "      but rather user and group names.",
                            "    - sshd(8): avoid possible NULL dereference if an allocation fails during",
                            "      config parsing.",
                            "    - All: fix ineffective guards against loading overly large public keys",
                            "      in several places.",
                            "    - sftp(1): ensure file descriptors used by sftp to communicate to its",
                            "      ssh(1) subprocess don't leak into executed subprocesses (e.g. via",
                            "      \"!\").",
                            "    - Sync fmt_scaled.c with OpenBSD upstream, picking up an exactness fix",
                            "      for large exponents.",
                            "    - sshd(8): remove duplicate sandbox entry for clock_gettime64.",
                            "    - Sync getrrsetbyname.c with OpenBSD upstream, picking up robustness",
                            "      fixes.",
                            "    - Fix a number of memory leaks on error paths in the portability code.",
                            "    - Revise the README.privsep documentation to reflect sshd's recent",
                            "      switch to a multi-binary model.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 19:11:28 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * openssh-client Conflicts: openssh-server (<< 1:10.3p1-6~) (closes:",
                            "    #1141550).",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-9",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 09:51:32 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/copyright: Add some missing authors.",
                            "  * Standards-Version: 4.7.4.",
                            "  * openssh-tests: Make a couple more scripts executable.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-8",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 03 Jul 2026 16:54:01 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Reupload with binaries, since openssh-common is new.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 03 Jul 2026 00:32:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Move documentation to a new openssh-common package (closes: #1070098).",
                            "  * Remove dependency on openssh-client{,-gssapi} from",
                            "    openssh-server{,-gssapi} (closes: #699473).",
                            "  * Use --link-doc on all packages.",
                            "  * Move ssh-keygen and openssh-{pkcs11,sk}-helper to openssh-common.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Thu, 02 Jul 2026 20:24:29 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * Support DPKG_ROOT.",
                            "",
                            "  [ Colin Watson ]",
                            "  * d/copyright: Significantly rework to be lrc-clean.",
                            "",
                            "  [ Roland C. Dowdeswell ]",
                            "  * Fix GSS C25519 server blob bounds check.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 26 Jun 2026 16:16:18 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:01:03 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "openssh-server",
                "from_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.3p1-4ubuntu1",
                    "version": "1:10.3p1-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.5p1-1ubuntu2",
                    "version": "1:10.5p1-1ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-73281",
                        "url": "https://ubuntu.com/security/CVE-2026-73281",
                        "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73282",
                        "url": "https://ubuntu.com/security/CVE-2026-73282",
                        "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73283",
                        "url": "https://ubuntu.com/security/CVE-2026-73283",
                        "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59995",
                        "url": "https://ubuntu.com/security/CVE-2026-59995",
                        "cve_description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59996",
                        "url": "https://ubuntu.com/security/CVE-2026-59996",
                        "cve_description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59997",
                        "url": "https://ubuntu.com/security/CVE-2026-59997",
                        "cve_description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59998",
                        "url": "https://ubuntu.com/security/CVE-2026-59998",
                        "cve_description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59999",
                        "url": "https://ubuntu.com/security/CVE-2026-59999",
                        "cve_description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60000",
                        "url": "https://ubuntu.com/security/CVE-2026-60000",
                        "cve_description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60001",
                        "url": "https://ubuntu.com/security/CVE-2026-60001",
                        "cve_description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60002",
                        "url": "https://ubuntu.com/security/CVE-2026-60002",
                        "cve_description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2150273,
                    2166924,
                    2166081,
                    2164936,
                    2165026,
                    2164221
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2150273-openssh-pam-upn: Fix PAM user mismatch with",
                            "    alternative UPN suffixes by comparing account UIDs instead of",
                            "    username strings (LP: #2150273)",
                            "  * d/t/password-auth-no-pam: create /run/sshd for the custom test",
                            "    service (LP: #2166924)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150273,
                            2166924
                        ],
                        "author": "Finn Rayk Gartner <finn.gartner@canonical.com>",
                        "date": "Wed, 09 Sep 2026 21:08:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2166081). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "      [Not needed since 1:10.5p1-1]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166081
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 01 Sep 2026 14:45:43 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-73281",
                                "url": "https://ubuntu.com/security/CVE-2026-73281",
                                "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73282",
                                "url": "https://ubuntu.com/security/CVE-2026-73282",
                                "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73283",
                                "url": "https://ubuntu.com/security/CVE-2026-73283",
                                "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1144192):",
                            "    - CVE-2026-73281: ssh-agent(1): fix an interaction between agent locking",
                            "      and the session-bind@openssh.com extension that is used to identify",
                            "      forwarded agents. These binding requests were refused when the agent",
                            "      was locked, with the result that operations that were intended to be",
                            "      limited to local use only could be performed remotely, including the",
                            "      ability to add PKCS#11 tokens and make use of keys that had",
                            "      destination restrictions applied.",
                            "    - CVE-2026-73282: ssh(1): avoid potential realloc use-after-free in the",
                            "      client if a remote forwarding is added via the local session",
                            "      multiplexing socket while a remote forwarding open request is pending",
                            "      with the server.",
                            "    - CVE-2026-73283: sshd(8): make the authorized_keys \"restrict\" keyword",
                            "      apply correctly to tunnel forwarding too (which is administratively",
                            "      disabled by default).",
                            "    - ssh-keygen(1): add ability to set or clear the touch-required and",
                            "      verify-required flags on FIDO private keys when resetting a private",
                            "      key's passphrase.",
                            "    - ssh(1): tweak ordering of certificates tried during pubkey",
                            "      authentication to prefer FIDO keys that do not require user presence",
                            "      (touch) first, and FIDO keys that require user verification via PIN or",
                            "      biometrics last. This effectively tries low-friction authenticators",
                            "      before higher friction ones.",
                            "    - ssh(1): add a \"ssh -Z user@host\" mode that prints the keys that will",
                            "      be tried for public key authentication in the order that they will be",
                            "      used.",
                            "    - sshd(8) use setproctitle(3) to identify sshd-session when it's acting",
                            "      as a post-authentication monitor.",
                            "    - ssh-keyscan(1): make reading the server banner a non-blocking",
                            "      operation to prevent a stuck server from blocking a many-host keyscan",
                            "      from proceeding.",
                            "    - sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the",
                            "      packet code as this provides context of the failing peer (address,",
                            "      port, user, etc).",
                            "    - sshd(8): when signing hostkey proofs for a client UpdateHostKeys",
                            "      request, allow each hostkey to perform at most one signature",
                            "      operation.",
                            "    - ssh-keygen(1): pass back errors from ed25519 key generation, which",
                            "      theoretically can fail.",
                            "    - sshd(8): move check of public key type against allowed algorithms to",
                            "      before parsing of the key sent by the peer. This removes at least some",
                            "      key parsing and verification paths from the pre-auth attack surface.",
                            "    - ssh-keygen(1): fix double frees (impossible to reach outside of a test",
                            "      harness), and also use freezero where possible.",
                            "    - sshd(8): fix ChannelTimeout and RekeyLimit not being applied in",
                            "      sshd_config Match blocks.",
                            "    - sshd(8): in sshd config dump mode, write all directives in mixed case",
                            "      for consistency.",
                            "    - sshd(8): re-allow PAMServiceName inside a Match block, which was",
                            "      incorrectly disabled during a refactoring in openssh-10.4.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 31 Aug 2026 20:53:27 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164936). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "  * Added:",
                            "    - d/openssh-server.ucf-md5sum: update for 1:10.4p1-5ubuntu1",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/ssh-gssapi: disable -e in cleanup()",
                            "      [Test no longer shipped in this source package]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-5ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164936
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Thu, 27 Aug 2026 09:37:48 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop GSS-API authentication and key exchange support, to reduce",
                            "    pre-authentication attack surface.  Users who need these features should",
                            "    install openssh-client-gssapi or openssh-server-gssapi instead.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 23 Aug 2026 17:39:55 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/rules: only act on files from bin:openssh-tests if it's being",
                            "    built (LP: #2165026)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165026
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 25 Aug 2026 09:19:48 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164221). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/t/ssh-gssapi: disable -e in cleanup()",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "  * Added:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164221
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:34:01 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add missing test dependencies.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 31 Jul 2026 17:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove most openssh-* dependencies from openssh-tests.",
                            "  * Add Slovak debconf translation (thanks, Damian Daniel; closes:",
                            "    #1142938).",
                            "  * Remove references to rsh/rcp/rlogin/rshd from package descriptions.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Tue, 28 Jul 2026 16:29:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Alexander Fisher ]",
                            "  * Build-Depends: add libcrypt-dev so crypt() is detected at build time,",
                            "    fixing password authentication with UsePAM=no (closes: #1142354).",
                            "  * debian/tests: add password-auth-no-pam regression test.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 19 Jul 2026 12:46:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-59995",
                                "url": "https://ubuntu.com/security/CVE-2026-59995",
                                "cve_description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59996",
                                "url": "https://ubuntu.com/security/CVE-2026-59996",
                                "cve_description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59997",
                                "url": "https://ubuntu.com/security/CVE-2026-59997",
                                "cve_description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59998",
                                "url": "https://ubuntu.com/security/CVE-2026-59998",
                                "cve_description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59999",
                                "url": "https://ubuntu.com/security/CVE-2026-59999",
                                "cve_description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60000",
                                "url": "https://ubuntu.com/security/CVE-2026-60000",
                                "cve_description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60001",
                                "url": "https://ubuntu.com/security/CVE-2026-60001",
                                "cve_description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60002",
                                "url": "https://ubuntu.com/security/CVE-2026-60002",
                                "cve_description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Sven Joachim ]",
                            "  * Make doc symlinks relative on upgrade from 1:10.3p1-5 (closes:",
                            "    #1141420).",
                            "",
                            "  [ Colin Watson ]",
                            "  * New upstream release:",
                            "    - CVE-2026-59995: sftp(1): when downloading files on the command-line",
                            "      using \"sftp host:/path .\", a malicious server could cause the file to",
                            "      be downloaded to an unexpected location. This issue was identified by",
                            "      the Swival Security Scanner.",
                            "    - CVE-2026-59996: scp(1): when copying files between two remote",
                            "      destinations, do not allow a malicious server to write files to the",
                            "      parent directory of the intended target directory. This issue was",
                            "      identified by the Swival Security Scanner.",
                            "    - CVE-2026-59997: sshd(8): when using the \"internal-sftp\" SFTP server",
                            "      implementation (this is not the default), long command lines were",
                            "      previously truncated silently after the 9th argument. If a",
                            "      security-relevant option was in the 10th or later position, it would",
                            "      be discarded. Reported by Steve Caffrey.",
                            "    - CVE-2026-59998: sshd(8): add a documentation note to mention that the",
                            "      GSSAPIStrictAcceptorCheck option is ineffective when the server is",
                            "      joined to a Windows Active Directory. Reported by Yarin Aharoni of",
                            "      Safebreach.",
                            "    - CVE-2026-59999: sshd(8): DisableForwarding=yes didn't override",
                            "      PermitTunnel=yes as it was documented to do. Note that PermitTunnel is",
                            "      not enabled by default. Reported independently by Huzaifa Sidhpurwala",
                            "      of Redhat and Marko Jevtic.",
                            "    - CVE-2026-60000: sshd(8): avoid a potential pre-authentication denial",
                            "      of service when GSSAPIAuthentication was enabled (this feature is off",
                            "      by default). This was not mitigated by MaxAuthTries, but would be",
                            "      penalised by PerSourcePenalties. This was reported by Manfred Kaiser",
                            "      of the milCERT AT (Austrian Ministry of Defence).",
                            "    - CVE-2026-60001: sshd(8): fix a number of cases where the minimum",
                            "      authentication delay was not being enforced. Reported by the Orange",
                            "      Cyberdefense Vulnerability Team.",
                            "    - CVE-2026-60002: ssh(1): fix a possible client-side use-after-free if",
                            "      the server changes its host key during a key reexchange. This was",
                            "      reported by Zhenpeng (Leo) Lin of Depthfirst.",
                            "    - All: add experimental support for a composite post-quantum signature",
                            "      scheme that combines ML-DSA 44 and Ed25519 as specified in",
                            "      draft-miller-sshm-mldsa44-ed25519-composite-sigs. This scheme is not",
                            "      enabled by default. To use it, you'll need to add it to",
                            "      HostKeyAlgorithms, PubkeyAcceptedAlgorithms, etc. Keys may be",
                            "      generated using \"ssh-keygen -t mldsa44-ed25519\".",
                            "    - ssh(1), sshd(8): replace the wildcard pattern matcher with an",
                            "      implementation based on an NFA. This avoids exponential worst-case",
                            "      behaviour for the old implementation.",
                            "    - ssh-agent(1): fix incorrect reply to \"query\" SSH_AGENTC_EXTENSION",
                            "      requests.",
                            "    - sshd(8): avoid sending observably different messages for valid vs",
                            "      invalid users in GSSAPIAuthentication (disabled by default).",
                            "    - ssh(1), sshd(8): fix several bugs that incorrectly classified bulk",
                            "      traffic as interactive.",
                            "    - ssh-keygen(1), ssh-add(1): skip unsupported key types when downloading",
                            "      resident keys from a FIDO token. Previously, downloads would abort",
                            "      when one was encountered.",
                            "    - ssh(1): fix a potential use-after-free on an error path if",
                            "      cipher_init() fails.",
                            "    - sshd(8): perform stricter encoding and validation of transport state",
                            "      passed between sshd privilege separation subprocesses. This somewhat",
                            "      further hardens the server against attacks on sshd-auth or",
                            "      sshd-session subprocesses.",
                            "    - ssh-agent(1): avoid possible runtime denial of service by enforcing",
                            "      some limits on the length of usernames in key use constraints.",
                            "    - sftp(1): fix two separate one-byte out-of-bounds reads, in",
                            "      SSH2_FXP_REALPATH and batch command processing.",
                            "    - sftp-server(8): disallow use of the copy-data extension to read and",
                            "      write to the same inode simultaneously.",
                            "    - ssh(1), sshd(8): avoid strlen(NULL) crash if an X11 channel was",
                            "      created before the x11-req SSH_MSG_CHANNEL_REQUEST was sent.",
                            "    - sftp(1), scp(1): avoid a situation where sftp_download() could get",
                            "      stuck in a loop if a broken server repeatedly returned zero length",
                            "      while reading a file.",
                            "    - ssh(1): avoid leaking DNS0x20 case-randomised names into names",
                            "      canonicalised using CanonicalizePermittedCNAMEs.",
                            "    - sftp-server(8): avoid truncation of pathnames passed to lstat() during",
                            "      SSH_FXP_REALPATH handling on systems where PATH_MAX is not the actual",
                            "      max.",
                            "    - ssh(1), sshd(8): correct arming of poll(2) event masks for some",
                            "      socket-type channels.",
                            "    - sshd(8): major refactor of sshd_config parsing and management code, to",
                            "      allow for more exact serialisation/deserialisation across privilege",
                            "      separation boundaries.",
                            "    - ssh-add(1): open connection to the agent only after getopt()",
                            "      processing has completed, to give options like \"-v\" a chance to",
                            "      display debug information about this operation.",
                            "    - sshd(8): differentiate between execution failures and a subsystem that",
                            "      was not found when logging why a subsystem failed to start.",
                            "    - All: use safer idioms for timegm(3) and mktime(3) error detection.",
                            "    - ssh(1), sshd(8): avoid accepting invalid cipher or MAC lists in config",
                            "      files or command-line arguments. This could cause runtime failures",
                            "      later.",
                            "    - ssh(1): fix NULL deref crash during pubkey auth when using a PEM style",
                            "      private key with no corresponding .pub key adjacent to it (closes:",
                            "      #1134814).",
                            "    - sshd(8): don't print an error message when trying to load a host",
                            "      private key when PKCS#11 keys are in use, as these don't need the",
                            "      private half on the filesystem.",
                            "    - All: don't use deprecated ERR_load_crypto_strings().",
                            "    - ssh(1): properly report errors during configuration default setting.",
                            "    - ssh(1): use correct directive name (Match instead of Host) in error",
                            "      message.",
                            "    - sftp(1): fix \"ls -ln\" which was not correctly showing numeric UID/GIDs",
                            "      but rather user and group names.",
                            "    - sshd(8): avoid possible NULL dereference if an allocation fails during",
                            "      config parsing.",
                            "    - All: fix ineffective guards against loading overly large public keys",
                            "      in several places.",
                            "    - sftp(1): ensure file descriptors used by sftp to communicate to its",
                            "      ssh(1) subprocess don't leak into executed subprocesses (e.g. via",
                            "      \"!\").",
                            "    - Sync fmt_scaled.c with OpenBSD upstream, picking up an exactness fix",
                            "      for large exponents.",
                            "    - sshd(8): remove duplicate sandbox entry for clock_gettime64.",
                            "    - Sync getrrsetbyname.c with OpenBSD upstream, picking up robustness",
                            "      fixes.",
                            "    - Fix a number of memory leaks on error paths in the portability code.",
                            "    - Revise the README.privsep documentation to reflect sshd's recent",
                            "      switch to a multi-binary model.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 19:11:28 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * openssh-client Conflicts: openssh-server (<< 1:10.3p1-6~) (closes:",
                            "    #1141550).",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-9",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 09:51:32 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/copyright: Add some missing authors.",
                            "  * Standards-Version: 4.7.4.",
                            "  * openssh-tests: Make a couple more scripts executable.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-8",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 03 Jul 2026 16:54:01 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Reupload with binaries, since openssh-common is new.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 03 Jul 2026 00:32:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Move documentation to a new openssh-common package (closes: #1070098).",
                            "  * Remove dependency on openssh-client{,-gssapi} from",
                            "    openssh-server{,-gssapi} (closes: #699473).",
                            "  * Use --link-doc on all packages.",
                            "  * Move ssh-keygen and openssh-{pkcs11,sk}-helper to openssh-common.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Thu, 02 Jul 2026 20:24:29 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * Support DPKG_ROOT.",
                            "",
                            "  [ Colin Watson ]",
                            "  * d/copyright: Significantly rework to be lrc-clean.",
                            "",
                            "  [ Roland C. Dowdeswell ]",
                            "  * Fix GSS C25519 server blob bounds check.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 26 Jun 2026 16:16:18 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:01:03 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "openssh-sftp-server",
                "from_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.3p1-4ubuntu1",
                    "version": "1:10.3p1-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.5p1-1ubuntu2",
                    "version": "1:10.5p1-1ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-73281",
                        "url": "https://ubuntu.com/security/CVE-2026-73281",
                        "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73282",
                        "url": "https://ubuntu.com/security/CVE-2026-73282",
                        "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73283",
                        "url": "https://ubuntu.com/security/CVE-2026-73283",
                        "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59995",
                        "url": "https://ubuntu.com/security/CVE-2026-59995",
                        "cve_description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59996",
                        "url": "https://ubuntu.com/security/CVE-2026-59996",
                        "cve_description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59997",
                        "url": "https://ubuntu.com/security/CVE-2026-59997",
                        "cve_description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59998",
                        "url": "https://ubuntu.com/security/CVE-2026-59998",
                        "cve_description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59999",
                        "url": "https://ubuntu.com/security/CVE-2026-59999",
                        "cve_description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60000",
                        "url": "https://ubuntu.com/security/CVE-2026-60000",
                        "cve_description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60001",
                        "url": "https://ubuntu.com/security/CVE-2026-60001",
                        "cve_description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60002",
                        "url": "https://ubuntu.com/security/CVE-2026-60002",
                        "cve_description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2150273,
                    2166924,
                    2166081,
                    2164936,
                    2165026,
                    2164221
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2150273-openssh-pam-upn: Fix PAM user mismatch with",
                            "    alternative UPN suffixes by comparing account UIDs instead of",
                            "    username strings (LP: #2150273)",
                            "  * d/t/password-auth-no-pam: create /run/sshd for the custom test",
                            "    service (LP: #2166924)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150273,
                            2166924
                        ],
                        "author": "Finn Rayk Gartner <finn.gartner@canonical.com>",
                        "date": "Wed, 09 Sep 2026 21:08:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2166081). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "      [Not needed since 1:10.5p1-1]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166081
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 01 Sep 2026 14:45:43 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-73281",
                                "url": "https://ubuntu.com/security/CVE-2026-73281",
                                "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73282",
                                "url": "https://ubuntu.com/security/CVE-2026-73282",
                                "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73283",
                                "url": "https://ubuntu.com/security/CVE-2026-73283",
                                "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1144192):",
                            "    - CVE-2026-73281: ssh-agent(1): fix an interaction between agent locking",
                            "      and the session-bind@openssh.com extension that is used to identify",
                            "      forwarded agents. These binding requests were refused when the agent",
                            "      was locked, with the result that operations that were intended to be",
                            "      limited to local use only could be performed remotely, including the",
                            "      ability to add PKCS#11 tokens and make use of keys that had",
                            "      destination restrictions applied.",
                            "    - CVE-2026-73282: ssh(1): avoid potential realloc use-after-free in the",
                            "      client if a remote forwarding is added via the local session",
                            "      multiplexing socket while a remote forwarding open request is pending",
                            "      with the server.",
                            "    - CVE-2026-73283: sshd(8): make the authorized_keys \"restrict\" keyword",
                            "      apply correctly to tunnel forwarding too (which is administratively",
                            "      disabled by default).",
                            "    - ssh-keygen(1): add ability to set or clear the touch-required and",
                            "      verify-required flags on FIDO private keys when resetting a private",
                            "      key's passphrase.",
                            "    - ssh(1): tweak ordering of certificates tried during pubkey",
                            "      authentication to prefer FIDO keys that do not require user presence",
                            "      (touch) first, and FIDO keys that require user verification via PIN or",
                            "      biometrics last. This effectively tries low-friction authenticators",
                            "      before higher friction ones.",
                            "    - ssh(1): add a \"ssh -Z user@host\" mode that prints the keys that will",
                            "      be tried for public key authentication in the order that they will be",
                            "      used.",
                            "    - sshd(8) use setproctitle(3) to identify sshd-session when it's acting",
                            "      as a post-authentication monitor.",
                            "    - ssh-keyscan(1): make reading the server banner a non-blocking",
                            "      operation to prevent a stuck server from blocking a many-host keyscan",
                            "      from proceeding.",
                            "    - sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the",
                            "      packet code as this provides context of the failing peer (address,",
                            "      port, user, etc).",
                            "    - sshd(8): when signing hostkey proofs for a client UpdateHostKeys",
                            "      request, allow each hostkey to perform at most one signature",
                            "      operation.",
                            "    - ssh-keygen(1): pass back errors from ed25519 key generation, which",
                            "      theoretically can fail.",
                            "    - sshd(8): move check of public key type against allowed algorithms to",
                            "      before parsing of the key sent by the peer. This removes at least some",
                            "      key parsing and verification paths from the pre-auth attack surface.",
                            "    - ssh-keygen(1): fix double frees (impossible to reach outside of a test",
                            "      harness), and also use freezero where possible.",
                            "    - sshd(8): fix ChannelTimeout and RekeyLimit not being applied in",
                            "      sshd_config Match blocks.",
                            "    - sshd(8): in sshd config dump mode, write all directives in mixed case",
                            "      for consistency.",
                            "    - sshd(8): re-allow PAMServiceName inside a Match block, which was",
                            "      incorrectly disabled during a refactoring in openssh-10.4.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 31 Aug 2026 20:53:27 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164936). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "  * Added:",
                            "    - d/openssh-server.ucf-md5sum: update for 1:10.4p1-5ubuntu1",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/ssh-gssapi: disable -e in cleanup()",
                            "      [Test no longer shipped in this source package]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-5ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164936
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Thu, 27 Aug 2026 09:37:48 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop GSS-API authentication and key exchange support, to reduce",
                            "    pre-authentication attack surface.  Users who need these features should",
                            "    install openssh-client-gssapi or openssh-server-gssapi instead.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 23 Aug 2026 17:39:55 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/rules: only act on files from bin:openssh-tests if it's being",
                            "    built (LP: #2165026)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165026
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 25 Aug 2026 09:19:48 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164221). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/t/ssh-gssapi: disable -e in cleanup()",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "  * Added:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164221
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:34:01 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add missing test dependencies.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 31 Jul 2026 17:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove most openssh-* dependencies from openssh-tests.",
                            "  * Add Slovak debconf translation (thanks, Damian Daniel; closes:",
                            "    #1142938).",
                            "  * Remove references to rsh/rcp/rlogin/rshd from package descriptions.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Tue, 28 Jul 2026 16:29:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Alexander Fisher ]",
                            "  * Build-Depends: add libcrypt-dev so crypt() is detected at build time,",
                            "    fixing password authentication with UsePAM=no (closes: #1142354).",
                            "  * debian/tests: add password-auth-no-pam regression test.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 19 Jul 2026 12:46:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-59995",
                                "url": "https://ubuntu.com/security/CVE-2026-59995",
                                "cve_description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59996",
                                "url": "https://ubuntu.com/security/CVE-2026-59996",
                                "cve_description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59997",
                                "url": "https://ubuntu.com/security/CVE-2026-59997",
                                "cve_description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59998",
                                "url": "https://ubuntu.com/security/CVE-2026-59998",
                                "cve_description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59999",
                                "url": "https://ubuntu.com/security/CVE-2026-59999",
                                "cve_description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60000",
                                "url": "https://ubuntu.com/security/CVE-2026-60000",
                                "cve_description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60001",
                                "url": "https://ubuntu.com/security/CVE-2026-60001",
                                "cve_description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60002",
                                "url": "https://ubuntu.com/security/CVE-2026-60002",
                                "cve_description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Sven Joachim ]",
                            "  * Make doc symlinks relative on upgrade from 1:10.3p1-5 (closes:",
                            "    #1141420).",
                            "",
                            "  [ Colin Watson ]",
                            "  * New upstream release:",
                            "    - CVE-2026-59995: sftp(1): when downloading files on the command-line",
                            "      using \"sftp host:/path .\", a malicious server could cause the file to",
                            "      be downloaded to an unexpected location. This issue was identified by",
                            "      the Swival Security Scanner.",
                            "    - CVE-2026-59996: scp(1): when copying files between two remote",
                            "      destinations, do not allow a malicious server to write files to the",
                            "      parent directory of the intended target directory. This issue was",
                            "      identified by the Swival Security Scanner.",
                            "    - CVE-2026-59997: sshd(8): when using the \"internal-sftp\" SFTP server",
                            "      implementation (this is not the default), long command lines were",
                            "      previously truncated silently after the 9th argument. If a",
                            "      security-relevant option was in the 10th or later position, it would",
                            "      be discarded. Reported by Steve Caffrey.",
                            "    - CVE-2026-59998: sshd(8): add a documentation note to mention that the",
                            "      GSSAPIStrictAcceptorCheck option is ineffective when the server is",
                            "      joined to a Windows Active Directory. Reported by Yarin Aharoni of",
                            "      Safebreach.",
                            "    - CVE-2026-59999: sshd(8): DisableForwarding=yes didn't override",
                            "      PermitTunnel=yes as it was documented to do. Note that PermitTunnel is",
                            "      not enabled by default. Reported independently by Huzaifa Sidhpurwala",
                            "      of Redhat and Marko Jevtic.",
                            "    - CVE-2026-60000: sshd(8): avoid a potential pre-authentication denial",
                            "      of service when GSSAPIAuthentication was enabled (this feature is off",
                            "      by default). This was not mitigated by MaxAuthTries, but would be",
                            "      penalised by PerSourcePenalties. This was reported by Manfred Kaiser",
                            "      of the milCERT AT (Austrian Ministry of Defence).",
                            "    - CVE-2026-60001: sshd(8): fix a number of cases where the minimum",
                            "      authentication delay was not being enforced. Reported by the Orange",
                            "      Cyberdefense Vulnerability Team.",
                            "    - CVE-2026-60002: ssh(1): fix a possible client-side use-after-free if",
                            "      the server changes its host key during a key reexchange. This was",
                            "      reported by Zhenpeng (Leo) Lin of Depthfirst.",
                            "    - All: add experimental support for a composite post-quantum signature",
                            "      scheme that combines ML-DSA 44 and Ed25519 as specified in",
                            "      draft-miller-sshm-mldsa44-ed25519-composite-sigs. This scheme is not",
                            "      enabled by default. To use it, you'll need to add it to",
                            "      HostKeyAlgorithms, PubkeyAcceptedAlgorithms, etc. Keys may be",
                            "      generated using \"ssh-keygen -t mldsa44-ed25519\".",
                            "    - ssh(1), sshd(8): replace the wildcard pattern matcher with an",
                            "      implementation based on an NFA. This avoids exponential worst-case",
                            "      behaviour for the old implementation.",
                            "    - ssh-agent(1): fix incorrect reply to \"query\" SSH_AGENTC_EXTENSION",
                            "      requests.",
                            "    - sshd(8): avoid sending observably different messages for valid vs",
                            "      invalid users in GSSAPIAuthentication (disabled by default).",
                            "    - ssh(1), sshd(8): fix several bugs that incorrectly classified bulk",
                            "      traffic as interactive.",
                            "    - ssh-keygen(1), ssh-add(1): skip unsupported key types when downloading",
                            "      resident keys from a FIDO token. Previously, downloads would abort",
                            "      when one was encountered.",
                            "    - ssh(1): fix a potential use-after-free on an error path if",
                            "      cipher_init() fails.",
                            "    - sshd(8): perform stricter encoding and validation of transport state",
                            "      passed between sshd privilege separation subprocesses. This somewhat",
                            "      further hardens the server against attacks on sshd-auth or",
                            "      sshd-session subprocesses.",
                            "    - ssh-agent(1): avoid possible runtime denial of service by enforcing",
                            "      some limits on the length of usernames in key use constraints.",
                            "    - sftp(1): fix two separate one-byte out-of-bounds reads, in",
                            "      SSH2_FXP_REALPATH and batch command processing.",
                            "    - sftp-server(8): disallow use of the copy-data extension to read and",
                            "      write to the same inode simultaneously.",
                            "    - ssh(1), sshd(8): avoid strlen(NULL) crash if an X11 channel was",
                            "      created before the x11-req SSH_MSG_CHANNEL_REQUEST was sent.",
                            "    - sftp(1), scp(1): avoid a situation where sftp_download() could get",
                            "      stuck in a loop if a broken server repeatedly returned zero length",
                            "      while reading a file.",
                            "    - ssh(1): avoid leaking DNS0x20 case-randomised names into names",
                            "      canonicalised using CanonicalizePermittedCNAMEs.",
                            "    - sftp-server(8): avoid truncation of pathnames passed to lstat() during",
                            "      SSH_FXP_REALPATH handling on systems where PATH_MAX is not the actual",
                            "      max.",
                            "    - ssh(1), sshd(8): correct arming of poll(2) event masks for some",
                            "      socket-type channels.",
                            "    - sshd(8): major refactor of sshd_config parsing and management code, to",
                            "      allow for more exact serialisation/deserialisation across privilege",
                            "      separation boundaries.",
                            "    - ssh-add(1): open connection to the agent only after getopt()",
                            "      processing has completed, to give options like \"-v\" a chance to",
                            "      display debug information about this operation.",
                            "    - sshd(8): differentiate between execution failures and a subsystem that",
                            "      was not found when logging why a subsystem failed to start.",
                            "    - All: use safer idioms for timegm(3) and mktime(3) error detection.",
                            "    - ssh(1), sshd(8): avoid accepting invalid cipher or MAC lists in config",
                            "      files or command-line arguments. This could cause runtime failures",
                            "      later.",
                            "    - ssh(1): fix NULL deref crash during pubkey auth when using a PEM style",
                            "      private key with no corresponding .pub key adjacent to it (closes:",
                            "      #1134814).",
                            "    - sshd(8): don't print an error message when trying to load a host",
                            "      private key when PKCS#11 keys are in use, as these don't need the",
                            "      private half on the filesystem.",
                            "    - All: don't use deprecated ERR_load_crypto_strings().",
                            "    - ssh(1): properly report errors during configuration default setting.",
                            "    - ssh(1): use correct directive name (Match instead of Host) in error",
                            "      message.",
                            "    - sftp(1): fix \"ls -ln\" which was not correctly showing numeric UID/GIDs",
                            "      but rather user and group names.",
                            "    - sshd(8): avoid possible NULL dereference if an allocation fails during",
                            "      config parsing.",
                            "    - All: fix ineffective guards against loading overly large public keys",
                            "      in several places.",
                            "    - sftp(1): ensure file descriptors used by sftp to communicate to its",
                            "      ssh(1) subprocess don't leak into executed subprocesses (e.g. via",
                            "      \"!\").",
                            "    - Sync fmt_scaled.c with OpenBSD upstream, picking up an exactness fix",
                            "      for large exponents.",
                            "    - sshd(8): remove duplicate sandbox entry for clock_gettime64.",
                            "    - Sync getrrsetbyname.c with OpenBSD upstream, picking up robustness",
                            "      fixes.",
                            "    - Fix a number of memory leaks on error paths in the portability code.",
                            "    - Revise the README.privsep documentation to reflect sshd's recent",
                            "      switch to a multi-binary model.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 19:11:28 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * openssh-client Conflicts: openssh-server (<< 1:10.3p1-6~) (closes:",
                            "    #1141550).",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-9",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 09:51:32 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/copyright: Add some missing authors.",
                            "  * Standards-Version: 4.7.4.",
                            "  * openssh-tests: Make a couple more scripts executable.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-8",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 03 Jul 2026 16:54:01 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Reupload with binaries, since openssh-common is new.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 03 Jul 2026 00:32:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Move documentation to a new openssh-common package (closes: #1070098).",
                            "  * Remove dependency on openssh-client{,-gssapi} from",
                            "    openssh-server{,-gssapi} (closes: #699473).",
                            "  * Use --link-doc on all packages.",
                            "  * Move ssh-keygen and openssh-{pkcs11,sk}-helper to openssh-common.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Thu, 02 Jul 2026 20:24:29 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * Support DPKG_ROOT.",
                            "",
                            "  [ Colin Watson ]",
                            "  * d/copyright: Significantly rework to be lrc-clean.",
                            "",
                            "  [ Roland C. Dowdeswell ]",
                            "  * Fix GSS C25519 server blob bounds check.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 26 Jun 2026 16:16:18 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:01:03 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "openssl",
                "from_version": {
                    "source_package_name": "openssl",
                    "source_package_version": "3.5.5-1ubuntu4",
                    "version": "3.5.5-1ubuntu4"
                },
                "to_version": {
                    "source_package_name": "openssl",
                    "source_package_version": "4.0.1-1ubuntu4",
                    "version": "4.0.1-1ubuntu4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-7383",
                        "url": "https://ubuntu.com/security/CVE-2026-7383",
                        "cve_description": "Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow.  Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefined behaviour.  In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination size for Unicode output is computed in a signed int: by left shift of the input character count for BMPSTRING (UTF-16) and UNIVERSALSTRING (UTF-32), and by summing per-character byte counts for UTF8STRING. The calculation overflows when the input reaches around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30 characters) the size wraps to zero, OPENSSL_malloc(1) is called, and the subsequent character copy writes several gigabytes past the one-byte allocation.  X.509 certificate processing routes through ASN1_STRING_set_by_NID(), whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID size limits cap the input length; no network protocol or certificate-handling path in OpenSSL exercises the overflow. Triggering the bug requires an application that calls ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers a custom string type via ASN1_STRING_TABLE_add(), with attacker-controlled input on the order of half a gigabyte or more. For these reasons this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-9076",
                        "url": "https://ubuntu.com/security/CVE-2026-9076",
                        "cve_description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key().  Impact summary: A heap buffer over-read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not revealed to the attacker.  The key unwrapping function performs a check-byte test as specified in the RFC that reads 7 bytes from a heap allocation that is based on the wrapped key length from the message. There is a minimum length check based on the block length of the wrapping cipher. However the cipher is selected from an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no requirement that the cipher be a block cipher. When an attacker selects a stream-mode cipher the guard will be ineffective and the allocated buffer containing the unwrapped key can be too small to fit the check-bytes specified in the RFC and a buffer over-read can happen.  Applications calling CMS_decrypt() or CMS_decrypt_set1_password() (equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS data are vulnerable to this issue. No password knowledge is required: the over-read happens during the unwrap attempt before any authentication succeeds.  The over-read is limited to a few bytes and is not written to output, so there is no information disclosure. Triggering a crash requires the allocation to border unmapped memory, which is unlikely with the normal allocator.  The FIPS modules are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34180",
                        "url": "https://ubuntu.com/security/CVE-2026-34180",
                        "cve_description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms.  Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer.  More typically such ASN.1 elements would instead be truncated.  An integer truncation in OpenSSL's ASN.1 decoder causes the content length of an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the worst case the truncated length is treated as a request to scan the binary content for a terminating zero byte, possibly causing OpenSSL to read either less than or beyond the end of the allocated buffer.  Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or any other d2i_* decoding function are affected. OpenSSL's own command-line tools are not vulnerable, as data read through the BIO layer is checked before it reaches the affected code. The issue only affects 64-bit Unix and Unix-like platforms; 32-bit platforms and 64-bit Windows are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34181",
                        "url": "https://ubuntu.com/security/CVE-2026-34181",
                        "cve_description": "Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery.  Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability.  If a service accepting PKCS#12 files is using passwords for authenticating the received files, the attacker can create unencrypted PKCS#12 files that use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing them to craft a file that will be accepted with a 1 in 256 probability. That would then cause the service to accept a certificate and private key controlled by the attacker.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34182",
                        "url": "https://ubuntu.com/security/CVE-2026-34182",
                        "cve_description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises.  Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message.  In one use case, an attacker may send a CMS message containing AuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL erroneously allows this selection, and attempts to decrypt and validate the message.  An on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData addressed to the victim can re-emit it with the recipientInfos set left byte-for-byte intact, so the victim's private key still unwraps the genuine CEK (the content-encryption key), but with the inner OID rewritten to AES-256-OFB (Output Feedback Mode, an unauthenticated keystream mode) and with an attacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the real CEK, never consults the MAC field, and CMS_decrypt() returns success.  If the application under attack responds to the attacker with any indicator showing success or failure of the decryption effort, it is possible for the attacker to use this as an oracle to obtain key equivalent functionality for the CEK used for the chosen recipient of the message.  In another use case, an attacker can reduce the tag length of the chosen AEAD cipher for a given AuthEnvelopedData container to be a single byte long, allowing an attacker to brute force CMS decryption, producing an integrity bypass for applications that trust CMS_decrypt() to reject modified content.  The FIPS modules are not affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34183",
                        "url": "https://ubuntu.com/security/CVE-2026-34183",
                        "cve_description": "Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames.  Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service.  A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-35188",
                        "url": "https://ubuntu.com/security/CVE-2026-35188",
                        "cve_description": "Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path.  Impact summary: Successful exploitation allows an attacker to corrupt heap memory via a double-free, potentially leading to a Denial of Service or possibly an attacker controlled code execution or other undefined behavior.  If OCSP stapling is enabled and the TLS client connects to a malicious server, a crafted OCSP stapled response can trigger a double free in the TLS client when the stapled response is checked.  The OCSP stapling is not enabled by default. Reliable code execution through a double-free is technically complex and highly environment-dependent but the Denial of Service impact is straightforward to achieve, warranting Moderate severity.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42764",
                        "url": "https://ubuntu.com/security/CVE-2026-42764",
                        "cve_description": "Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled.  Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service.  If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token.  By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the default configuration not vulnerable to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with the SSL_new_listener() call, the address validation is disabled making the vulnerable code reachable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42765",
                        "url": "https://ubuntu.com/security/CVE-2026-42765",
                        "cve_description": "Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens.  This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verification. Both flags are disabled by default. For that reason, we have assigned Low severity to the issue.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42766",
                        "url": "https://ubuntu.com/security/CVE-2026-42766",
                        "cve_description": "Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as OPTIONAL in the ASN.1 specification and may therefore be absent in specially crafted inputs. During the password-based CMS decryption the OpenSSL CMS implementation dereferences this field without first checking whether it was present.  An attacker who supplies such a CMS message to an application performing password-based CMS decryption can trigger an application crash, leading to a Denial of Service.  Applications that process password-encrypted CMS messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42767",
                        "url": "https://ubuntu.com/security/CVE-2026-42767",
                        "cve_description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42768",
                        "url": "https://ubuntu.com/security/CVE-2026-42768",
                        "cve_description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output.  Impact summary: The Bleichenbacher-style attack allows an attacker to use the victim's vulnerable application as a way to decrypt or sign messages with the victim's private RSA key.  The attack is possible in 2 variants.  1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without providing the recipient certificate. In this case OpenSSL iterates over every KeyTransRecipientInfo (KTRI) without stopping at the first success.  An attacker who authors a message with two KTRI entries — the first one wrapping a real CEK under the victim's public key, the second with an arbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to get a valid PKCS#1 v1.5 padding if the error code of the application is available.  That is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an adaptive-chosen-ciphertext side channel from which the attacker decrypts any RSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under it.  2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with the recipient certificate, and the recipient is not found, a random key is substituted.  An attacker who authors a message and is able to compare both error code and the result of the decryption, can mount a Bleichenbacher oracle.  We are not aware of any applications that provide a remote attacker an opportunity to mount an attack described in these scenarios. We consider the existence of such application very unlikely, and for this reason this CVE has been evaluated as Low severity.  To avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the invoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described in draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit rejection was explicitly disabled.  The implicit rejection mechanism always returns a plaintext value, the symmetric key. This result is deterministic for the ciphertext and the private key.  The length of the decryption result can happen to match the length of the key of the symmetric cipher that was used for the content encryption. When a certificate is not provided, the last RecipientInfo producing a key that looks valid will be used. It may cause getting garbage content on decryption. As a proper way to deal with this a recipient certificate has to be provided to identify the particular RecipientInfo for decryption.  The FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as CMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42769",
                        "url": "https://ubuntu.com/security/CVE-2026-42769",
                        "cve_description": "Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level.  Impact Summary: The Registration Autority could replace the root CA certificate for the CMP clients with an arbitrary root CA certificate.  One of the parts of the Certificate Management Protocol (CMP), specified in RFC 9810, is Root Certification Authority (root CA) key Rollover, which is sent by the server in a message with type 'id-it-rootCaKeyUpdate'. As part of these messages, 'newWithOld' certificate, the new root CA certificate signed with the old root CA key, is provided, and verifying its signature is crucial for transferring the trust from the old CA key to the new one.  The 'id-it-rootCaKeyUpdate' messages are expected to be processed with OSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld' certificate.  A typo in the certificate chain building code led to adding an incorrect certificate ('newWithOld' instead of 'oldRoot') to the certificate chain, rendering the certificate verification process ineffectual (only the issuer name and the algorithm OIDs were verified by other parts of the verification code).  An attacker who already has credentials that satisfy the CMP message protection checks can generate a new key pair and use a crafted self-signed certificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP clients would accept as a new trust anchor.  Significant preconditions for the attack (having valid RA-level credentials) are the reason the issue was assigned Low severity.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42770",
                        "url": "https://ubuntu.com/security/CVE-2026-42770",
                        "cve_description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership.  Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts.  When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared.  A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack).  The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42771",
                        "url": "https://ubuntu.com/security/CVE-2026-42771",
                        "cve_description": "Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen.  Impact summary: This out of bounds read will not directly exfiltrate the data read to the attacker so the most likely result is a crash and a Denial of Service.  An internal helper function called from X509_VERIFY_PARAM_[set|add]_email() used a wrong length when validating the local part of an email address. This could cause the 64 octet limit on the local part of an email address to be not enforced, or cause an out of bound read and potentially a crash.  The bug is reachable via S-MIME validation with a crafted From: address supplied in an email message that can potentially cause a crash.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45445",
                        "url": "https://ubuntu.com/security/CVE-2026-45445",
                        "cve_description": "Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded.  Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality.  If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not on the plaintext or ciphertext, allowing universal forgery of arbitrary ciphertext from a single captured message.  OpenSSL provides two ways to drive a cipher: the documented streaming interface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level one-shot, EVP_Cipher(), whose documentation explicitly recommends against use by applications in favour of EVP_CipherUpdate() and EVP_CipherFinal_ex().  The OCB provider's streaming handler flushes the application-supplied IV into the OCB context before processing data; the one-shot handler did not.  Every call to EVP_Cipher() on an AES-OCB context therefore ran with the all-zero key-derived offset state left by cipher initialisation, regardless of the caller's IV.  If EVP_EncryptFinal_ex() is subsequently used to obtain the authentication tag, the deferred IV setup runs at that point and clears the running checksum that should have been accumulated over the plaintext.  The resulting tag is a function of (key, IV) only and verifies against any ciphertext produced under the same (key, IV) pair.  The OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a TLS cipher suite, and libssl does not call EVP_Cipher() in any case. Applications that drive AES-OCB through the documented streaming AEAD API (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only applications that combine the AES-OCB cipher with the EVP_Cipher() one-shot API are vulnerable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45446",
                        "url": "https://ubuntu.com/security/CVE-2026-45446",
                        "cve_description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages.  Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers.  AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not encrypted), and plaintext, and produces ciphertext plus a 16-byte tag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only if the tag is verified succesfully.  In OpenSSL's provider implementation of these ciphers, the expected tag is computed only when decryption function is invoked with non-empty data. If the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without invocation of the ciphertext update, which can happen when the received ciphertext length is zero, the tag is never recalculated and still holds its all-zeros value.  When AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty ciphertext, and all-zeros tag passes authentication under any key they do not know, single-shot. When AES-SIV is used, for mounting the attack it's necessary for the application to reuse the decryption context without resetting the key.  AES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since OpenSSL 3.2.  No protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support either AES-GCM-SIV or AES-SIV. To mount an attack, the applications must implement their own protocol and use the EVP interface. Also they must skip the ciphertext update when a message with an empty ciphertext arrives.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as these algorithms are not FIPS approved and the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45447",
                        "url": "https://ubuntu.com/security/CVE-2026-45447",
                        "cve_description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.  Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution.  When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition.  In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution.  Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-2673",
                        "url": "https://ubuntu.com/security/CVE-2026-2673",
                        "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-03-13 19:54:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28387",
                        "url": "https://ubuntu.com/security/CVE-2026-28387",
                        "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28388",
                        "url": "https://ubuntu.com/security/CVE-2026-28388",
                        "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28389",
                        "url": "https://ubuntu.com/security/CVE-2026-28389",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28390",
                        "url": "https://ubuntu.com/security/CVE-2026-28390",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31789",
                        "url": "https://ubuntu.com/security/CVE-2026-31789",
                        "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31790",
                        "url": "https://ubuntu.com/security/CVE-2026-31790",
                        "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-2673",
                        "url": "https://ubuntu.com/security/CVE-2026-2673",
                        "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-03-13 19:54:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28387",
                        "url": "https://ubuntu.com/security/CVE-2026-28387",
                        "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28389",
                        "url": "https://ubuntu.com/security/CVE-2026-28389",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28390",
                        "url": "https://ubuntu.com/security/CVE-2026-28390",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31789",
                        "url": "https://ubuntu.com/security/CVE-2026-31789",
                        "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31790",
                        "url": "https://ubuntu.com/security/CVE-2026-31790",
                        "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28386",
                        "url": "https://ubuntu.com/security/CVE-2026-28386",
                        "cve_description": "Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output.  The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy.  Only x86-64 systems with AVX-512 and VAES instruction support are affected. Other architectures and systems without VAES support use different code paths that are not affected.  OpenSSL FIPS module in 3.6 version is affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28388",
                        "url": "https://ubuntu.com/security/CVE-2026-28388",
                        "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-11187",
                        "url": "https://ubuntu.com/security/CVE-2025-11187",
                        "cve_description": "Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification.  Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations.  When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without validation. If the value of keylength exceeds the size of the fixed stack buffer used for the derived key (64 bytes), the key derivation will overflow the buffer. The overflow length is attacker-controlled. Also, if the salt parameter is not an OCTET STRING type this can lead to invalid or NULL pointer dereference.  Exploiting this issue requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For this reason the issue was assessed as Moderate severity.  The FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as PKCS#12 processing is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue.  OpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do not support PBMAC1 in PKCS#12.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15467",
                        "url": "https://ubuntu.com/security/CVE-2025-15467",
                        "cve_description": "Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.  Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.  When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs.  Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.  OpenSSL 1.1.1 and 1.0.2 are not affected by this issue. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15468",
                        "url": "https://ubuntu.com/security/CVE-2025-15468",
                        "cve_description": "Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.  Impact summary: A NULL pointer dereference leads to abnormal termination of the running process causing Denial of Service.  Some applications call SSL_CIPHER_find() from the client_hello_cb callback on the cipher ID received from the peer. If this is done with an SSL object implementing the QUIC protocol, NULL pointer dereference will happen if the examined cipher ID is unknown or unsupported.  As it is not very common to call this function in applications using the QUIC protocol and the worst outcome is Denial of Service, the issue was assessed as Low severity.  The vulnerable code was introduced in the 3.2 version with the addition of the QUIC protocol support.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the QUIC implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15469",
                        "url": "https://ubuntu.com/security/CVE-2025-15469",
                        "cve_description": "Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error.  Impact summary: A user signing or verifying files larger than 16MB with one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire file is authenticated while trailing data beyond 16MB remains unauthenticated.  When the 'openssl dgst' command is used with algorithms that only support one-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input is buffered with a 16MB limit. If the input exceeds this limit, the tool silently truncates to the first 16MB and continues without signaling an error, contrary to what the documentation states. This creates an integrity gap where trailing bytes can be modified without detection if both signing and verification are performed using the same affected codepath.  The issue affects only the command-line tool behavior. Verifiers that process the full message using library APIs will reject the signature, so the risk primarily affects workflows that both sign and verify with the affected 'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and library users are unaffected.  The FIPS modules in 3.5 and 3.6 are not affected by this issue, as the command-line tools are outside the OpenSSL FIPS module boundary.  OpenSSL 3.5 and 3.6 are vulnerable to this issue.  OpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-66199",
                        "url": "https://ubuntu.com/security/CVE-2025-66199",
                        "cve_description": "Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.  Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work, potentially leading to service degradation or resource exhaustion (Denial of Service).  In affected configurations, the peer-supplied uncompressed certificate length from a CompressedCertificate message is used to grow a heap buffer prior to decompression. This length is not bounded by the max_cert_list setting, which otherwise constrains certificate message sizes. An attacker can exploit this to cause large per-connection allocations followed by handshake failure. No memory corruption or information disclosure occurs.  This issue only affects builds where TLS 1.3 certificate compression is compiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression algorithm (brotli, zlib, or zstd) is available, and where the compression extension is negotiated. Both clients receiving a server CompressedCertificate and servers in mutual TLS scenarios receiving a client CompressedCertificate are affected. Servers that do not request client certificates are not vulnerable to client-initiated attacks.  Users can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION to disable receiving compressed certificates.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the TLS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-68160",
                        "url": "https://ubuntu.com/security/CVE-2025-68160",
                        "cve_description": "Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.  Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application.  The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69418",
                        "url": "https://ubuntu.com/security/CVE-2025-69418",
                        "cve_description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69419",
                        "url": "https://ubuntu.com/security/CVE-2025-69419",
                        "cve_description": "Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.  Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service.  The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer.  The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer. The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69420",
                        "url": "https://ubuntu.com/security/CVE-2025-69420",
                        "cve_description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.  Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69421",
                        "url": "https://ubuntu.com/security/CVE-2025-69421",
                        "cve_description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.  Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files.  The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure.  Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-22795",
                        "url": "https://ubuntu.com/security/CVE-2026-22795",
                        "cve_description": "Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.  Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service.  A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read.  The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-22796",
                        "url": "https://ubuntu.com/security/CVE-2026-22796",
                        "cve_description": "Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.  Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163146,
                    2158026,
                    2158026,
                    2160606,
                    2147669,
                    2153135
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/default-configuration-read-dropins-and-crypto-config.patch:",
                            "    partially restore patch, needed by src:crypto-policies",
                            "    (LP: #2163146)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163146
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 12 Aug 2026 15:20:38 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert \"Add Depends on libjitterentropy3-dev, zlib1g-dev, and libzstd-dev.",
                            "    (LP: #2158026)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158026
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Mon, 10 Aug 2026 11:49:51 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add Depends on libjitterentropy3-dev, zlib1g-dev, and libzstd-dev.",
                            "    libcrypto.pc declares these as static private dependencies",
                            "    (Libs.private) but libssl-dev did not pull them in, breaking static",
                            "    linking against libcrypto. (LP: #2158026)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158026
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Mon, 03 Aug 2026 16:49:15 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Ravi Kant Sharma ]",
                            "  * Merge with Debian experimental (LP: #2160606). Remaining changes:",
                            "    - Use perl:native in the autopkgtest for installability on i386.",
                            "    - Symlink copyright/changelog.Debian.gz in libssl3* to libssl-dev/openssl",
                            "    - Disable LTO with which the codebase is generally incompatible",
                            "      (LP #2058017)",
                            "    - Don't enable or package anything FIPS (LP #2087955)",
                            "    - Match last filename for output in ecp_nistp521-ppc64.pl (LP #2137464)",
                            "    - Enable CPU jitter fluctuations",
                            "    - fips patches (debian/patches/fips):",
                            "      - crypto: Add kernel FIPS mode detection",
                            "      - crypto: Automatically use the FIPS provider...",
                            "      - apps/speed: Omit unavailable algorithms in FIPS mode",
                            "      - apps: pass -propquery arg to the libctx DRBG fetches",
                            "      - test: Ensure encoding runs with the correct context...",
                            "      - Add Ubuntu-specific defines to help FIPS certification (LP #2073991)",
                            "        + UBUNTU_OSSL_SELF_TEST_DESC_PCT_DH",
                            "        + UBUNTU_OSSL_PROV_FIPS_PARAM_UNAPPROVED_USAGE",
                            "      - Detect FIPS jitterentropy mode and load jitterentropy enabled FIPS",
                            "        provider",
                            "      - Fallback to default provider when FIPS provider is missing.",
                            "  * Dropped patches, not required anymore in Ubuntu",
                            "    - d/p/default-configuration-read-dropins-and-crypto-config.patch",
                            "",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160606
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Tue, 14 Jul 2026 12:53:05 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-7383",
                                "url": "https://ubuntu.com/security/CVE-2026-7383",
                                "cve_description": "Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow.  Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefined behaviour.  In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination size for Unicode output is computed in a signed int: by left shift of the input character count for BMPSTRING (UTF-16) and UNIVERSALSTRING (UTF-32), and by summing per-character byte counts for UTF8STRING. The calculation overflows when the input reaches around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30 characters) the size wraps to zero, OPENSSL_malloc(1) is called, and the subsequent character copy writes several gigabytes past the one-byte allocation.  X.509 certificate processing routes through ASN1_STRING_set_by_NID(), whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID size limits cap the input length; no network protocol or certificate-handling path in OpenSSL exercises the overflow. Triggering the bug requires an application that calls ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers a custom string type via ASN1_STRING_TABLE_add(), with attacker-controlled input on the order of half a gigabyte or more. For these reasons this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-9076",
                                "url": "https://ubuntu.com/security/CVE-2026-9076",
                                "cve_description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key().  Impact summary: A heap buffer over-read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not revealed to the attacker.  The key unwrapping function performs a check-byte test as specified in the RFC that reads 7 bytes from a heap allocation that is based on the wrapped key length from the message. There is a minimum length check based on the block length of the wrapping cipher. However the cipher is selected from an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no requirement that the cipher be a block cipher. When an attacker selects a stream-mode cipher the guard will be ineffective and the allocated buffer containing the unwrapped key can be too small to fit the check-bytes specified in the RFC and a buffer over-read can happen.  Applications calling CMS_decrypt() or CMS_decrypt_set1_password() (equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS data are vulnerable to this issue. No password knowledge is required: the over-read happens during the unwrap attempt before any authentication succeeds.  The over-read is limited to a few bytes and is not written to output, so there is no information disclosure. Triggering a crash requires the allocation to border unmapped memory, which is unlikely with the normal allocator.  The FIPS modules are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34180",
                                "url": "https://ubuntu.com/security/CVE-2026-34180",
                                "cve_description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms.  Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer.  More typically such ASN.1 elements would instead be truncated.  An integer truncation in OpenSSL's ASN.1 decoder causes the content length of an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the worst case the truncated length is treated as a request to scan the binary content for a terminating zero byte, possibly causing OpenSSL to read either less than or beyond the end of the allocated buffer.  Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or any other d2i_* decoding function are affected. OpenSSL's own command-line tools are not vulnerable, as data read through the BIO layer is checked before it reaches the affected code. The issue only affects 64-bit Unix and Unix-like platforms; 32-bit platforms and 64-bit Windows are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34181",
                                "url": "https://ubuntu.com/security/CVE-2026-34181",
                                "cve_description": "Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery.  Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability.  If a service accepting PKCS#12 files is using passwords for authenticating the received files, the attacker can create unencrypted PKCS#12 files that use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing them to craft a file that will be accepted with a 1 in 256 probability. That would then cause the service to accept a certificate and private key controlled by the attacker.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34182",
                                "url": "https://ubuntu.com/security/CVE-2026-34182",
                                "cve_description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises.  Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message.  In one use case, an attacker may send a CMS message containing AuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL erroneously allows this selection, and attempts to decrypt and validate the message.  An on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData addressed to the victim can re-emit it with the recipientInfos set left byte-for-byte intact, so the victim's private key still unwraps the genuine CEK (the content-encryption key), but with the inner OID rewritten to AES-256-OFB (Output Feedback Mode, an unauthenticated keystream mode) and with an attacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the real CEK, never consults the MAC field, and CMS_decrypt() returns success.  If the application under attack responds to the attacker with any indicator showing success or failure of the decryption effort, it is possible for the attacker to use this as an oracle to obtain key equivalent functionality for the CEK used for the chosen recipient of the message.  In another use case, an attacker can reduce the tag length of the chosen AEAD cipher for a given AuthEnvelopedData container to be a single byte long, allowing an attacker to brute force CMS decryption, producing an integrity bypass for applications that trust CMS_decrypt() to reject modified content.  The FIPS modules are not affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34183",
                                "url": "https://ubuntu.com/security/CVE-2026-34183",
                                "cve_description": "Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames.  Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service.  A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-35188",
                                "url": "https://ubuntu.com/security/CVE-2026-35188",
                                "cve_description": "Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path.  Impact summary: Successful exploitation allows an attacker to corrupt heap memory via a double-free, potentially leading to a Denial of Service or possibly an attacker controlled code execution or other undefined behavior.  If OCSP stapling is enabled and the TLS client connects to a malicious server, a crafted OCSP stapled response can trigger a double free in the TLS client when the stapled response is checked.  The OCSP stapling is not enabled by default. Reliable code execution through a double-free is technically complex and highly environment-dependent but the Denial of Service impact is straightforward to achieve, warranting Moderate severity.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42764",
                                "url": "https://ubuntu.com/security/CVE-2026-42764",
                                "cve_description": "Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled.  Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service.  If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token.  By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the default configuration not vulnerable to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with the SSL_new_listener() call, the address validation is disabled making the vulnerable code reachable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42765",
                                "url": "https://ubuntu.com/security/CVE-2026-42765",
                                "cve_description": "Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens.  This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verification. Both flags are disabled by default. For that reason, we have assigned Low severity to the issue.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42766",
                                "url": "https://ubuntu.com/security/CVE-2026-42766",
                                "cve_description": "Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as OPTIONAL in the ASN.1 specification and may therefore be absent in specially crafted inputs. During the password-based CMS decryption the OpenSSL CMS implementation dereferences this field without first checking whether it was present.  An attacker who supplies such a CMS message to an application performing password-based CMS decryption can trigger an application crash, leading to a Denial of Service.  Applications that process password-encrypted CMS messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42767",
                                "url": "https://ubuntu.com/security/CVE-2026-42767",
                                "cve_description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42768",
                                "url": "https://ubuntu.com/security/CVE-2026-42768",
                                "cve_description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output.  Impact summary: The Bleichenbacher-style attack allows an attacker to use the victim's vulnerable application as a way to decrypt or sign messages with the victim's private RSA key.  The attack is possible in 2 variants.  1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without providing the recipient certificate. In this case OpenSSL iterates over every KeyTransRecipientInfo (KTRI) without stopping at the first success.  An attacker who authors a message with two KTRI entries — the first one wrapping a real CEK under the victim's public key, the second with an arbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to get a valid PKCS#1 v1.5 padding if the error code of the application is available.  That is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an adaptive-chosen-ciphertext side channel from which the attacker decrypts any RSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under it.  2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with the recipient certificate, and the recipient is not found, a random key is substituted.  An attacker who authors a message and is able to compare both error code and the result of the decryption, can mount a Bleichenbacher oracle.  We are not aware of any applications that provide a remote attacker an opportunity to mount an attack described in these scenarios. We consider the existence of such application very unlikely, and for this reason this CVE has been evaluated as Low severity.  To avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the invoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described in draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit rejection was explicitly disabled.  The implicit rejection mechanism always returns a plaintext value, the symmetric key. This result is deterministic for the ciphertext and the private key.  The length of the decryption result can happen to match the length of the key of the symmetric cipher that was used for the content encryption. When a certificate is not provided, the last RecipientInfo producing a key that looks valid will be used. It may cause getting garbage content on decryption. As a proper way to deal with this a recipient certificate has to be provided to identify the particular RecipientInfo for decryption.  The FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as CMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42769",
                                "url": "https://ubuntu.com/security/CVE-2026-42769",
                                "cve_description": "Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level.  Impact Summary: The Registration Autority could replace the root CA certificate for the CMP clients with an arbitrary root CA certificate.  One of the parts of the Certificate Management Protocol (CMP), specified in RFC 9810, is Root Certification Authority (root CA) key Rollover, which is sent by the server in a message with type 'id-it-rootCaKeyUpdate'. As part of these messages, 'newWithOld' certificate, the new root CA certificate signed with the old root CA key, is provided, and verifying its signature is crucial for transferring the trust from the old CA key to the new one.  The 'id-it-rootCaKeyUpdate' messages are expected to be processed with OSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld' certificate.  A typo in the certificate chain building code led to adding an incorrect certificate ('newWithOld' instead of 'oldRoot') to the certificate chain, rendering the certificate verification process ineffectual (only the issuer name and the algorithm OIDs were verified by other parts of the verification code).  An attacker who already has credentials that satisfy the CMP message protection checks can generate a new key pair and use a crafted self-signed certificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP clients would accept as a new trust anchor.  Significant preconditions for the attack (having valid RA-level credentials) are the reason the issue was assigned Low severity.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42770",
                                "url": "https://ubuntu.com/security/CVE-2026-42770",
                                "cve_description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership.  Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts.  When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared.  A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack).  The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42771",
                                "url": "https://ubuntu.com/security/CVE-2026-42771",
                                "cve_description": "Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen.  Impact summary: This out of bounds read will not directly exfiltrate the data read to the attacker so the most likely result is a crash and a Denial of Service.  An internal helper function called from X509_VERIFY_PARAM_[set|add]_email() used a wrong length when validating the local part of an email address. This could cause the 64 octet limit on the local part of an email address to be not enforced, or cause an out of bound read and potentially a crash.  The bug is reachable via S-MIME validation with a crafted From: address supplied in an email message that can potentially cause a crash.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45445",
                                "url": "https://ubuntu.com/security/CVE-2026-45445",
                                "cve_description": "Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded.  Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality.  If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not on the plaintext or ciphertext, allowing universal forgery of arbitrary ciphertext from a single captured message.  OpenSSL provides two ways to drive a cipher: the documented streaming interface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level one-shot, EVP_Cipher(), whose documentation explicitly recommends against use by applications in favour of EVP_CipherUpdate() and EVP_CipherFinal_ex().  The OCB provider's streaming handler flushes the application-supplied IV into the OCB context before processing data; the one-shot handler did not.  Every call to EVP_Cipher() on an AES-OCB context therefore ran with the all-zero key-derived offset state left by cipher initialisation, regardless of the caller's IV.  If EVP_EncryptFinal_ex() is subsequently used to obtain the authentication tag, the deferred IV setup runs at that point and clears the running checksum that should have been accumulated over the plaintext.  The resulting tag is a function of (key, IV) only and verifies against any ciphertext produced under the same (key, IV) pair.  The OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a TLS cipher suite, and libssl does not call EVP_Cipher() in any case. Applications that drive AES-OCB through the documented streaming AEAD API (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only applications that combine the AES-OCB cipher with the EVP_Cipher() one-shot API are vulnerable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45446",
                                "url": "https://ubuntu.com/security/CVE-2026-45446",
                                "cve_description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages.  Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers.  AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not encrypted), and plaintext, and produces ciphertext plus a 16-byte tag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only if the tag is verified succesfully.  In OpenSSL's provider implementation of these ciphers, the expected tag is computed only when decryption function is invoked with non-empty data. If the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without invocation of the ciphertext update, which can happen when the received ciphertext length is zero, the tag is never recalculated and still holds its all-zeros value.  When AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty ciphertext, and all-zeros tag passes authentication under any key they do not know, single-shot. When AES-SIV is used, for mounting the attack it's necessary for the application to reuse the decryption context without resetting the key.  AES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since OpenSSL 3.2.  No protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support either AES-GCM-SIV or AES-SIV. To mount an attack, the applications must implement their own protocol and use the EVP interface. Also they must skip the ciphertext update when a message with an empty ciphertext arrives.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as these algorithms are not FIPS approved and the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45447",
                                "url": "https://ubuntu.com/security/CVE-2026-45447",
                                "cve_description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.  Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution.  When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition.  In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution.  Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Import 4.0.1",
                            "   - CVE-2026-7383 (\"Possible Heap Buffer Overflow in ASN.1 Multibyte String",
                            "     Conversion\")",
                            "   - CVE-2026-9076 (\"Out-of-Bounds Read in CMS Password-Based Decryption\")",
                            "   - CVE-2026-34180 (\"Heap Buffer Over-read in ASN.1 Content Parsing\")",
                            "   - CVE-2026-34181 (\"PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC",
                            "     Keys\")",
                            "   - CVE-2026-34182 (\"CMS AuthEnvelopedData Processing May Accept Forged",
                            "     Messages\")",
                            "   - CVE-2026-34183 (\"Unbounded Memory Growth in the QUIC PATH_CHALLENGE",
                            "     Handler\")",
                            "   - CVE-2026-35188 (\"Double-free When Checking OCSP Stapled Response\")",
                            "   - CVE-2026-42764 (\"NULL pointer dereference in QUIC server initial packet",
                            "     handling\")",
                            "   - CVE-2026-42765 (\"NULL Dereference in Certificate Verification with OCSP",
                            "     Checking\")",
                            "   - CVE-2026-42766 (\"Possible NULL Dereference in Password-Based CMS",
                            "     Decryption\")",
                            "   - CVE-2026-42767 (\"NULL Pointer Dereference in CRMF EncryptedValue",
                            "     Decryption\")",
                            "   - CVE-2026-42768 (\"Multi-RecipientInfo Bleichenbacher Oracle in",
                            "     CMS_decrypt() and PKCS7_decrypt()\")",
                            "   - CVE-2026-42769 (\"Trust-Anchor Substitution via cert/issuer Typo in CMP",
                            "     rootCaKeyUpdate\")",
                            "   - CVE-2026-42770 (\"FFC-DH Peer Validation Uses Attacker-Supplied q\")",
                            "   - CVE-2026-42771 (\"Possible Out of Bounds Read in",
                            "     X509_VERIFY_PARAM_set1_email()\")",
                            "   - CVE-2026-45445 (\"AES-OCB IV Ignored on EVP_Cipher() Path\")",
                            "   - CVE-2026-45446 (\"Incorrect Tag Processing for Empty Messages in",
                            "     AES-GCM-SIV and AES-SIV modes\")",
                            "   - CVE-2026-45447 (\"Heap Use-After-Free in OpenSSL PKCS7_verify()\")",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Sat, 13 Jun 2026 20:01:42 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-2673",
                                "url": "https://ubuntu.com/security/CVE-2026-2673",
                                "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-03-13 19:54:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28387",
                                "url": "https://ubuntu.com/security/CVE-2026-28387",
                                "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28388",
                                "url": "https://ubuntu.com/security/CVE-2026-28388",
                                "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28389",
                                "url": "https://ubuntu.com/security/CVE-2026-28389",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28390",
                                "url": "https://ubuntu.com/security/CVE-2026-28390",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31789",
                                "url": "https://ubuntu.com/security/CVE-2026-31789",
                                "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31790",
                                "url": "https://ubuntu.com/security/CVE-2026-31790",
                                "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Eric Berry ]",
                            "  * OpenSSL crashes in resolute when userspace entropy",
                            "    is enabled but fips provider is not installed (LP: #2147669)",
                            "",
                            "  [ Ravi Kant Sharma ]",
                            "  * Merge with Debian experimental (LP: #2153135). Remaining changes:",
                            "    - Use perl:native in the autopkgtest for installability on i386.",
                            "    - Symlink copyright/changelog.Debian.gz in libssl3* to libssl-dev/openssl",
                            "    - Disable LTO with which the codebase is generally incompatible",
                            "      (LP #2058017)",
                            "    - Default config reads crypto-config and /etc/ssl/openssl.cnf.d dropins",
                            "    - Don't enable or package anything FIPS (LP #2087955)",
                            "    - Match last filename for output in ecp_nistp521-ppc64.pl (LP #2137464)",
                            "    - Enable CPU jitter fluctuations",
                            "    - fips patches (debian/patches/fips):",
                            "      - crypto: Add kernel FIPS mode detection",
                            "      - crypto: Automatically use the FIPS provider...",
                            "      - apps/speed: Omit unavailable algorithms in FIPS mode",
                            "      - apps: pass -propquery arg to the libctx DRBG fetches",
                            "      - test: Ensure encoding runs with the correct context...",
                            "      - Add Ubuntu-specific defines to help FIPS certification (LP #2073991)",
                            "        + UBUNTU_OSSL_SELF_TEST_DESC_PCT_DH",
                            "        + UBUNTU_OSSL_PROV_FIPS_PARAM_UNAPPROVED_USAGE",
                            "      - Detect FIPS jitterentropy mode and load jitterentropy enabled FIPS",
                            "        provider",
                            "      - Fallback to default provider when FIPS provider is missing.",
                            "  * Refreshed patches",
                            "    - fips/apps-speed-Omit-unavailable-algorithms-in-FIPS-mode.patch",
                            "    - fips/crypto-Add-kernel-FIPS-mode-detection.patch",
                            "    - fips/crypto-add-userspace-fips-mode-detection.patch",
                            "    - fips/crypto-Automatically-use-the-FIPS-provider-when-the-kerne.patch",
                            "  * Dropped patches, merged upstream",
                            "    - CVE-2026-2673.patch",
                            "    - CVE-2026-28387.patch",
                            "    - CVE-2026-28388-1.patch",
                            "    - CVE-2026-28388-2.patch",
                            "    - CVE-2026-28389.patch",
                            "    - CVE-2026-28390.patch",
                            "    - CVE-2026-31789.patch",
                            "    - CVE-2026-31790-1.patch",
                            "    - CVE-2026-31790-2.patch",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2147669,
                            2153135
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Wed, 20 May 2026 12:14:25 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-2673",
                                "url": "https://ubuntu.com/security/CVE-2026-2673",
                                "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-03-13 19:54:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28387",
                                "url": "https://ubuntu.com/security/CVE-2026-28387",
                                "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28389",
                                "url": "https://ubuntu.com/security/CVE-2026-28389",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28390",
                                "url": "https://ubuntu.com/security/CVE-2026-28390",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31789",
                                "url": "https://ubuntu.com/security/CVE-2026-31789",
                                "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31790",
                                "url": "https://ubuntu.com/security/CVE-2026-31790",
                                "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28386",
                                "url": "https://ubuntu.com/security/CVE-2026-28386",
                                "cve_description": "Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output.  The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy.  Only x86-64 systems with AVX-512 and VAES instruction support are affected. Other architectures and systems without VAES support use different code paths that are not affected.  OpenSSL FIPS module in 3.6 version is affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28388",
                                "url": "https://ubuntu.com/security/CVE-2026-28388",
                                "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Import 4.0.0",
                            "    - CVE-2026-2673 (\"OpenSSL TLS 1.3 server may choose unexpected key agreement",
                            "      group\") (Closes: #1130650).",
                            "    - CVE-2026-28387 (\"Potential use-after-free in DANE client code\")",
                            "    - CVE-2026-28389 (\"Possible NULL dereference when processing CMS",
                            "      KeyAgreeRecipientInfo\")",
                            "    - CVE-2026-28390 (\"Possible NULL dereference when processing CMS",
                            "      KeyTransportRecipient Info\")",
                            "    - CVE-2026-31789 (\"Heap buffer overflow in hexadecimal conversion\")",
                            "    - CVE-2026-31790 (\"Incorrect failure handling in RSA KEM RSASVE",
                            "      encapsulation\")",
                            "    - CVE-2026-28386 (\"Out-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512",
                            "      Support\")",
                            "    - CVE-2026-28388 (\"NULL Pointer Dereference When Processing a Delta CRL\")",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 16 Apr 2026 20:31:23 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 4.0.0-beta1",
                            "  * Add musl targets (Closes: #1131164).",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0~beta1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 26 Mar 2026 22:34:26 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 4.0.0-alpha1 (Closes: #1126531).",
                            "  * Update Standards-Version.",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0~alpha1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Fri, 13 Mar 2026 18:16:34 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 12 Mar 2026 21:00:23 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2025-11187",
                                "url": "https://ubuntu.com/security/CVE-2025-11187",
                                "cve_description": "Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification.  Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations.  When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without validation. If the value of keylength exceeds the size of the fixed stack buffer used for the derived key (64 bytes), the key derivation will overflow the buffer. The overflow length is attacker-controlled. Also, if the salt parameter is not an OCTET STRING type this can lead to invalid or NULL pointer dereference.  Exploiting this issue requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For this reason the issue was assessed as Moderate severity.  The FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as PKCS#12 processing is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue.  OpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do not support PBMAC1 in PKCS#12.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-15467",
                                "url": "https://ubuntu.com/security/CVE-2025-15467",
                                "cve_description": "Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.  Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.  When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs.  Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.  OpenSSL 1.1.1 and 1.0.2 are not affected by this issue. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-15468",
                                "url": "https://ubuntu.com/security/CVE-2025-15468",
                                "cve_description": "Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.  Impact summary: A NULL pointer dereference leads to abnormal termination of the running process causing Denial of Service.  Some applications call SSL_CIPHER_find() from the client_hello_cb callback on the cipher ID received from the peer. If this is done with an SSL object implementing the QUIC protocol, NULL pointer dereference will happen if the examined cipher ID is unknown or unsupported.  As it is not very common to call this function in applications using the QUIC protocol and the worst outcome is Denial of Service, the issue was assessed as Low severity.  The vulnerable code was introduced in the 3.2 version with the addition of the QUIC protocol support.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the QUIC implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-15469",
                                "url": "https://ubuntu.com/security/CVE-2025-15469",
                                "cve_description": "Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error.  Impact summary: A user signing or verifying files larger than 16MB with one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire file is authenticated while trailing data beyond 16MB remains unauthenticated.  When the 'openssl dgst' command is used with algorithms that only support one-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input is buffered with a 16MB limit. If the input exceeds this limit, the tool silently truncates to the first 16MB and continues without signaling an error, contrary to what the documentation states. This creates an integrity gap where trailing bytes can be modified without detection if both signing and verification are performed using the same affected codepath.  The issue affects only the command-line tool behavior. Verifiers that process the full message using library APIs will reject the signature, so the risk primarily affects workflows that both sign and verify with the affected 'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and library users are unaffected.  The FIPS modules in 3.5 and 3.6 are not affected by this issue, as the command-line tools are outside the OpenSSL FIPS module boundary.  OpenSSL 3.5 and 3.6 are vulnerable to this issue.  OpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-66199",
                                "url": "https://ubuntu.com/security/CVE-2025-66199",
                                "cve_description": "Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.  Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work, potentially leading to service degradation or resource exhaustion (Denial of Service).  In affected configurations, the peer-supplied uncompressed certificate length from a CompressedCertificate message is used to grow a heap buffer prior to decompression. This length is not bounded by the max_cert_list setting, which otherwise constrains certificate message sizes. An attacker can exploit this to cause large per-connection allocations followed by handshake failure. No memory corruption or information disclosure occurs.  This issue only affects builds where TLS 1.3 certificate compression is compiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression algorithm (brotli, zlib, or zstd) is available, and where the compression extension is negotiated. Both clients receiving a server CompressedCertificate and servers in mutual TLS scenarios receiving a client CompressedCertificate are affected. Servers that do not request client certificates are not vulnerable to client-initiated attacks.  Users can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION to disable receiving compressed certificates.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the TLS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-68160",
                                "url": "https://ubuntu.com/security/CVE-2025-68160",
                                "cve_description": "Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.  Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application.  The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69418",
                                "url": "https://ubuntu.com/security/CVE-2025-69418",
                                "cve_description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69419",
                                "url": "https://ubuntu.com/security/CVE-2025-69419",
                                "cve_description": "Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.  Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service.  The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer.  The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer. The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69420",
                                "url": "https://ubuntu.com/security/CVE-2025-69420",
                                "cve_description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.  Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69421",
                                "url": "https://ubuntu.com/security/CVE-2025-69421",
                                "cve_description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.  Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files.  The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure.  Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-22795",
                                "url": "https://ubuntu.com/security/CVE-2026-22795",
                                "cve_description": "Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.  Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service.  A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read.  The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-22796",
                                "url": "https://ubuntu.com/security/CVE-2026-22796",
                                "cve_description": "Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.  Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Import 3.6.1",
                            "   - CVE-2025-11187 (Improper validation of PBMAC1 parameters in PKCS#12 MAC",
                            "     verification)",
                            "   - CVE-2025-15467 (Stack buffer overflow in CMS AuthEnvelopedData parsing)",
                            "   - CVE-2025-15468 (NULL dereference in SSL_CIPHER_find() function on unknown",
                            "     cipher ID)",
                            "   - CVE-2025-15469 (\"openssl dgst\" one-shot codepath silently truncates inputs",
                            "     >16MB)",
                            "   - CVE-2025-66199 (TLS 1.3 CompressedCertificate excessive memory allocation)",
                            "   - CVE-2025-68160 (Heap out-of-bounds write in BIO_f_linebuffer on short",
                            "     writes)",
                            "   - CVE-2025-69418 (Unauthenticated/unencrypted trailing bytes with low-level",
                            "     OCB function calls)",
                            "   - CVE-2025-69419 (Out of bounds write in PKCS12_get_friendlyname() UTF-8",
                            "     conversion)",
                            "   - CVE-2025-69420 (Missing ASN1_TYPE validation in TS_RESP_verify_response()",
                            "     function)",
                            "   - CVE-2025-69421 (NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex",
                            "     function)",
                            "   - CVE-2026-22795 (Missing ASN1_TYPE validation in PKCS#12 parsing)",
                            "   - CVE-2026-22796 (ASN1_TYPE Type Confusion in the",
                            "   - PKCS7_digest_from_attributes() function)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Tue, 27 Jan 2026 21:32:02 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Apply fix for upstream issue #28902",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Fri, 26 Dec 2025 17:01:03 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 3.6.0",
                            "  * Stop shipping c_rehash. It bas been long replaced by \"openssl rehash\"",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Fri, 03 Oct 2025 17:40:10 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 3.6.0-beta1",
                            "  * Drop pic & Bsymbolic patches. This shouldn't be needed anymore.",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0~~beta1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 18 Sep 2025 21:36:20 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 3.6.0-alpha1",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0~~alpha1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Sat, 06 Sep 2025 20:21:28 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "openssl-provider-legacy",
                "from_version": {
                    "source_package_name": "openssl",
                    "source_package_version": "3.5.5-1ubuntu4",
                    "version": "3.5.5-1ubuntu4"
                },
                "to_version": {
                    "source_package_name": "openssl",
                    "source_package_version": "4.0.1-1ubuntu4",
                    "version": "4.0.1-1ubuntu4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-7383",
                        "url": "https://ubuntu.com/security/CVE-2026-7383",
                        "cve_description": "Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow.  Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefined behaviour.  In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination size for Unicode output is computed in a signed int: by left shift of the input character count for BMPSTRING (UTF-16) and UNIVERSALSTRING (UTF-32), and by summing per-character byte counts for UTF8STRING. The calculation overflows when the input reaches around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30 characters) the size wraps to zero, OPENSSL_malloc(1) is called, and the subsequent character copy writes several gigabytes past the one-byte allocation.  X.509 certificate processing routes through ASN1_STRING_set_by_NID(), whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID size limits cap the input length; no network protocol or certificate-handling path in OpenSSL exercises the overflow. Triggering the bug requires an application that calls ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers a custom string type via ASN1_STRING_TABLE_add(), with attacker-controlled input on the order of half a gigabyte or more. For these reasons this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-9076",
                        "url": "https://ubuntu.com/security/CVE-2026-9076",
                        "cve_description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key().  Impact summary: A heap buffer over-read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not revealed to the attacker.  The key unwrapping function performs a check-byte test as specified in the RFC that reads 7 bytes from a heap allocation that is based on the wrapped key length from the message. There is a minimum length check based on the block length of the wrapping cipher. However the cipher is selected from an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no requirement that the cipher be a block cipher. When an attacker selects a stream-mode cipher the guard will be ineffective and the allocated buffer containing the unwrapped key can be too small to fit the check-bytes specified in the RFC and a buffer over-read can happen.  Applications calling CMS_decrypt() or CMS_decrypt_set1_password() (equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS data are vulnerable to this issue. No password knowledge is required: the over-read happens during the unwrap attempt before any authentication succeeds.  The over-read is limited to a few bytes and is not written to output, so there is no information disclosure. Triggering a crash requires the allocation to border unmapped memory, which is unlikely with the normal allocator.  The FIPS modules are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34180",
                        "url": "https://ubuntu.com/security/CVE-2026-34180",
                        "cve_description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms.  Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer.  More typically such ASN.1 elements would instead be truncated.  An integer truncation in OpenSSL's ASN.1 decoder causes the content length of an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the worst case the truncated length is treated as a request to scan the binary content for a terminating zero byte, possibly causing OpenSSL to read either less than or beyond the end of the allocated buffer.  Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or any other d2i_* decoding function are affected. OpenSSL's own command-line tools are not vulnerable, as data read through the BIO layer is checked before it reaches the affected code. The issue only affects 64-bit Unix and Unix-like platforms; 32-bit platforms and 64-bit Windows are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34181",
                        "url": "https://ubuntu.com/security/CVE-2026-34181",
                        "cve_description": "Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery.  Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability.  If a service accepting PKCS#12 files is using passwords for authenticating the received files, the attacker can create unencrypted PKCS#12 files that use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing them to craft a file that will be accepted with a 1 in 256 probability. That would then cause the service to accept a certificate and private key controlled by the attacker.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34182",
                        "url": "https://ubuntu.com/security/CVE-2026-34182",
                        "cve_description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises.  Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message.  In one use case, an attacker may send a CMS message containing AuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL erroneously allows this selection, and attempts to decrypt and validate the message.  An on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData addressed to the victim can re-emit it with the recipientInfos set left byte-for-byte intact, so the victim's private key still unwraps the genuine CEK (the content-encryption key), but with the inner OID rewritten to AES-256-OFB (Output Feedback Mode, an unauthenticated keystream mode) and with an attacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the real CEK, never consults the MAC field, and CMS_decrypt() returns success.  If the application under attack responds to the attacker with any indicator showing success or failure of the decryption effort, it is possible for the attacker to use this as an oracle to obtain key equivalent functionality for the CEK used for the chosen recipient of the message.  In another use case, an attacker can reduce the tag length of the chosen AEAD cipher for a given AuthEnvelopedData container to be a single byte long, allowing an attacker to brute force CMS decryption, producing an integrity bypass for applications that trust CMS_decrypt() to reject modified content.  The FIPS modules are not affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-34183",
                        "url": "https://ubuntu.com/security/CVE-2026-34183",
                        "cve_description": "Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames.  Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service.  A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-35188",
                        "url": "https://ubuntu.com/security/CVE-2026-35188",
                        "cve_description": "Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path.  Impact summary: Successful exploitation allows an attacker to corrupt heap memory via a double-free, potentially leading to a Denial of Service or possibly an attacker controlled code execution or other undefined behavior.  If OCSP stapling is enabled and the TLS client connects to a malicious server, a crafted OCSP stapled response can trigger a double free in the TLS client when the stapled response is checked.  The OCSP stapling is not enabled by default. Reliable code execution through a double-free is technically complex and highly environment-dependent but the Denial of Service impact is straightforward to achieve, warranting Moderate severity.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42764",
                        "url": "https://ubuntu.com/security/CVE-2026-42764",
                        "cve_description": "Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled.  Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service.  If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token.  By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the default configuration not vulnerable to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with the SSL_new_listener() call, the address validation is disabled making the vulnerable code reachable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42765",
                        "url": "https://ubuntu.com/security/CVE-2026-42765",
                        "cve_description": "Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens.  This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verification. Both flags are disabled by default. For that reason, we have assigned Low severity to the issue.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42766",
                        "url": "https://ubuntu.com/security/CVE-2026-42766",
                        "cve_description": "Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as OPTIONAL in the ASN.1 specification and may therefore be absent in specially crafted inputs. During the password-based CMS decryption the OpenSSL CMS implementation dereferences this field without first checking whether it was present.  An attacker who supplies such a CMS message to an application performing password-based CMS decryption can trigger an application crash, leading to a Denial of Service.  Applications that process password-encrypted CMS messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42767",
                        "url": "https://ubuntu.com/security/CVE-2026-42767",
                        "cve_description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42768",
                        "url": "https://ubuntu.com/security/CVE-2026-42768",
                        "cve_description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output.  Impact summary: The Bleichenbacher-style attack allows an attacker to use the victim's vulnerable application as a way to decrypt or sign messages with the victim's private RSA key.  The attack is possible in 2 variants.  1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without providing the recipient certificate. In this case OpenSSL iterates over every KeyTransRecipientInfo (KTRI) without stopping at the first success.  An attacker who authors a message with two KTRI entries — the first one wrapping a real CEK under the victim's public key, the second with an arbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to get a valid PKCS#1 v1.5 padding if the error code of the application is available.  That is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an adaptive-chosen-ciphertext side channel from which the attacker decrypts any RSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under it.  2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with the recipient certificate, and the recipient is not found, a random key is substituted.  An attacker who authors a message and is able to compare both error code and the result of the decryption, can mount a Bleichenbacher oracle.  We are not aware of any applications that provide a remote attacker an opportunity to mount an attack described in these scenarios. We consider the existence of such application very unlikely, and for this reason this CVE has been evaluated as Low severity.  To avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the invoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described in draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit rejection was explicitly disabled.  The implicit rejection mechanism always returns a plaintext value, the symmetric key. This result is deterministic for the ciphertext and the private key.  The length of the decryption result can happen to match the length of the key of the symmetric cipher that was used for the content encryption. When a certificate is not provided, the last RecipientInfo producing a key that looks valid will be used. It may cause getting garbage content on decryption. As a proper way to deal with this a recipient certificate has to be provided to identify the particular RecipientInfo for decryption.  The FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as CMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42769",
                        "url": "https://ubuntu.com/security/CVE-2026-42769",
                        "cve_description": "Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level.  Impact Summary: The Registration Autority could replace the root CA certificate for the CMP clients with an arbitrary root CA certificate.  One of the parts of the Certificate Management Protocol (CMP), specified in RFC 9810, is Root Certification Authority (root CA) key Rollover, which is sent by the server in a message with type 'id-it-rootCaKeyUpdate'. As part of these messages, 'newWithOld' certificate, the new root CA certificate signed with the old root CA key, is provided, and verifying its signature is crucial for transferring the trust from the old CA key to the new one.  The 'id-it-rootCaKeyUpdate' messages are expected to be processed with OSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld' certificate.  A typo in the certificate chain building code led to adding an incorrect certificate ('newWithOld' instead of 'oldRoot') to the certificate chain, rendering the certificate verification process ineffectual (only the issuer name and the algorithm OIDs were verified by other parts of the verification code).  An attacker who already has credentials that satisfy the CMP message protection checks can generate a new key pair and use a crafted self-signed certificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP clients would accept as a new trust anchor.  Significant preconditions for the attack (having valid RA-level credentials) are the reason the issue was assigned Low severity.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42770",
                        "url": "https://ubuntu.com/security/CVE-2026-42770",
                        "cve_description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership.  Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts.  When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared.  A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack).  The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42771",
                        "url": "https://ubuntu.com/security/CVE-2026-42771",
                        "cve_description": "Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen.  Impact summary: This out of bounds read will not directly exfiltrate the data read to the attacker so the most likely result is a crash and a Denial of Service.  An internal helper function called from X509_VERIFY_PARAM_[set|add]_email() used a wrong length when validating the local part of an email address. This could cause the 64 octet limit on the local part of an email address to be not enforced, or cause an out of bound read and potentially a crash.  The bug is reachable via S-MIME validation with a crafted From: address supplied in an email message that can potentially cause a crash.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45445",
                        "url": "https://ubuntu.com/security/CVE-2026-45445",
                        "cve_description": "Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded.  Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality.  If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not on the plaintext or ciphertext, allowing universal forgery of arbitrary ciphertext from a single captured message.  OpenSSL provides two ways to drive a cipher: the documented streaming interface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level one-shot, EVP_Cipher(), whose documentation explicitly recommends against use by applications in favour of EVP_CipherUpdate() and EVP_CipherFinal_ex().  The OCB provider's streaming handler flushes the application-supplied IV into the OCB context before processing data; the one-shot handler did not.  Every call to EVP_Cipher() on an AES-OCB context therefore ran with the all-zero key-derived offset state left by cipher initialisation, regardless of the caller's IV.  If EVP_EncryptFinal_ex() is subsequently used to obtain the authentication tag, the deferred IV setup runs at that point and clears the running checksum that should have been accumulated over the plaintext.  The resulting tag is a function of (key, IV) only and verifies against any ciphertext produced under the same (key, IV) pair.  The OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a TLS cipher suite, and libssl does not call EVP_Cipher() in any case. Applications that drive AES-OCB through the documented streaming AEAD API (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only applications that combine the AES-OCB cipher with the EVP_Cipher() one-shot API are vulnerable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45446",
                        "url": "https://ubuntu.com/security/CVE-2026-45446",
                        "cve_description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages.  Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers.  AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not encrypted), and plaintext, and produces ciphertext plus a 16-byte tag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only if the tag is verified succesfully.  In OpenSSL's provider implementation of these ciphers, the expected tag is computed only when decryption function is invoked with non-empty data. If the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without invocation of the ciphertext update, which can happen when the received ciphertext length is zero, the tag is never recalculated and still holds its all-zeros value.  When AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty ciphertext, and all-zeros tag passes authentication under any key they do not know, single-shot. When AES-SIV is used, for mounting the attack it's necessary for the application to reuse the decryption context without resetting the key.  AES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since OpenSSL 3.2.  No protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support either AES-GCM-SIV or AES-SIV. To mount an attack, the applications must implement their own protocol and use the EVP interface. Also they must skip the ciphertext update when a message with an empty ciphertext arrives.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as these algorithms are not FIPS approved and the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45447",
                        "url": "https://ubuntu.com/security/CVE-2026-45447",
                        "cve_description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.  Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution.  When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition.  In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution.  Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-06-09 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-2673",
                        "url": "https://ubuntu.com/security/CVE-2026-2673",
                        "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-03-13 19:54:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28387",
                        "url": "https://ubuntu.com/security/CVE-2026-28387",
                        "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28388",
                        "url": "https://ubuntu.com/security/CVE-2026-28388",
                        "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28389",
                        "url": "https://ubuntu.com/security/CVE-2026-28389",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28390",
                        "url": "https://ubuntu.com/security/CVE-2026-28390",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31789",
                        "url": "https://ubuntu.com/security/CVE-2026-31789",
                        "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31790",
                        "url": "https://ubuntu.com/security/CVE-2026-31790",
                        "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-2673",
                        "url": "https://ubuntu.com/security/CVE-2026-2673",
                        "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-03-13 19:54:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28387",
                        "url": "https://ubuntu.com/security/CVE-2026-28387",
                        "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28389",
                        "url": "https://ubuntu.com/security/CVE-2026-28389",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28390",
                        "url": "https://ubuntu.com/security/CVE-2026-28390",
                        "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31789",
                        "url": "https://ubuntu.com/security/CVE-2026-31789",
                        "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-31790",
                        "url": "https://ubuntu.com/security/CVE-2026-31790",
                        "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28386",
                        "url": "https://ubuntu.com/security/CVE-2026-28386",
                        "cve_description": "Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output.  The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy.  Only x86-64 systems with AVX-512 and VAES instruction support are affected. Other architectures and systems without VAES support use different code paths that are not affected.  OpenSSL FIPS module in 3.6 version is affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-28388",
                        "url": "https://ubuntu.com/security/CVE-2026-28388",
                        "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-04-07 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-11187",
                        "url": "https://ubuntu.com/security/CVE-2025-11187",
                        "cve_description": "Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification.  Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations.  When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without validation. If the value of keylength exceeds the size of the fixed stack buffer used for the derived key (64 bytes), the key derivation will overflow the buffer. The overflow length is attacker-controlled. Also, if the salt parameter is not an OCTET STRING type this can lead to invalid or NULL pointer dereference.  Exploiting this issue requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For this reason the issue was assessed as Moderate severity.  The FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as PKCS#12 processing is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue.  OpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do not support PBMAC1 in PKCS#12.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15467",
                        "url": "https://ubuntu.com/security/CVE-2025-15467",
                        "cve_description": "Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.  Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.  When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs.  Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.  OpenSSL 1.1.1 and 1.0.2 are not affected by this issue. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15468",
                        "url": "https://ubuntu.com/security/CVE-2025-15468",
                        "cve_description": "Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.  Impact summary: A NULL pointer dereference leads to abnormal termination of the running process causing Denial of Service.  Some applications call SSL_CIPHER_find() from the client_hello_cb callback on the cipher ID received from the peer. If this is done with an SSL object implementing the QUIC protocol, NULL pointer dereference will happen if the examined cipher ID is unknown or unsupported.  As it is not very common to call this function in applications using the QUIC protocol and the worst outcome is Denial of Service, the issue was assessed as Low severity.  The vulnerable code was introduced in the 3.2 version with the addition of the QUIC protocol support.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the QUIC implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15469",
                        "url": "https://ubuntu.com/security/CVE-2025-15469",
                        "cve_description": "Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error.  Impact summary: A user signing or verifying files larger than 16MB with one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire file is authenticated while trailing data beyond 16MB remains unauthenticated.  When the 'openssl dgst' command is used with algorithms that only support one-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input is buffered with a 16MB limit. If the input exceeds this limit, the tool silently truncates to the first 16MB and continues without signaling an error, contrary to what the documentation states. This creates an integrity gap where trailing bytes can be modified without detection if both signing and verification are performed using the same affected codepath.  The issue affects only the command-line tool behavior. Verifiers that process the full message using library APIs will reject the signature, so the risk primarily affects workflows that both sign and verify with the affected 'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and library users are unaffected.  The FIPS modules in 3.5 and 3.6 are not affected by this issue, as the command-line tools are outside the OpenSSL FIPS module boundary.  OpenSSL 3.5 and 3.6 are vulnerable to this issue.  OpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-66199",
                        "url": "https://ubuntu.com/security/CVE-2025-66199",
                        "cve_description": "Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.  Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work, potentially leading to service degradation or resource exhaustion (Denial of Service).  In affected configurations, the peer-supplied uncompressed certificate length from a CompressedCertificate message is used to grow a heap buffer prior to decompression. This length is not bounded by the max_cert_list setting, which otherwise constrains certificate message sizes. An attacker can exploit this to cause large per-connection allocations followed by handshake failure. No memory corruption or information disclosure occurs.  This issue only affects builds where TLS 1.3 certificate compression is compiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression algorithm (brotli, zlib, or zstd) is available, and where the compression extension is negotiated. Both clients receiving a server CompressedCertificate and servers in mutual TLS scenarios receiving a client CompressedCertificate are affected. Servers that do not request client certificates are not vulnerable to client-initiated attacks.  Users can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION to disable receiving compressed certificates.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the TLS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-68160",
                        "url": "https://ubuntu.com/security/CVE-2025-68160",
                        "cve_description": "Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.  Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application.  The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69418",
                        "url": "https://ubuntu.com/security/CVE-2025-69418",
                        "cve_description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69419",
                        "url": "https://ubuntu.com/security/CVE-2025-69419",
                        "cve_description": "Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.  Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service.  The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer.  The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer. The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69420",
                        "url": "https://ubuntu.com/security/CVE-2025-69420",
                        "cve_description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.  Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-69421",
                        "url": "https://ubuntu.com/security/CVE-2025-69421",
                        "cve_description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.  Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files.  The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure.  Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-22795",
                        "url": "https://ubuntu.com/security/CVE-2026-22795",
                        "cve_description": "Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.  Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service.  A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read.  The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-22796",
                        "url": "https://ubuntu.com/security/CVE-2026-22796",
                        "cve_description": "Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.  Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-01-27 16:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163146,
                    2158026,
                    2158026,
                    2160606,
                    2147669,
                    2153135
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/default-configuration-read-dropins-and-crypto-config.patch:",
                            "    partially restore patch, needed by src:crypto-policies",
                            "    (LP: #2163146)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163146
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 12 Aug 2026 15:20:38 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert \"Add Depends on libjitterentropy3-dev, zlib1g-dev, and libzstd-dev.",
                            "    (LP: #2158026)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158026
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Mon, 10 Aug 2026 11:49:51 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add Depends on libjitterentropy3-dev, zlib1g-dev, and libzstd-dev.",
                            "    libcrypto.pc declares these as static private dependencies",
                            "    (Libs.private) but libssl-dev did not pull them in, breaking static",
                            "    linking against libcrypto. (LP: #2158026)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158026
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Mon, 03 Aug 2026 16:49:15 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Ravi Kant Sharma ]",
                            "  * Merge with Debian experimental (LP: #2160606). Remaining changes:",
                            "    - Use perl:native in the autopkgtest for installability on i386.",
                            "    - Symlink copyright/changelog.Debian.gz in libssl3* to libssl-dev/openssl",
                            "    - Disable LTO with which the codebase is generally incompatible",
                            "      (LP #2058017)",
                            "    - Don't enable or package anything FIPS (LP #2087955)",
                            "    - Match last filename for output in ecp_nistp521-ppc64.pl (LP #2137464)",
                            "    - Enable CPU jitter fluctuations",
                            "    - fips patches (debian/patches/fips):",
                            "      - crypto: Add kernel FIPS mode detection",
                            "      - crypto: Automatically use the FIPS provider...",
                            "      - apps/speed: Omit unavailable algorithms in FIPS mode",
                            "      - apps: pass -propquery arg to the libctx DRBG fetches",
                            "      - test: Ensure encoding runs with the correct context...",
                            "      - Add Ubuntu-specific defines to help FIPS certification (LP #2073991)",
                            "        + UBUNTU_OSSL_SELF_TEST_DESC_PCT_DH",
                            "        + UBUNTU_OSSL_PROV_FIPS_PARAM_UNAPPROVED_USAGE",
                            "      - Detect FIPS jitterentropy mode and load jitterentropy enabled FIPS",
                            "        provider",
                            "      - Fallback to default provider when FIPS provider is missing.",
                            "  * Dropped patches, not required anymore in Ubuntu",
                            "    - d/p/default-configuration-read-dropins-and-crypto-config.patch",
                            "",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160606
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Tue, 14 Jul 2026 12:53:05 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-7383",
                                "url": "https://ubuntu.com/security/CVE-2026-7383",
                                "cve_description": "Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow.  Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefined behaviour.  In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination size for Unicode output is computed in a signed int: by left shift of the input character count for BMPSTRING (UTF-16) and UNIVERSALSTRING (UTF-32), and by summing per-character byte counts for UTF8STRING. The calculation overflows when the input reaches around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30 characters) the size wraps to zero, OPENSSL_malloc(1) is called, and the subsequent character copy writes several gigabytes past the one-byte allocation.  X.509 certificate processing routes through ASN1_STRING_set_by_NID(), whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID size limits cap the input length; no network protocol or certificate-handling path in OpenSSL exercises the overflow. Triggering the bug requires an application that calls ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers a custom string type via ASN1_STRING_TABLE_add(), with attacker-controlled input on the order of half a gigabyte or more. For these reasons this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-9076",
                                "url": "https://ubuntu.com/security/CVE-2026-9076",
                                "cve_description": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key().  Impact summary: A heap buffer over-read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not revealed to the attacker.  The key unwrapping function performs a check-byte test as specified in the RFC that reads 7 bytes from a heap allocation that is based on the wrapped key length from the message. There is a minimum length check based on the block length of the wrapping cipher. However the cipher is selected from an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no requirement that the cipher be a block cipher. When an attacker selects a stream-mode cipher the guard will be ineffective and the allocated buffer containing the unwrapped key can be too small to fit the check-bytes specified in the RFC and a buffer over-read can happen.  Applications calling CMS_decrypt() or CMS_decrypt_set1_password() (equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS data are vulnerable to this issue. No password knowledge is required: the over-read happens during the unwrap attempt before any authentication succeeds.  The over-read is limited to a few bytes and is not written to output, so there is no information disclosure. Triggering a crash requires the allocation to border unmapped memory, which is unlikely with the normal allocator.  The FIPS modules are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34180",
                                "url": "https://ubuntu.com/security/CVE-2026-34180",
                                "cve_description": "Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms.  Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer.  More typically such ASN.1 elements would instead be truncated.  An integer truncation in OpenSSL's ASN.1 decoder causes the content length of an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the worst case the truncated length is treated as a request to scan the binary content for a terminating zero byte, possibly causing OpenSSL to read either less than or beyond the end of the allocated buffer.  Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or any other d2i_* decoding function are affected. OpenSSL's own command-line tools are not vulnerable, as data read through the BIO layer is checked before it reaches the affected code. The issue only affects 64-bit Unix and Unix-like platforms; 32-bit platforms and 64-bit Windows are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34181",
                                "url": "https://ubuntu.com/security/CVE-2026-34181",
                                "cve_description": "Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery.  Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability.  If a service accepting PKCS#12 files is using passwords for authenticating the received files, the attacker can create unencrypted PKCS#12 files that use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing them to craft a file that will be accepted with a 1 in 256 probability. That would then cause the service to accept a certificate and private key controlled by the attacker.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34182",
                                "url": "https://ubuntu.com/security/CVE-2026-34182",
                                "cve_description": "Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises.  Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message.  In one use case, an attacker may send a CMS message containing AuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL erroneously allows this selection, and attempts to decrypt and validate the message.  An on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData addressed to the victim can re-emit it with the recipientInfos set left byte-for-byte intact, so the victim's private key still unwraps the genuine CEK (the content-encryption key), but with the inner OID rewritten to AES-256-OFB (Output Feedback Mode, an unauthenticated keystream mode) and with an attacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the real CEK, never consults the MAC field, and CMS_decrypt() returns success.  If the application under attack responds to the attacker with any indicator showing success or failure of the decryption effort, it is possible for the attacker to use this as an oracle to obtain key equivalent functionality for the CEK used for the chosen recipient of the message.  In another use case, an attacker can reduce the tag length of the chosen AEAD cipher for a given AuthEnvelopedData container to be a single byte long, allowing an attacker to brute force CMS decryption, producing an integrity bypass for applications that trust CMS_decrypt() to reject modified content.  The FIPS modules are not affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-34183",
                                "url": "https://ubuntu.com/security/CVE-2026-34183",
                                "cve_description": "Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames.  Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service.  A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-35188",
                                "url": "https://ubuntu.com/security/CVE-2026-35188",
                                "cve_description": "Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path.  Impact summary: Successful exploitation allows an attacker to corrupt heap memory via a double-free, potentially leading to a Denial of Service or possibly an attacker controlled code execution or other undefined behavior.  If OCSP stapling is enabled and the TLS client connects to a malicious server, a crafted OCSP stapled response can trigger a double free in the TLS client when the stapled response is checked.  The OCSP stapling is not enabled by default. Reliable code execution through a double-free is technically complex and highly environment-dependent but the Denial of Service impact is straightforward to achieve, warranting Moderate severity.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42764",
                                "url": "https://ubuntu.com/security/CVE-2026-42764",
                                "cve_description": "Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled.  Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service.  If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token.  By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the default configuration not vulnerable to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with the SSL_new_listener() call, the address validation is disabled making the vulnerable code reachable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42765",
                                "url": "https://ubuntu.com/security/CVE-2026-42765",
                                "cve_description": "Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens.  This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verification. Both flags are disabled by default. For that reason, we have assigned Low severity to the issue.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42766",
                                "url": "https://ubuntu.com/security/CVE-2026-42766",
                                "cve_description": "Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as OPTIONAL in the ASN.1 specification and may therefore be absent in specially crafted inputs. During the password-based CMS decryption the OpenSSL CMS implementation dereferences this field without first checking whether it was present.  An attacker who supplies such a CMS message to an application performing password-based CMS decryption can trigger an application crash, leading to a Denial of Service.  Applications that process password-encrypted CMS messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42767",
                                "url": "https://ubuntu.com/security/CVE-2026-42767",
                                "cve_description": "Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42768",
                                "url": "https://ubuntu.com/security/CVE-2026-42768",
                                "cve_description": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output.  Impact summary: The Bleichenbacher-style attack allows an attacker to use the victim's vulnerable application as a way to decrypt or sign messages with the victim's private RSA key.  The attack is possible in 2 variants.  1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without providing the recipient certificate. In this case OpenSSL iterates over every KeyTransRecipientInfo (KTRI) without stopping at the first success.  An attacker who authors a message with two KTRI entries — the first one wrapping a real CEK under the victim's public key, the second with an arbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to get a valid PKCS#1 v1.5 padding if the error code of the application is available.  That is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an adaptive-chosen-ciphertext side channel from which the attacker decrypts any RSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under it.  2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with the recipient certificate, and the recipient is not found, a random key is substituted.  An attacker who authors a message and is able to compare both error code and the result of the decryption, can mount a Bleichenbacher oracle.  We are not aware of any applications that provide a remote attacker an opportunity to mount an attack described in these scenarios. We consider the existence of such application very unlikely, and for this reason this CVE has been evaluated as Low severity.  To avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the invoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described in draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit rejection was explicitly disabled.  The implicit rejection mechanism always returns a plaintext value, the symmetric key. This result is deterministic for the ciphertext and the private key.  The length of the decryption result can happen to match the length of the key of the symmetric cipher that was used for the content encryption. When a certificate is not provided, the last RecipientInfo producing a key that looks valid will be used. It may cause getting garbage content on decryption. As a proper way to deal with this a recipient certificate has to be provided to identify the particular RecipientInfo for decryption.  The FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as CMS and S/MIME processing happens outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42769",
                                "url": "https://ubuntu.com/security/CVE-2026-42769",
                                "cve_description": "Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level.  Impact Summary: The Registration Autority could replace the root CA certificate for the CMP clients with an arbitrary root CA certificate.  One of the parts of the Certificate Management Protocol (CMP), specified in RFC 9810, is Root Certification Authority (root CA) key Rollover, which is sent by the server in a message with type 'id-it-rootCaKeyUpdate'. As part of these messages, 'newWithOld' certificate, the new root CA certificate signed with the old root CA key, is provided, and verifying its signature is crucial for transferring the trust from the old CA key to the new one.  The 'id-it-rootCaKeyUpdate' messages are expected to be processed with OSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld' certificate.  A typo in the certificate chain building code led to adding an incorrect certificate ('newWithOld' instead of 'oldRoot') to the certificate chain, rendering the certificate verification process ineffectual (only the issuer name and the algorithm OIDs were verified by other parts of the verification code).  An attacker who already has credentials that satisfy the CMP message protection checks can generate a new key pair and use a crafted self-signed certificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP clients would accept as a new trust anchor.  Significant preconditions for the attack (having valid RA-level credentials) are the reason the issue was assigned Low severity.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42770",
                                "url": "https://ubuntu.com/security/CVE-2026-42770",
                                "cve_description": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership.  Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts.  When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared.  A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack).  The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42771",
                                "url": "https://ubuntu.com/security/CVE-2026-42771",
                                "cve_description": "Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen.  Impact summary: This out of bounds read will not directly exfiltrate the data read to the attacker so the most likely result is a crash and a Denial of Service.  An internal helper function called from X509_VERIFY_PARAM_[set|add]_email() used a wrong length when validating the local part of an email address. This could cause the 64 octet limit on the local part of an email address to be not enforced, or cause an out of bound read and potentially a crash.  The bug is reachable via S-MIME validation with a crafted From: address supplied in an email message that can potentially cause a crash.  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45445",
                                "url": "https://ubuntu.com/security/CVE-2026-45445",
                                "cve_description": "Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded.  Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality.  If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not on the plaintext or ciphertext, allowing universal forgery of arbitrary ciphertext from a single captured message.  OpenSSL provides two ways to drive a cipher: the documented streaming interface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level one-shot, EVP_Cipher(), whose documentation explicitly recommends against use by applications in favour of EVP_CipherUpdate() and EVP_CipherFinal_ex().  The OCB provider's streaming handler flushes the application-supplied IV into the OCB context before processing data; the one-shot handler did not.  Every call to EVP_Cipher() on an AES-OCB context therefore ran with the all-zero key-derived offset state left by cipher initialisation, regardless of the caller's IV.  If EVP_EncryptFinal_ex() is subsequently used to obtain the authentication tag, the deferred IV setup runs at that point and clears the running checksum that should have been accumulated over the plaintext.  The resulting tag is a function of (key, IV) only and verifies against any ciphertext produced under the same (key, IV) pair.  The OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a TLS cipher suite, and libssl does not call EVP_Cipher() in any case. Applications that drive AES-OCB through the documented streaming AEAD API (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only applications that combine the AES-OCB cipher with the EVP_Cipher() one-shot API are vulnerable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as AES-OCB is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45446",
                                "url": "https://ubuntu.com/security/CVE-2026-45446",
                                "cve_description": "Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages.  Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers.  AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not encrypted), and plaintext, and produces ciphertext plus a 16-byte tag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only if the tag is verified succesfully.  In OpenSSL's provider implementation of these ciphers, the expected tag is computed only when decryption function is invoked with non-empty data. If the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without invocation of the ciphertext update, which can happen when the received ciphertext length is zero, the tag is never recalculated and still holds its all-zeros value.  When AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty ciphertext, and all-zeros tag passes authentication under any key they do not know, single-shot. When AES-SIV is used, for mounting the attack it's necessary for the application to reuse the decryption context without resetting the key.  AES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since OpenSSL 3.2.  No protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support either AES-GCM-SIV or AES-SIV. To mount an attack, the applications must implement their own protocol and use the EVP interface. Also they must skip the ciphertext update when a message with an empty ciphertext arrives.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as these algorithms are not FIPS approved and the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45447",
                                "url": "https://ubuntu.com/security/CVE-2026-45447",
                                "cve_description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.  Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution.  When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition.  In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution.  Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-06-09 17:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Import 4.0.1",
                            "   - CVE-2026-7383 (\"Possible Heap Buffer Overflow in ASN.1 Multibyte String",
                            "     Conversion\")",
                            "   - CVE-2026-9076 (\"Out-of-Bounds Read in CMS Password-Based Decryption\")",
                            "   - CVE-2026-34180 (\"Heap Buffer Over-read in ASN.1 Content Parsing\")",
                            "   - CVE-2026-34181 (\"PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC",
                            "     Keys\")",
                            "   - CVE-2026-34182 (\"CMS AuthEnvelopedData Processing May Accept Forged",
                            "     Messages\")",
                            "   - CVE-2026-34183 (\"Unbounded Memory Growth in the QUIC PATH_CHALLENGE",
                            "     Handler\")",
                            "   - CVE-2026-35188 (\"Double-free When Checking OCSP Stapled Response\")",
                            "   - CVE-2026-42764 (\"NULL pointer dereference in QUIC server initial packet",
                            "     handling\")",
                            "   - CVE-2026-42765 (\"NULL Dereference in Certificate Verification with OCSP",
                            "     Checking\")",
                            "   - CVE-2026-42766 (\"Possible NULL Dereference in Password-Based CMS",
                            "     Decryption\")",
                            "   - CVE-2026-42767 (\"NULL Pointer Dereference in CRMF EncryptedValue",
                            "     Decryption\")",
                            "   - CVE-2026-42768 (\"Multi-RecipientInfo Bleichenbacher Oracle in",
                            "     CMS_decrypt() and PKCS7_decrypt()\")",
                            "   - CVE-2026-42769 (\"Trust-Anchor Substitution via cert/issuer Typo in CMP",
                            "     rootCaKeyUpdate\")",
                            "   - CVE-2026-42770 (\"FFC-DH Peer Validation Uses Attacker-Supplied q\")",
                            "   - CVE-2026-42771 (\"Possible Out of Bounds Read in",
                            "     X509_VERIFY_PARAM_set1_email()\")",
                            "   - CVE-2026-45445 (\"AES-OCB IV Ignored on EVP_Cipher() Path\")",
                            "   - CVE-2026-45446 (\"Incorrect Tag Processing for Empty Messages in",
                            "     AES-GCM-SIV and AES-SIV modes\")",
                            "   - CVE-2026-45447 (\"Heap Use-After-Free in OpenSSL PKCS7_verify()\")",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Sat, 13 Jun 2026 20:01:42 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-2673",
                                "url": "https://ubuntu.com/security/CVE-2026-2673",
                                "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-03-13 19:54:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28387",
                                "url": "https://ubuntu.com/security/CVE-2026-28387",
                                "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28388",
                                "url": "https://ubuntu.com/security/CVE-2026-28388",
                                "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28389",
                                "url": "https://ubuntu.com/security/CVE-2026-28389",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28390",
                                "url": "https://ubuntu.com/security/CVE-2026-28390",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31789",
                                "url": "https://ubuntu.com/security/CVE-2026-31789",
                                "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31790",
                                "url": "https://ubuntu.com/security/CVE-2026-31790",
                                "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Eric Berry ]",
                            "  * OpenSSL crashes in resolute when userspace entropy",
                            "    is enabled but fips provider is not installed (LP: #2147669)",
                            "",
                            "  [ Ravi Kant Sharma ]",
                            "  * Merge with Debian experimental (LP: #2153135). Remaining changes:",
                            "    - Use perl:native in the autopkgtest for installability on i386.",
                            "    - Symlink copyright/changelog.Debian.gz in libssl3* to libssl-dev/openssl",
                            "    - Disable LTO with which the codebase is generally incompatible",
                            "      (LP #2058017)",
                            "    - Default config reads crypto-config and /etc/ssl/openssl.cnf.d dropins",
                            "    - Don't enable or package anything FIPS (LP #2087955)",
                            "    - Match last filename for output in ecp_nistp521-ppc64.pl (LP #2137464)",
                            "    - Enable CPU jitter fluctuations",
                            "    - fips patches (debian/patches/fips):",
                            "      - crypto: Add kernel FIPS mode detection",
                            "      - crypto: Automatically use the FIPS provider...",
                            "      - apps/speed: Omit unavailable algorithms in FIPS mode",
                            "      - apps: pass -propquery arg to the libctx DRBG fetches",
                            "      - test: Ensure encoding runs with the correct context...",
                            "      - Add Ubuntu-specific defines to help FIPS certification (LP #2073991)",
                            "        + UBUNTU_OSSL_SELF_TEST_DESC_PCT_DH",
                            "        + UBUNTU_OSSL_PROV_FIPS_PARAM_UNAPPROVED_USAGE",
                            "      - Detect FIPS jitterentropy mode and load jitterentropy enabled FIPS",
                            "        provider",
                            "      - Fallback to default provider when FIPS provider is missing.",
                            "  * Refreshed patches",
                            "    - fips/apps-speed-Omit-unavailable-algorithms-in-FIPS-mode.patch",
                            "    - fips/crypto-Add-kernel-FIPS-mode-detection.patch",
                            "    - fips/crypto-add-userspace-fips-mode-detection.patch",
                            "    - fips/crypto-Automatically-use-the-FIPS-provider-when-the-kerne.patch",
                            "  * Dropped patches, merged upstream",
                            "    - CVE-2026-2673.patch",
                            "    - CVE-2026-28387.patch",
                            "    - CVE-2026-28388-1.patch",
                            "    - CVE-2026-28388-2.patch",
                            "    - CVE-2026-28389.patch",
                            "    - CVE-2026-28390.patch",
                            "    - CVE-2026-31789.patch",
                            "    - CVE-2026-31790-1.patch",
                            "    - CVE-2026-31790-2.patch",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2147669,
                            2153135
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Wed, 20 May 2026 12:14:25 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-2673",
                                "url": "https://ubuntu.com/security/CVE-2026-2673",
                                "cve_description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-03-13 19:54:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28387",
                                "url": "https://ubuntu.com/security/CVE-2026-28387",
                                "cve_description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28389",
                                "url": "https://ubuntu.com/security/CVE-2026-28389",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28390",
                                "url": "https://ubuntu.com/security/CVE-2026-28390",
                                "cve_description": "Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31789",
                                "url": "https://ubuntu.com/security/CVE-2026-31789",
                                "cve_description": "Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-31790",
                                "url": "https://ubuntu.com/security/CVE-2026-31790",
                                "cve_description": "Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28386",
                                "url": "https://ubuntu.com/security/CVE-2026-28386",
                                "cve_description": "Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output.  The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy.  Only x86-64 systems with AVX-512 and VAES instruction support are affected. Other architectures and systems without VAES support use different code paths that are not affected.  OpenSSL FIPS module in 3.6 version is affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-28388",
                                "url": "https://ubuntu.com/security/CVE-2026-28388",
                                "cve_description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-04-07 22:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Import 4.0.0",
                            "    - CVE-2026-2673 (\"OpenSSL TLS 1.3 server may choose unexpected key agreement",
                            "      group\") (Closes: #1130650).",
                            "    - CVE-2026-28387 (\"Potential use-after-free in DANE client code\")",
                            "    - CVE-2026-28389 (\"Possible NULL dereference when processing CMS",
                            "      KeyAgreeRecipientInfo\")",
                            "    - CVE-2026-28390 (\"Possible NULL dereference when processing CMS",
                            "      KeyTransportRecipient Info\")",
                            "    - CVE-2026-31789 (\"Heap buffer overflow in hexadecimal conversion\")",
                            "    - CVE-2026-31790 (\"Incorrect failure handling in RSA KEM RSASVE",
                            "      encapsulation\")",
                            "    - CVE-2026-28386 (\"Out-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512",
                            "      Support\")",
                            "    - CVE-2026-28388 (\"NULL Pointer Dereference When Processing a Delta CRL\")",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 16 Apr 2026 20:31:23 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 4.0.0-beta1",
                            "  * Add musl targets (Closes: #1131164).",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0~beta1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 26 Mar 2026 22:34:26 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 4.0.0-alpha1 (Closes: #1126531).",
                            "  * Update Standards-Version.",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.0~alpha1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Fri, 13 Mar 2026 18:16:34 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 12 Mar 2026 21:00:23 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2025-11187",
                                "url": "https://ubuntu.com/security/CVE-2025-11187",
                                "cve_description": "Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification.  Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations.  When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without validation. If the value of keylength exceeds the size of the fixed stack buffer used for the derived key (64 bytes), the key derivation will overflow the buffer. The overflow length is attacker-controlled. Also, if the salt parameter is not an OCTET STRING type this can lead to invalid or NULL pointer dereference.  Exploiting this issue requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For this reason the issue was assessed as Moderate severity.  The FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as PKCS#12 processing is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue.  OpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do not support PBMAC1 in PKCS#12.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-15467",
                                "url": "https://ubuntu.com/security/CVE-2025-15467",
                                "cve_description": "Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.  Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.  When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs.  Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.  OpenSSL 1.1.1 and 1.0.2 are not affected by this issue. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-15468",
                                "url": "https://ubuntu.com/security/CVE-2025-15468",
                                "cve_description": "Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.  Impact summary: A NULL pointer dereference leads to abnormal termination of the running process causing Denial of Service.  Some applications call SSL_CIPHER_find() from the client_hello_cb callback on the cipher ID received from the peer. If this is done with an SSL object implementing the QUIC protocol, NULL pointer dereference will happen if the examined cipher ID is unknown or unsupported.  As it is not very common to call this function in applications using the QUIC protocol and the worst outcome is Denial of Service, the issue was assessed as Low severity.  The vulnerable code was introduced in the 3.2 version with the addition of the QUIC protocol support.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the QUIC implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-15469",
                                "url": "https://ubuntu.com/security/CVE-2025-15469",
                                "cve_description": "Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error.  Impact summary: A user signing or verifying files larger than 16MB with one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire file is authenticated while trailing data beyond 16MB remains unauthenticated.  When the 'openssl dgst' command is used with algorithms that only support one-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input is buffered with a 16MB limit. If the input exceeds this limit, the tool silently truncates to the first 16MB and continues without signaling an error, contrary to what the documentation states. This creates an integrity gap where trailing bytes can be modified without detection if both signing and verification are performed using the same affected codepath.  The issue affects only the command-line tool behavior. Verifiers that process the full message using library APIs will reject the signature, so the risk primarily affects workflows that both sign and verify with the affected 'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and library users are unaffected.  The FIPS modules in 3.5 and 3.6 are not affected by this issue, as the command-line tools are outside the OpenSSL FIPS module boundary.  OpenSSL 3.5 and 3.6 are vulnerable to this issue.  OpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-66199",
                                "url": "https://ubuntu.com/security/CVE-2025-66199",
                                "cve_description": "Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.  Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work, potentially leading to service degradation or resource exhaustion (Denial of Service).  In affected configurations, the peer-supplied uncompressed certificate length from a CompressedCertificate message is used to grow a heap buffer prior to decompression. This length is not bounded by the max_cert_list setting, which otherwise constrains certificate message sizes. An attacker can exploit this to cause large per-connection allocations followed by handshake failure. No memory corruption or information disclosure occurs.  This issue only affects builds where TLS 1.3 certificate compression is compiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression algorithm (brotli, zlib, or zstd) is available, and where the compression extension is negotiated. Both clients receiving a server CompressedCertificate and servers in mutual TLS scenarios receiving a client CompressedCertificate are affected. Servers that do not request client certificates are not vulnerable to client-initiated attacks.  Users can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION to disable receiving compressed certificates.  The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the TLS implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-68160",
                                "url": "https://ubuntu.com/security/CVE-2025-68160",
                                "cve_description": "Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.  Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application.  The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIO_f_linebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69418",
                                "url": "https://ubuntu.com/security/CVE-2025-69418",
                                "cve_description": "Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69419",
                                "url": "https://ubuntu.com/security/CVE-2025-69419",
                                "cve_description": "Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.  Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service.  The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer.  The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16 source byte count as the destination buffer capacity to UTF8_putc(). For BMP code points above U+07FF, UTF-8 requires three bytes, but the forwarded capacity can be just two bytes. UTF8_putc() then returns -1, and this negative value is added to the output length without validation, causing the length to become negative. The subsequent trailing NUL byte is then written at a negative offset, causing write outside of heap allocated buffer. The vulnerability is reachable via the public PKCS12_get_friendlyname() API when parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a different code path that avoids this issue, PKCS12_get_friendlyname() directly invokes the vulnerable function. Exploitation requires an attacker to provide a malicious PKCS#12 file to be parsed by the application and the attacker can just trigger a one zero byte write before the allocated buffer. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69420",
                                "url": "https://ubuntu.com/security/CVE-2025-69420",
                                "cve_description": "Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.  Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the TimeStamp Response implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-69421",
                                "url": "https://ubuntu.com/security/CVE-2025-69421",
                                "cve_description": "Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.  Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files.  The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure.  Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-22795",
                                "url": "https://ubuntu.com/security/CVE-2026-22795",
                                "cve_description": "Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.  Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service.  A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read.  The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.  OpenSSL 1.0.2 is not affected by this issue. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-22796",
                                "url": "https://ubuntu.com/security/CVE-2026-22796",
                                "cve_description": "Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.  Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.  The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash.  Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity.  The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary.  OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-01-27 16:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Import 3.6.1",
                            "   - CVE-2025-11187 (Improper validation of PBMAC1 parameters in PKCS#12 MAC",
                            "     verification)",
                            "   - CVE-2025-15467 (Stack buffer overflow in CMS AuthEnvelopedData parsing)",
                            "   - CVE-2025-15468 (NULL dereference in SSL_CIPHER_find() function on unknown",
                            "     cipher ID)",
                            "   - CVE-2025-15469 (\"openssl dgst\" one-shot codepath silently truncates inputs",
                            "     >16MB)",
                            "   - CVE-2025-66199 (TLS 1.3 CompressedCertificate excessive memory allocation)",
                            "   - CVE-2025-68160 (Heap out-of-bounds write in BIO_f_linebuffer on short",
                            "     writes)",
                            "   - CVE-2025-69418 (Unauthenticated/unencrypted trailing bytes with low-level",
                            "     OCB function calls)",
                            "   - CVE-2025-69419 (Out of bounds write in PKCS12_get_friendlyname() UTF-8",
                            "     conversion)",
                            "   - CVE-2025-69420 (Missing ASN1_TYPE validation in TS_RESP_verify_response()",
                            "     function)",
                            "   - CVE-2025-69421 (NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex",
                            "     function)",
                            "   - CVE-2026-22795 (Missing ASN1_TYPE validation in PKCS#12 parsing)",
                            "   - CVE-2026-22796 (ASN1_TYPE Type Confusion in the",
                            "   - PKCS7_digest_from_attributes() function)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Tue, 27 Jan 2026 21:32:02 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Apply fix for upstream issue #28902",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Fri, 26 Dec 2025 17:01:03 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 3.6.0",
                            "  * Stop shipping c_rehash. It bas been long replaced by \"openssl rehash\"",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Fri, 03 Oct 2025 17:40:10 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 3.6.0-beta1",
                            "  * Drop pic & Bsymbolic patches. This shouldn't be needed anymore.",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0~~beta1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Thu, 18 Sep 2025 21:36:20 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import 3.6.0-alpha1",
                            ""
                        ],
                        "package": "openssl",
                        "version": "3.6.0~~alpha1-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sebastian Andrzej Siewior <sebastian@breakpoint.cc>",
                        "date": "Sat, 06 Sep 2025 20:21:28 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "passwd",
                "from_version": {
                    "source_package_name": "shadow",
                    "source_package_version": "1:4.17.4-2ubuntu3",
                    "version": "1:4.17.4-2ubuntu3"
                },
                "to_version": {
                    "source_package_name": "shadow",
                    "source_package_version": "1:4.19.3-2ubuntu1",
                    "version": "1:4.19.3-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153355
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153355). Remaining changes:",
                            "    - d/p/: Enable private home directories by default",
                            "    - debian/{source_shadow.py,login.defs.install}: Add apport hook",
                            "    - d/p/1010_extrausers.patch: add libnss-extrausers support to passwd/usermod",
                            "    - d/p/1011_extrausers_toggle.patch: extrausers support for useradd/groupadd",
                            "    - d/p/1012_extrausers_chfn.patch: --extrausers support for chfn tool",
                            "    - d/p/1013_extrausers_deluser.patch: --extrausers support for userdel",
                            "    - d/p/1014_extrausers_delgroup.patch: --extrausers support for groupdel",
                            "    - d/p/1016_extrausers_gpasswd.patch: extrausers support for gpasswd",
                            "    - d/t/{control,numeric-username}: test that fully numeric names are rejected",
                            "    - d/t/smoke: Extend for extrausers support",
                            "    - Add some cursory tests for the extrausers features",
                            "    - d/p/lp2063200: fix useradd group validation with extrausers (LP 2063200)",
                            "    - d/p/: disallow pure numeric user and group names (LP 2076898)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.3-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153355
                        ],
                        "author": "Nadzeya Hutsko <nadzeya.hutsko@canonical.com>",
                        "date": "Mon, 01 Jun 2026 15:59:52 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix getsubids parsing of /etc/subgid.",
                            "    Thanks to Aurelien Jarno (Closes: #1132509)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 02 Apr 2026 19:44:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.19.3",
                            "  * Update Upstream signing keys",
                            "  * d/watch: enable pgpmode=auto",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Mon, 23 Feb 2026 09:54:37 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.19.2",
                            "  * Refresh patches, drop upstream-applied chkhask patches",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Sun, 25 Jan 2026 14:18:54 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Import upstream patches to fix hash check (Closes: #1124835)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Thu, 08 Jan 2026 00:01:00 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * chpasswd: Disable broken hash check, bug #1124835",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Wed, 07 Jan 2026 11:11:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Disable logind integration on !linux",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Tue, 06 Jan 2026 02:38:50 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.19.0",
                            "  * Refresh patches",
                            "  * Drop upstream-applied patches",
                            "  * Add new build-dependency on libsystemd-dev [linux-any]",
                            "  * login.defs: Remove commented out USERDEL_CMD",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.19.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Tue, 06 Jan 2026 01:16:37 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Frans Spiesschaert ]",
                            "  * Update Dutch translations (Closes: #1115411)",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.18.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Wed, 17 Sep 2025 00:46:09 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 4.18.0",
                            "  * Refresh patches",
                            "  * d/copyright: update for upstream-deleted code",
                            "  * Drop newly unnecessay Build-Depends: bison",
                            ""
                        ],
                        "package": "shadow",
                        "version": "1:4.18.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Chris Hofstaedtler <zeha@debian.org>",
                        "date": "Tue, 26 Aug 2025 23:05:38 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "pci.ids",
                "from_version": {
                    "source_package_name": "pci.ids",
                    "source_package_version": "0.0~2026.06.16-1",
                    "version": "0.0~2026.06.16-1"
                },
                "to_version": {
                    "source_package_name": "pci.ids",
                    "source_package_version": "0.0~2026.07.21-1",
                    "version": "0.0~2026.07.21-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "pci.ids",
                        "version": "0.0~2026.07.21-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guillem Jover <guillem@debian.org>",
                        "date": "Sun, 26 Jul 2026 03:55:02 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "pci.ids",
                        "version": "0.0~2026.07.06-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guillem Jover <guillem@debian.org>",
                        "date": "Mon, 06 Jul 2026 23:43:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "pci.ids",
                        "version": "0.0~2026.07.03-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Guillem Jover <guillem@debian.org>",
                        "date": "Sat, 04 Jul 2026 01:51:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "perl-base",
                "from_version": {
                    "source_package_name": "perl",
                    "source_package_version": "5.40.1-8ubuntu1",
                    "version": "5.40.1-8ubuntu1"
                },
                "to_version": {
                    "source_package_name": "perl",
                    "source_package_version": "5.42.3-1",
                    "version": "5.42.3-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-7017",
                        "url": "https://ubuntu.com/security/CVE-2026-7017",
                        "cve_description": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-9538",
                        "url": "https://ubuntu.com/security/CVE-2026-9538",
                        "cve_description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42496",
                        "url": "https://ubuntu.com/security/CVE-2026-42496",
                        "cve_description": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42497",
                        "url": "https://ubuntu.com/security/CVE-2026-42497",
                        "cve_description": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-12087",
                        "url": "https://ubuntu.com/security/CVE-2026-12087",
                        "cve_description": "Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-15 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-13221",
                        "url": "https://ubuntu.com/security/CVE-2026-13221",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15649",
                        "url": "https://ubuntu.com/security/CVE-2025-15649",
                        "cve_description": "IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-7010",
                        "url": "https://ubuntu.com/security/CVE-2026-7010",
                        "cve_description": "HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 22:22:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-8376",
                        "url": "https://ubuntu.com/security/CVE-2026-8376",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 00:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48959",
                        "url": "https://ubuntu.com/security/CVE-2026-48959",
                        "cve_description": "IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48961",
                        "url": "https://ubuntu.com/security/CVE-2026-48961",
                        "cve_description": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48962",
                        "url": "https://ubuntu.com/security/CVE-2026-48962",
                        "cve_description": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-57432",
                        "url": "https://ubuntu.com/security/CVE-2026-57432",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-57433",
                        "url": "https://ubuntu.com/security/CVE-2026-57433",
                        "cve_description": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-7017",
                                "url": "https://ubuntu.com/security/CVE-2026-7017",
                                "cve_description": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-9538",
                                "url": "https://ubuntu.com/security/CVE-2026-9538",
                                "cve_description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42496",
                                "url": "https://ubuntu.com/security/CVE-2026-42496",
                                "cve_description": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42497",
                                "url": "https://ubuntu.com/security/CVE-2026-42497",
                                "cve_description": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-12087",
                                "url": "https://ubuntu.com/security/CVE-2026-12087",
                                "cve_description": "Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-15 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-13221",
                                "url": "https://ubuntu.com/security/CVE-2026-13221",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.3.",
                            "  * [SECURITY] includes various upstream fixes:",
                            "    + CVE-2026-7017: HTTP::Tiny credential forwarding on redirects.",
                            "        (Closes: #1141639)",
                            "    + CVE-2026-9538: Archive::Tar memory exhaustion.",
                            "        (Closes: #1138861)",
                            "    + CVE-2026-42496: Archive::Tar symlink extraction.",
                            "        (Closes: #1138860)",
                            "    + CVE-2026-42497: Archive::Tar hardlink extraction.",
                            "        (Closes: #1138859)",
                            "    + CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read.",
                            "        (Closes: #1140152)",
                            "    + CVE-2026-13221: silently incorrect regular expression matches.",
                            "        (Closes: #1142037)",
                            "  * Refresh cross support files for all architectures.",
                            "    + also update the architecture lists in d/cross/README",
                            "  * Disable salsa-ci.yml as nobody currently cares about the results.",
                            "  * Update debian/copyright based on DFSG team review.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Mon, 17 Aug 2026 22:59:18 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add 5.42.2 to debian/released-versions.",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Wed, 22 Jul 2026 22:26:36 +0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2025-15649",
                                "url": "https://ubuntu.com/security/CVE-2025-15649",
                                "cve_description": "IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-7010",
                                "url": "https://ubuntu.com/security/CVE-2026-7010",
                                "cve_description": "HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 22:22:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-8376",
                                "url": "https://ubuntu.com/security/CVE-2026-8376",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 00:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48959",
                                "url": "https://ubuntu.com/security/CVE-2026-48959",
                                "cve_description": "IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48961",
                                "url": "https://ubuntu.com/security/CVE-2026-48961",
                                "cve_description": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48962",
                                "url": "https://ubuntu.com/security/CVE-2026-48962",
                                "cve_description": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-57432",
                                "url": "https://ubuntu.com/security/CVE-2026-57432",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-57433",
                                "url": "https://ubuntu.com/security/CVE-2026-57433",
                                "cve_description": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * [SECURITY] backport various fixes from upstream:",
                            "    + CVE-2025-15649: header parsing in IO::Uncompress::Unzip.",
                            "        (Closes: #1138863)",
                            "    + CVE-2026-7010:  CRLF-validation in HTTP::Tiny.",
                            "        (Closes: #1138858)",
                            "    + CVE-2026-8376:  Buffer overflow in Perl_study_chunk.",
                            "        (Closes: #1137345)",
                            "    + CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip.",
                            "        (Closes: #1138856)",
                            "    + CVE-2026-48961: crash in zipdetails.",
                            "        (Closes: #1138855)",
                            "    + CVE-2026-48962: code execution in IO-Compress via output globs.",
                            "        (Closes: #1138854)",
                            "    + CVE-2026-57432: out of bound heap reads in pack() and unpack().",
                            "        (Closes: #1138905)",
                            "    + CVE-2026-57433: signed integer overflow in Storable.",
                            "        (Closes: #1138906)",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sat, 06 Jun 2026 18:02:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.2.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Fri, 24 Apr 2026 22:39:00 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Helmut Grohne ]",
                            "  * Add libcrypt-dev to libperl-dev's Depends. (Closes: #1102978)",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Mon, 17 Nov 2025 21:03:18 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Reinstate Provides: libtest2-suite-perl. (See #1080359)",
                            "  * Refresh cross build support files for most architectures.",
                            "  * Update lintian overrides for 5.42.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sun, 24 Aug 2025 11:55:37 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.0.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sat, 16 Aug 2025 18:44:35 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "procps",
                "from_version": {
                    "source_package_name": "procps",
                    "source_package_version": "2:4.0.4-9ubuntu1",
                    "version": "2:4.0.4-9ubuntu1"
                },
                "to_version": {
                    "source_package_name": "procps",
                    "source_package_version": "2:4.0.6-3ubuntu1",
                    "version": "2:4.0.6-3ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153347
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable (LP: #2153347). Remaining changes:",
                            "    - debian/sysctl.d:",
                            "      + 55-console-messages.conf: stop low-level kernel messages on console.",
                            "      + 55-kernel-hardening.conf: add the kptr_restrict setting",
                            "      + 55-ipv6-privacy.conf: add a file to sysctl.d to apply the defaults",
                            "        for IPv6 privacy extensions for interfaces. (LP #176125, #841353)",
                            "      + 55-magic-sysrq.conf: Disable most magic sysrq by default, allowing",
                            "        critical sync, remount, reboot functions. (LP #194676, #1025467)",
                            "      + 55-network-security.conf: enable rp_filter.",
                            "      + 55-ptrace.conf: describe new PTRACE setting.",
                            "      + 55-zeropage.conf: safe mmap_min_addr value for graceful fall-back",
                            "        for armhf and arm64.",
                            "      + 55-qemu.conf.s390x for qemu.",
                            "      + 55-bufferbloat.conf: set default qdisc to fq_codel",
                            "      + 55-map-count.conf: Increase vm.max_map_count to 1048576",
                            "    - d/t/stack-limit: add basic autopkgtest to validate limits",
                            "    - d/tests: Add basic autopkgtest to validate sysctl-defaults (LP #1962038)",
                            "    - d/t/stack-limit: call 'pgrep systemd' instead of 'pgrep bash'",
                            "      The autopkgtest currently fails because there is no bash session, and",
                            "      pgrep returns non-zero. Use systemd because that will match for pid1.",
                            "    - d/tests: make sysctl-defaults test comprehensive",
                            "    - d/t/test_sysctl_defaults.py: skip test if sysctl key invalid",
                            "    - d/t/control: show all sysctl.d configs before test",
                            "    - d/t/control: make sysctl-defaults test Restrictions: isolation-machine",
                            "      (LP #2115346)",
                            "  * Dropped changes (applied upstream):",
                            "    - d/p/ignore_eaccess.patch: ignore EACCES when opening sysctl file (LP #1903351)",
                            "    - d/p/ignore_erofs.patch: ignore EROFS when opening sysctl file (LP #1419554)",
                            "    - d/p/0010-testsuite-ps-etime-ELAPSED-doesn-t-match-full-format.patch:",
                            "      Fix test failure (FTBFS) in testsuite/ps.test/ps_output.exp due to",
                            "      invalid regex match inside LXD containers.",
                            "    - d/p/lp2120904-openat.patch: utilize file descriptors and openat (LP #2120904)",
                            "    - d/p/lp2120904-nullpointer.patch: fix a race when 'status' is unavailable",
                            "      in /proc/<pid> resulting in NULL pointer (LP #2120904)",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153347
                        ],
                        "author": "Carter Hawthorne <carter.hawthorne@canonical.com>",
                        "date": "Thu, 13 Aug 2026 15:27:14 -0700"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Break & Replace manpages-zh Closes: #1141435",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Tue, 28 Jul 2026 21:10:17 +1000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Mattias Ellert ]",
                            "  * Fix compilation and installation on GNU/Hurd (Closes: #1138217)",
                            "",
                            "  [ Craig Small ]",
                            "  * Only include linux-sysctl-defaults on Linux systems Closes: #1129174",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Tue, 30 Jun 2026 19:23:38 +1000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            "    library and w: Don't check for sd_booted Closes: #1108549",
                            "    pgrep: Match on process ID Closes: #612146",
                            "    pgrep: Add --quiet option",
                            "    pmap: add -k option to print raw names from kernel",
                            "    ps.1: cols and collums alias width option Closes: #926361",
                            "    ps.1: Add format equivalents Closes: #925437",
                            "    slabtop: Increase column width Closes: #959375",
                            "    sysctl: Use options after --system  Closes: #978989",
                            "    w: Add terminal mode to show all terminal sessions",
                            "    w: Use process TTY as backup for user TTY Closes: #1080335",
                            "    w: Use correct return value for sd_get_sessions Closes: #1068904",
                            "    watch: Add --follow option Closes: #469156",
                            "    watch: 256 color support",
                            "    watch.1: Warn about -d permanent option Closes: #883638",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Thu, 29 Jan 2026 21:34:30 +1100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            "    library: Recover from meminfo seek using LXC Closes: #1072831",
                            "    ps.1: Update man page to standards Closes: #1081801",
                            "    snice: Minor fix for help screen Closes: #1086441",
                            "    sysctl: --all skips stat_refresh Closes: #978688",
                            "    vmstat.8: si/so are changed by --unit Closes: #1061944",
                            "    w.1: Note utmp is for non-systemd Closes: #1080333",
                            "    w.1: Update man page to standards Closes: #1077367",
                            "    w: Don't segfault with -s option",
                            "    watch.1: --chgexit only works for visible changes Closes: #729569",
                            "  * Remove ps_not_path_max patch as upstream has it",
                            "  * Remove makefile_w_link_systemd as its fixed upstream",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.5-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Thu, 19 Dec 2024 13:09:01 +1100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3",
                "from_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.3-0ubuntu2",
                    "version": "3.14.3-0ubuntu2"
                },
                "to_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.7-3",
                    "version": "3.14.7-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Remove a missed Python 3.13 dependency.",
                            "  * Update README.Debian.",
                            "",
                            "  [ Simon McVittie ]",
                            "  * policy: Expand the section about package names. (Closes: #791635)",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Thu, 27 Aug 2026 11:09:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Bump to version 3.14.7.",
                            "  * Remove Python 3.13 as a supported version.",
                            "  * Remove references to IronPython and Jython in the package descriptions.",
                            "  * Bump standards version.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 26 Aug 2026 16:45:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            "  * Bump to version 3.14.6.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Sat, 27 Jun 2026 09:14:35 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-apport",
                "from_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.35.0-0ubuntu1",
                    "version": "2.35.0-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.36.0-0ubuntu1",
                    "version": "2.36.0-0ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-77113",
                        "url": "https://ubuntu.com/security/CVE-2026-77113",
                        "cve_description": "",
                        "cve_priority": "n/a",
                        "cve_public_date": ""
                    }
                ],
                "launchpad_bugs_fixed": [
                    2161697,
                    2163744,
                    2109979,
                    2156405,
                    2161888,
                    2161957
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-77113",
                                "url": "https://ubuntu.com/security/CVE-2026-77113",
                                "cve_description": "",
                                "cve_priority": "n/a",
                                "cve_public_date": ""
                            }
                        ],
                        "log": [
                            "",
                            "  [ Benjamin Drung ]",
                            "  * New upstream release.",
                            "    - SECURITY UPDATE: path traversal during report extraction (LP: #2161697)",
                            "      + problem_report: validate key names in ProblemReport.load",
                            "      + CVE-2026-77113",
                            "    - apport_python_hook: support dbus-broker (LP: #2163744)",
                            "    - Fix partial writes for coredumps larger than 2 GiB (LP: #2109979)",
                            "  * autopkgtest: remove unneeded dirmngr dependency",
                            "  * Drop patches applied upstream and refresh remaining patches",
                            "  * python3-apport: Tighten python3-problem-report dependency to >= 2.36",
                            "  * Let python3-problem-report break apport << 2.36 (for apport-unpack)",
                            "",
                            "  [ Kat Kuo ]",
                            "  * oem-getlogs: Remove Ubuntu Report call and get DCD directly (LP: #2156405)",
                            ""
                        ],
                        "package": "apport",
                        "version": "2.36.0-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161697,
                            2163744,
                            2109979,
                            2156405
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 16:48:31 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * test: wait for child processes to complete execve() (LP: #2161888)",
                            "  * test: add riscv64 entry to archmap (see LP #2159030)",
                            "  * test: increase waiting timeout from 5/10 to 30 seconds (see LP #2159030)",
                            "  * rewrite check_files_md5 in pure Python (LP: #2161957)",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "apport",
                        "version": "2.35.0-0ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161888,
                            2161957
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 14:06:05 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-bcrypt",
                "from_version": {
                    "source_package_name": "python-bcrypt",
                    "source_package_version": "5.0.0-3build1",
                    "version": "5.0.0-3build1"
                },
                "to_version": {
                    "source_package_name": "python-bcrypt",
                    "source_package_version": "5.0.0-6",
                    "version": "5.0.0-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Accept bcrypt 0.19 (closes: #1143364).",
                            "  * Drop \"Rules-Requires-Root: no\", default as of dpkg-dev 1.22.13.",
                            "  * Drop \"Priority: optional\", default as of dpkg-dev 1.22.13.",
                            "  * Standards-Version: 4.7.4.",
                            ""
                        ],
                        "package": "python-bcrypt",
                        "version": "5.0.0-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:31:18 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "",
                            "  [ Peter Michael Green ]",
                            "  * Adjust packaging for getrandom 0.4 (closes: #1130519).",
                            ""
                        ],
                        "package": "python-bcrypt",
                        "version": "5.0.0-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Tue, 31 Mar 2026 16:31:49 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Accept pyo3 0.28.",
                            ""
                        ],
                        "package": "python-bcrypt",
                        "version": "5.0.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jelmer Vernooĳ <jelmer@debian.org>",
                        "date": "Tue, 17 Mar 2026 10:01:51 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-certifi",
                "from_version": {
                    "source_package_name": "python-certifi",
                    "source_package_version": "2026.6.17+ds-1",
                    "version": "2026.6.17+ds-1"
                },
                "to_version": {
                    "source_package_name": "python-certifi",
                    "source_package_version": "2026.7.22+ds-1",
                    "version": "2026.7.22+ds-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Install certifi/tests/test_certify.py as non-executable.",
                            "  * Enable autopkgtest-pkg-pybuild.",
                            ""
                        ],
                        "package": "python-certifi",
                        "version": "2026.7.22+ds-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 26 Jul 2026 14:46:16 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-cffi-backend",
                "from_version": {
                    "source_package_name": "python-cffi",
                    "source_package_version": "2.0.0-3build1",
                    "version": "2.0.0-3build1"
                },
                "to_version": {
                    "source_package_name": "python-cffi",
                    "source_package_version": "2.1.1-1",
                    "version": "2.1.1-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team Upload",
                            "  * New upstream version 2.1.1",
                            "  * Drop build-dep on python3-py (Closes: #1121670)",
                            "  * Refresh bundled-wheel-and-setuptools.patch",
                            "  * Drop pycparser-3.patch: applied upstream",
                            "  * Add debian/salsa-ci.yml",
                            "  * Bump Standards-Version to 4.7.4, drop Priority: tag",
                            "  * Drop duplicate dependency on dh-python",
                            ""
                        ],
                        "package": "python-cffi",
                        "version": "2.1.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Mon, 17 Aug 2026 14:07:44 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-click",
                "from_version": {
                    "source_package_name": "python-click",
                    "source_package_version": "8.2.0+0.really.8.1.8-1build1",
                    "version": "8.2.0+0.really.8.1.8-1build1"
                },
                "to_version": {
                    "source_package_name": "python-click",
                    "source_package_version": "8.3.3-2",
                    "version": "8.3.3-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Sort help args to make them reproducible",
                            ""
                        ],
                        "package": "python-click",
                        "version": "8.3.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jochen Sprickerhof <jspricke@debian.org>",
                        "date": "Tue, 28 Jul 2026 22:03:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream version 8.3.3.",
                            "    - Add new build-dependency python3-myst-parser.",
                            "    - Refresh patches with new upstream version.",
                            ""
                        ],
                        "package": "python-click",
                        "version": "8.3.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sérgio de Almeida Cipriano Júnior <cipriano@debian.org>",
                        "date": "Sun, 19 Jul 2026 11:16:47 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Don't parameterize tests using non-Collection iterables (closes:",
                            "    #1140873).",
                            "  * Drop \"Priority: optional\", default as of dpkg-dev 1.22.13.",
                            "  * Standards-Version: 4.7.4.",
                            ""
                        ],
                        "package": "python-click",
                        "version": "8.2.0+0.really.8.1.8-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Wed, 01 Jul 2026 10:21:30 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-cryptography",
                "from_version": {
                    "source_package_name": "python-cryptography",
                    "source_package_version": "46.0.5-1ubuntu2",
                    "version": "46.0.5-1ubuntu2"
                },
                "to_version": {
                    "source_package_name": "python-cryptography",
                    "source_package_version": "49.0.0-2ubuntu1",
                    "version": "49.0.0-2ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-34073",
                        "url": "https://ubuntu.com/security/CVE-2026-34073",
                        "cve_description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the \"peer name\" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-31 03:15:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-69247",
                        "url": "https://ubuntu.com/security/CVE-2026-69247",
                        "cve_description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-03 22:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2164143,
                    2155078
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-34073",
                                "url": "https://ubuntu.com/security/CVE-2026-34073",
                                "cve_description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the \"peer name\" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-31 03:15:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164143). Remaining changes:",
                            "    - Vendor rust for Ubuntu main",
                            "      - Adjust dependencies version for vendored build",
                            "      - Add a recipe in d/rules to generate the vendor tarball",
                            "      - Add vendored crates",
                            "      - Add debian/README.source",
                            "    * Drop patches, merged upstream",
                            "      - d/p/CVE-2026-34073.patch",
                            "      - d/p/CVE-2026-34073.patch",
                            "  * Fixes FTBFS with OpenSSL 4 (LP: #2155078)",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "49.0.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164143,
                            2155078
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Tue, 18 Aug 2026 19:30:20 +0000"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-69247",
                                "url": "https://ubuntu.com/security/CVE-2026-69247",
                                "cve_description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-03 22:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport the upstream fix for CVE-2026-69247 (Closes: #1143596).",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "49.0.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Wed, 05 Aug 2026 01:32:33 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "49.0.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Wed, 15 Jul 2026 14:39:03 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to experimental.",
                            "  * New upstream version.",
                            "  * Support building against pyo3 0.29.",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "49.0.0-1~exp1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Wed, 24 Jun 2026 00:27:00 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "    + Fix building with OpenSSL 4 (Closes: #1139232).",
                            "  * Add overlooked B-D: librust-base64-0.22-dev.",
                            "  * Update B-D from librust-asn1-0.23-dev to librust-asn1-0.24-dev.",
                            "  * Switch to debhelper compat level 14.",
                            "  * Add X-Style: black and reformat.",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "47.0.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Wed, 24 Jun 2026 00:01:10 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Bump Standards-Version to 4.7.4.",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "46.0.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Thu, 09 Apr 2026 12:18:03 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "46.0.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Fri, 27 Mar 2026 10:49:47 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Support building against pyo3 0.28.",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "46.0.5-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jelmer Vernooĳ <jelmer@debian.org>",
                        "date": "Tue, 17 Mar 2026 11:38:26 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "46.0.5-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 16:01:32 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-distro-info",
                "from_version": {
                    "source_package_name": "distro-info",
                    "source_package_version": "1.15",
                    "version": "1.15"
                },
                "to_version": {
                    "source_package_name": "distro-info",
                    "source_package_version": "1.17",
                    "version": "1.17"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1012459
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * test: replace experimental by rc-buggy for distro-info-data 0.73",
                            ""
                        ],
                        "package": "distro-info",
                        "version": "1.17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Sun, 19 Jul 2026 16:17:03 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Format Python code with black 26.3",
                            "  * Perl library:",
                            "    - fix exporting convert_date",
                            "    - add get_all_series() function (Closes: #1141228, LP: #1012459)",
                            "  * Add autopkgtest for testing libdistro-info-perl",
                            "  * Bump Standards-Version to 4.7.4",
                            "  * Use pybuild-plugin-pyproject to build the Python module",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "distro-info",
                        "version": "1.16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            1012459
                        ],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Fri, 17 Jul 2026 00:35:41 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-distupgrade",
                "from_version": {
                    "source_package_name": "ubuntu-release-upgrader",
                    "source_package_version": "1:26.10.3",
                    "version": "1:26.10.3"
                },
                "to_version": {
                    "source_package_name": "ubuntu-release-upgrader",
                    "source_package_version": "1:26.10.8",
                    "version": "1:26.10.8"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158525,
                    2166785,
                    2154822,
                    2154822
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * DistUpgradeQuirks: Add check for mysql_native_password use (LP: #2158525).",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.8",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158525
                        ],
                        "author": "Lena Voytek <lena.voytek@canonical.com>",
                        "date": "Tue, 08 Sep 2026 13:38:26 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * tests: test against recent releases",
                            "  * Use `sqv` instead of `gpgv` (LP: #2166785)",
                            "  * Run pre-build.sh to update templates and version",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.7",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166785
                        ],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 08 Sep 2026 17:18:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fixes for LP: #2154822:",
                            "    - DistUpgradeController: Fix rewriteMirrorUri to strip the country mirror",
                            "      on archs served by ports.u.c",
                            "    - test_sources_list: Disable test_apt_cacher_and_apt_bittorent on archs",
                            "      served by ports.u.c (rewriteMirrorUri now correctly causes changes that",
                            "      differ by architecture, and the test will only pass on archs served by",
                            "      archive.u.c)",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.6",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154822
                        ],
                        "author": "Dave Jones <dave.jones@canonical.com>",
                        "date": "Tue, 08 Sep 2026 12:09:21 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * DistUpgradeController: Split entries when the architecture(s) of the",
                            "    entry now reside on a different host, e.g. 26.04 where arm64 migrated",
                            "    from ports.u.c to archive.u.c (LP: #2154822)",
                            "  * DistUpgradeQuirks: minor changes to fix autopkgtest errors",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154822
                        ],
                        "author": "Dave Jones <dave.jones@canonical.com>",
                        "date": "Tue, 01 Sep 2026 20:33:49 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Florent 'Skia' Jacquet ]",
                            "  * test_pycodestyle: give a more verbose output upon failure",
                            "  * Add .launchpad.yaml to run at least some basic checks directly from git",
                            "  * Fix Stonking version number in announcements",
                            "",
                            "  [ kkuo ]",
                            "  * Remove unnecessary Ubuntu Insights consent migration logic",
                            "",
                            "  [ Oliver Reiche ]",
                            "  * DistUpgrade: fix release announcements for stonking",
                            "",
                            "  [ Alessandro Astone ]",
                            "  * Add quirk for installing dbus-broker",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Mon, 31 Aug 2026 12:01:33 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-gi",
                "from_version": {
                    "source_package_name": "pygobject",
                    "source_package_version": "3.56.2-1",
                    "version": "3.56.2-1"
                },
                "to_version": {
                    "source_package_name": "pygobject",
                    "source_package_version": "3.57.1-1",
                    "version": "3.57.1-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release (Closes: #1143867)",
                            ""
                        ],
                        "package": "pygobject",
                        "version": "3.57.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Sat, 15 Aug 2026 08:31:19 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Build with debhelper compat 14",
                            "  * Release to unstable",
                            ""
                        ],
                        "package": "pygobject",
                        "version": "3.57.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Thu, 06 Aug 2026 14:52:03 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * d/p: Drop patch applied upstream",
                            ""
                        ],
                        "package": "pygobject",
                        "version": "3.57.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Wed, 29 Jul 2026 13:03:40 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "  * d/p: Backport fix for big-endian test failure.",
                            "    This change stops trying to salvage broken GIR definitions with a",
                            "    workaround that was incorrect on big-endian architectures, and instead",
                            "    raises a python exception if that were to occur. (Closes: #1139446)",
                            ""
                        ],
                        "package": "pygobject",
                        "version": "3.56.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Wed, 29 Jul 2026 12:00:59 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * Update Standards Version to 4.7.4",
                            ""
                        ],
                        "package": "pygobject",
                        "version": "3.56.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Fri, 08 May 2026 16:58:00 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-httplib2",
                "from_version": {
                    "source_package_name": "python-httplib2",
                    "source_package_version": "0.31.2-2",
                    "version": "0.31.2-2"
                },
                "to_version": {
                    "source_package_name": "python-httplib2",
                    "source_package_version": "0.32.0-1",
                    "version": "0.32.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream release.",
                            "  * Use pytest-forked (closes: #1141010).",
                            "  * Unset pybuild's proxy environment variables; in this case, those just",
                            "    serve to confuse the test suite.",
                            ""
                        ],
                        "package": "python-httplib2",
                        "version": "0.32.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Wed, 01 Jul 2026 11:15:11 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-idna",
                "from_version": {
                    "source_package_name": "python-idna",
                    "source_package_version": "3.11-1",
                    "version": "3.11-1"
                },
                "to_version": {
                    "source_package_name": "python-idna",
                    "source_package_version": "3.18-1",
                    "version": "3.18-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * d/watch: Convert to version 5",
                            "  * New upstream version 3.18",
                            "  * d/control: Increase Standards-Version to 4.7.4",
                            ""
                        ],
                        "package": "python-idna",
                        "version": "3.18-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Carsten Schoenert <c.schoenert@t-online.de>",
                        "date": "Mon, 29 Jun 2026 14:41:21 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-jinja2",
                "from_version": {
                    "source_package_name": "jinja2",
                    "source_package_version": "3.1.6-2",
                    "version": "3.1.6-2"
                },
                "to_version": {
                    "source_package_name": "jinja2",
                    "source_package_version": "3.1.6-3",
                    "version": "3.1.6-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Test !nodoc & !nocheck profiles with Salsa CI",
                            "  * d/rules: guard call to \"make docs\" in a if-block",
                            "  * Mark python3-pallets-sphinx-themes as <!nodoc>",
                            "  * Update standards version to 4.7.4, no changes needed.",
                            "  * Use dh-sequence-* build dependencies instead of dh --with: sphinxdoc.",
                            "  * Add debian/upstream/metadata",
                            ""
                        ],
                        "package": "jinja2",
                        "version": "3.1.6-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Wed, 24 Jun 2026 10:54:19 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-jsonpatch",
                "from_version": {
                    "source_package_name": "python-json-patch",
                    "source_package_version": "1.32-6",
                    "version": "1.32-6"
                },
                "to_version": {
                    "source_package_name": "python-json-patch",
                    "source_package_version": "1.33-2",
                    "version": "1.33-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Uploading to unstable.",
                            ""
                        ],
                        "package": "python-json-patch",
                        "version": "1.33-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Thomas Goirand <zigo@debian.org>",
                        "date": "Thu, 26 Mar 2026 11:59:43 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "python-json-patch",
                        "version": "1.33-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Thomas Goirand <zigo@debian.org>",
                        "date": "Thu, 26 Feb 2026 13:32:02 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-lazr.restfulclient",
                "from_version": {
                    "source_package_name": "lazr.restfulclient",
                    "source_package_version": "0.14.6-3build1",
                    "version": "0.14.6-3build1"
                },
                "to_version": {
                    "source_package_name": "lazr.restfulclient",
                    "source_package_version": "4.0.0-1",
                    "version": "4.0.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * d/watch: Switch to PyPI.",
                            "  * New upstream release:",
                            "    - Replace pkg_resources namespace with a PEP 420 native namespace",
                            "      (closes: #1083460).",
                            "  * Drop \"Rules-Requires-Root: no\", default as of dpkg-dev 1.22.13.",
                            "  * Drop \"Priority: optional\", default as of dpkg-dev 1.22.13.",
                            "  * Standards-Version: 4.7.4.",
                            ""
                        ],
                        "package": "lazr.restfulclient",
                        "version": "4.0.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 02 Aug 2026 17:16:15 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-lazr.uri",
                "from_version": {
                    "source_package_name": "lazr.uri",
                    "source_package_version": "1.0.6-7build1",
                    "version": "1.0.6-7build1"
                },
                "to_version": {
                    "source_package_name": "lazr.uri",
                    "source_package_version": "4.0.0-1",
                    "version": "4.0.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * d/upstream/signing-key.asc: Add Finn Gärtner's key.",
                            "  * New upstream release:",
                            "    - Replace pkg_resources namespace with a PEP 420 native namespace",
                            "      (closes: #1083461).",
                            "  * Drop test dependency on python3-setuptools.",
                            ""
                        ],
                        "package": "lazr.uri",
                        "version": "4.0.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 02 Aug 2026 16:59:29 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Apply multi-arch hints.",
                            "  * Make DPT as Maintainer per new Team policy",
                            "  * Drop \"Rules-Requires-Root: no\": it is the default now",
                            "  * Add debian/salsa-ci.yml",
                            "  * Bump Standards-Version to 4.7.4, drop Priority: optional",
                            "  * Rewrite d/watch in v5 format",
                            "  * Use dh-sequence-python3",
                            "  * Mark python3-pytest as <!nocheck>",
                            ""
                        ],
                        "package": "lazr.uri",
                        "version": "1.0.6-8",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sat, 01 Aug 2026 20:20:53 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-markupsafe",
                "from_version": {
                    "source_package_name": "markupsafe",
                    "source_package_version": "3.0.3-1build1",
                    "version": "3.0.3-1build1"
                },
                "to_version": {
                    "source_package_name": "markupsafe",
                    "source_package_version": "3.0.3-2",
                    "version": "3.0.3-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "  * d/copyright: Use machine-readable format",
                            ""
                        ],
                        "package": "markupsafe",
                        "version": "3.0.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Germann <bage@debian.org>",
                        "date": "Mon, 03 Aug 2026 23:47:43 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-minimal",
                "from_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.3-0ubuntu2",
                    "version": "3.14.3-0ubuntu2"
                },
                "to_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.7-3",
                    "version": "3.14.7-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Remove a missed Python 3.13 dependency.",
                            "  * Update README.Debian.",
                            "",
                            "  [ Simon McVittie ]",
                            "  * policy: Expand the section about package names. (Closes: #791635)",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Thu, 27 Aug 2026 11:09:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Bump to version 3.14.7.",
                            "  * Remove Python 3.13 as a supported version.",
                            "  * Remove references to IronPython and Jython in the package descriptions.",
                            "  * Bump standards version.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 26 Aug 2026 16:45:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            "  * Bump to version 3.14.6.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Sat, 27 Jun 2026 09:14:35 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-netplan",
                "from_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.1-1ubuntu1",
                    "version": "1.2.1-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "netplan.io",
                    "source_package_version": "1.2.2-1",
                    "version": "1.2.2-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153219,
                    2145061,
                    2147446,
                    2071747,
                    2139598,
                    2138802
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153219). Remaining changes:",
                            "    - Skip test_link_offloading to allow for a green baseline (LP 2126938)",
                            "      + d/p/lp-2126938-skip-test-link-offloading.patch",
                            "  * Dropped:",
                            "    - d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "      3.14 by handling BlockingIOError in addition to TypeError (LP 2138802)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "      execute udev rules before starting sriov apply service (LP 2139598)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "      (LP 2071747)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "      Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "      units. (LP 2145061)",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "      networkd to apply dhcp labels to addresses (LP 2147446).",
                            "      [Included in Debian 1.2.1-1]",
                            "    - d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "      permissions for files not managed by netplan in integration tests.",
                            "      [Included in Debian 1.2.1-1]",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2.1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153219
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Thu, 21 May 2026 16:24:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2145061-wpa-supplicant-requires-netplan-configure.patch: add",
                            "    Requires=/After= dependency on netplan-configure.service to wpa supplicant",
                            "    units. (LP: #2145061)",
                            "  * d/p/lp2147446-state-label-DHCPv4-using-networkd-ConfigSource.patch: use",
                            "    networkd to apply dhcp labels to addresses (LP: #2147446).",
                            "  * d/p/tests-only-consider-netplan-generated-files.patch: skip checking file",
                            "    permissions for files not managed by netplan in integration tests.",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu5",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2145061,
                            2147446
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Wed, 08 Apr 2026 16:47:32 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp2071747-unresolvable-network-cycle.patch: fix network ordering cycle",
                            "    (LP: #2071747)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2071747
                        ],
                        "author": "Guilherme Puida Moreira <guilherme.moreira@canonical.com>",
                        "date": "Fri, 20 Mar 2026 16:09:27 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/patches/lp2139598-execute-udev-rules-before-sriov-apply-service.patch:",
                            "    execute udev rules before starting sriov apply service (LP: #2139598)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2139598
                        ],
                        "author": "Robert Malz <robert.malz@canonical.com>",
                        "date": "Tue, 03 Mar 2026 12:44:43 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2138802-BlockingIOError-py314.patch: fix \"netplan try\" with python",
                            "    3.14 by handling BlockingIOError in addition to TypeError (LP: #2138802)",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2138802
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Fri, 20 Feb 2026 11:25:14 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip test_link_offloading to allow for a green baseline (LP: 2126938)",
                            "    - d/p/lp-2126938-skip-test-link-offloading.patch",
                            ""
                        ],
                        "package": "netplan.io",
                        "version": "1.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Lukas Märdian <slyon@ubuntu.com>",
                        "date": "Tue, 13 Jan 2026 17:58:24 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "python3-problem-report",
                "from_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.35.0-0ubuntu1",
                    "version": "2.35.0-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "apport",
                    "source_package_version": "2.36.0-0ubuntu1",
                    "version": "2.36.0-0ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-77113",
                        "url": "https://ubuntu.com/security/CVE-2026-77113",
                        "cve_description": "",
                        "cve_priority": "n/a",
                        "cve_public_date": ""
                    }
                ],
                "launchpad_bugs_fixed": [
                    2161697,
                    2163744,
                    2109979,
                    2156405,
                    2161888,
                    2161957
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-77113",
                                "url": "https://ubuntu.com/security/CVE-2026-77113",
                                "cve_description": "",
                                "cve_priority": "n/a",
                                "cve_public_date": ""
                            }
                        ],
                        "log": [
                            "",
                            "  [ Benjamin Drung ]",
                            "  * New upstream release.",
                            "    - SECURITY UPDATE: path traversal during report extraction (LP: #2161697)",
                            "      + problem_report: validate key names in ProblemReport.load",
                            "      + CVE-2026-77113",
                            "    - apport_python_hook: support dbus-broker (LP: #2163744)",
                            "    - Fix partial writes for coredumps larger than 2 GiB (LP: #2109979)",
                            "  * autopkgtest: remove unneeded dirmngr dependency",
                            "  * Drop patches applied upstream and refresh remaining patches",
                            "  * python3-apport: Tighten python3-problem-report dependency to >= 2.36",
                            "  * Let python3-problem-report break apport << 2.36 (for apport-unpack)",
                            "",
                            "  [ Kat Kuo ]",
                            "  * oem-getlogs: Remove Ubuntu Report call and get DCD directly (LP: #2156405)",
                            ""
                        ],
                        "package": "apport",
                        "version": "2.36.0-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161697,
                            2163744,
                            2109979,
                            2156405
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 16:48:31 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * test: wait for child processes to complete execve() (LP: #2161888)",
                            "  * test: add riscv64 entry to archmap (see LP #2159030)",
                            "  * test: increase waiting timeout from 5/10 to 30 seconds (see LP #2159030)",
                            "  * rewrite check_files_md5 in pure Python (LP: #2161957)",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "apport",
                        "version": "2.35.0-0ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161888,
                            2161957
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 14:06:05 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-requests",
                "from_version": {
                    "source_package_name": "requests",
                    "source_package_version": "2.32.5+dfsg-1ubuntu1",
                    "version": "2.32.5+dfsg-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "requests",
                    "source_package_version": "2.34.2-1",
                    "version": "2.34.2-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2024-47081",
                        "url": "https://ubuntu.com/security/CVE-2024-47081",
                        "cve_description": "Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.",
                        "cve_priority": "medium",
                        "cve_public_date": "2025-06-09 18:15:00 UTC"
                    },
                    {
                        "cve": "CVE-2024-47081",
                        "url": "https://ubuntu.com/security/CVE-2024-47081",
                        "cve_description": "Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.",
                        "cve_priority": "medium",
                        "cve_public_date": "2025-06-09 18:15:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2130145,
                    2085279,
                    1975541,
                    1975541
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2024-47081",
                                "url": "https://ubuntu.com/security/CVE-2024-47081",
                                "cve_description": "Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.",
                                "cve_priority": "medium",
                                "cve_public_date": "2025-06-09 18:15:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2130145). Remaining changes:",
                            "    - d/p/remove-charset-normalizer-dependency.patch: Remove charset-normalizer",
                            "      as a build dependency (LP #1975541).",
                            "    Drop changes applied in upstream:",
                            "    - debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc",
                            "      lookup instead of netloc",
                            "  * d/p/remove-charset-normalizer-dependency.patch: refresh the patch",
                            ""
                        ],
                        "package": "requests",
                        "version": "2.32.5+dfsg-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2130145
                        ],
                        "author": "Nadzeya Hutsko <nadzeya.hutsko@canonical.com>",
                        "date": "Thu, 06 Nov 2025 12:18:28 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2024-47081",
                                "url": "https://ubuntu.com/security/CVE-2024-47081",
                                "cve_description": "Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.",
                                "cve_priority": "medium",
                                "cve_public_date": "2025-06-09 18:15:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Information Leak",
                            "    - debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc",
                            "      lookup instead of netloc",
                            "    - CVE-2024-47081",
                            ""
                        ],
                        "package": "requests",
                        "version": "2.32.3+dfsg-5ubuntu2",
                        "urgency": "medium",
                        "distributions": "questing",
                        "launchpad_bugs_fixed": [],
                        "author": "Bruce Cable <bruce.cable@canonical.com>",
                        "date": "Wed, 11 Jun 2025 13:28:01 +1000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2085279). Remaining changes:",
                            "    - d/p/remove-charset-normalizer-dependency.patch: Remove charset-normalizer",
                            "      as a build dependency (LP #1975541).",
                            ""
                        ],
                        "package": "requests",
                        "version": "2.32.3+dfsg-5ubuntu1",
                        "urgency": "medium",
                        "distributions": "questing",
                        "launchpad_bugs_fixed": [
                            2085279
                        ],
                        "author": "Lena Voytek <lena.voytek@canonical.com>",
                        "date": "Thu, 22 May 2025 16:50:10 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian Unstable. Remaining changes:",
                            "    - d/p/remove-charset-normalizer-dependency.patch: Remove charset-normalizer",
                            "      as a build dependency (LP: #1975541).",
                            ""
                        ],
                        "package": "requests",
                        "version": "2.32.3+dfsg-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "plucky",
                        "launchpad_bugs_fixed": [
                            1975541
                        ],
                        "author": "Simon Quigley <tsimonq2@ubuntu.com>",
                        "date": "Tue, 18 Feb 2025 01:55:57 -0600"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/remove-charset-normalizer-dependency.patch: Remove charset-normalizer",
                            "    as a build dependency of requests (LP: #1975541)",
                            ""
                        ],
                        "package": "requests",
                        "version": "2.32.3+dfsg-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "oracular",
                        "launchpad_bugs_fixed": [
                            1975541
                        ],
                        "author": "Lena Voytek <lena.voytek@canonical.com>",
                        "date": "Wed, 26 Jun 2024 08:56:02 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "python3-urllib3",
                "from_version": {
                    "source_package_name": "python-urllib3",
                    "source_package_version": "2.6.3-2ubuntu1",
                    "version": "2.6.3-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "python-urllib3",
                    "source_package_version": "2.7.0-3",
                    "version": "2.7.0-3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-44432",
                        "url": "https://ubuntu.com/security/CVE-2026-44432",
                        "cve_description": "urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-13 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-9375",
                        "url": "https://ubuntu.com/security/CVE-2026-9375",
                        "cve_description": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-19 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Replace deprecated pyOpenSSL X509.get_subject and Context.set_passwd_cb",
                            "    methods (closes: #1142214).",
                            ""
                        ],
                        "package": "python-urllib3",
                        "version": "2.7.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Tue, 21 Jul 2026 10:09:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Salsa CI: test nocheck profile",
                            "  * Mark python3-h2 build-dep as <!nocheck>",
                            "  * Rewrite d/watch in v5 format",
                            "  * Update standards version to 4.7.4, no changes needed.",
                            "  * Set upstream metadata fields: Documentation.",
                            ""
                        ],
                        "package": "python-urllib3",
                        "version": "2.7.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sun, 12 Jul 2026 17:23:46 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-44432",
                                "url": "https://ubuntu.com/security/CVE-2026-44432",
                                "cve_description": "urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-13 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-9375",
                                "url": "https://ubuntu.com/security/CVE-2026-9375",
                                "cve_description": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-19 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream release:",
                            "    - CVE-2026-44432, CVE-2026-9375: Decompression-bomb safeguards bypassed",
                            "      in parts of the streaming API (closes: #1136654, #1140427).",
                            "    - GHSA-qccp-gfcp-xxvc: Sensitive headers forwarded across origins in",
                            "      proxied low-level redirects.",
                            "  * Don't parameterize tests using non-Collection iterables",
                            "    (Closes: #1140932).",
                            ""
                        ],
                        "package": "python-urllib3",
                        "version": "2.7.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 28 Jun 2026 17:48:21 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3.14",
                "from_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.6-1",
                    "version": "3.14.6-1"
                },
                "to_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.7-4ubuntu1",
                    "version": "3.14.7-4ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert the module-install-* autopkg tests to run with setuptools v78.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:51:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-13.",
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Re-enable the module-install-* autopkgtests, updated for setuptools 80.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:30:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-05.",
                            "  * Disable the module-install-* autopkg tests for now.",
                            "  * Update symbols file.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sat, 05 Sep 2026 07:55:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-01.",
                            "    - Reworks the test_typing stack test. Closes: #1146095.",
                            "  * Apply the OpenSSL 4.0 patches from the 3.15 branch. Closes: #1137595.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 11:47:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Python 3.14.7 release.",
                            "  * Drop the the min-pyrepl patch, handled by an upstream backport.",
                            "  * Refresh patches.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 11 Aug 2026 10:48:35 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3.14-minimal",
                "from_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.6-1",
                    "version": "3.14.6-1"
                },
                "to_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.7-4ubuntu1",
                    "version": "3.14.7-4ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert the module-install-* autopkg tests to run with setuptools v78.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:51:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-13.",
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Re-enable the module-install-* autopkgtests, updated for setuptools 80.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:30:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-05.",
                            "  * Disable the module-install-* autopkg tests for now.",
                            "  * Update symbols file.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sat, 05 Sep 2026 07:55:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-01.",
                            "    - Reworks the test_typing stack test. Closes: #1146095.",
                            "  * Apply the OpenSSL 4.0 patches from the 3.15 branch. Closes: #1137595.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 11:47:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Python 3.14.7 release.",
                            "  * Drop the the min-pyrepl patch, handled by an upstream backport.",
                            "  * Refresh patches.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 11 Aug 2026 10:48:35 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "rust-coreutils",
                "from_version": {
                    "source_package_name": "rust-coreutils",
                    "source_package_version": "0.8.0-0ubuntu4",
                    "version": "0.8.0-0ubuntu4"
                },
                "to_version": {
                    "source_package_name": "rust-coreutils",
                    "source_package_version": "0.11.0-2ubuntu2",
                    "version": "0.11.0-2ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2151166,
                    2166225,
                    2152801,
                    2116290,
                    2130465,
                    2165041,
                    2164777,
                    2152801,
                    2164777,
                    2130465,
                    2165041,
                    2163175,
                    2134860,
                    2159679,
                    2132368,
                    2137580,
                    2142900,
                    2150342,
                    2157011,
                    2157342,
                    2116290,
                    2158691,
                    2160614,
                    2153168,
                    2154338,
                    2154042,
                    2152801,
                    2146819,
                    2146818,
                    2155763,
                    2115782
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/patches/fix-install-d-eexist-race.patch: Fix an issue where parallel",
                            "    invocations of install -D would result in an EEXIST race (LP: #2151166)",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.11.0-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2151166
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Mon, 14 Sep 2026 17:15:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable. Remaining changes: (LP: #2166225)",
                            "    - Install hardlinks: Rename rust-coreutils.links to",
                            "      rust-coreutils.hardlinks.",
                            "    - Remove Build-Depends on lld and use the default linker because lld is",
                            "      unavailable on some partial architectures such as i386.",
                            "    - d/rules: Add the multiarch library path needed when linking systemd",
                            "      support (LP: #2152801).",
                            "    - d/rules: Use Ubuntu's dh-cargo-vendored-sources helper and skip known",
                            "      failing tests.",
                            "    - d/control: Regenerate XS-Vendored-Sources-Rust for Ubuntu.",
                            "    - d/p/Tweak-release-build-profile.patch: Balance binary size and debug",
                            "      information.",
                            "    - d/p/dd-ensure-full-writes.patch: Handle partial writes to slow pipes.",
                            "    - d/p/rust-vendor/glibc-2.42.patch: Support the glibc 2.42 speed_t change.",
                            "    - d/p/rustix-use-libc-backend.patch: Route rustix syscalls through libc.",
                            "    - d/p/require-utility-to-be-invoked-at-matching-path.patch: Preserve",
                            "      pathname-based AppArmor policy semantics.",
                            "    - d/p/df-statfs-fallback.patch: Retain the direct statfs fallback when",
                            "      mount table paths are inaccessible (LP: #2116290).",
                            "    - d/p/cp-stop-resolving-cwd.patch: Avoid resolving cwd for absolute",
                            "      recursive copies (LP: #2130465).",
                            "    - Remove Debian's fix-ppc64el-baudrate.diff, which fails on Launchpad's",
                            "      ppc64el builders.",
                            "    - Fix Lintian warnings.",
                            "  * Drop Changes:",
                            "    - Install libstdbuf.so: adopted by Debian in 0.11.0-1.",
                            "    - Enable feat_systemd_logind and add libsystemd-dev: adopted by Debian in",
                            "      0.11.0-1; the Ubuntu multiarch linker-path adjustment remains.",
                            "    - d/p/remove-workspace-members.patch: adopted by Debian in 0.11.0-1.",
                            "    - d/p/build-stty.patch: no longer needed by the 0.11 Unix feature set.",
                            "    - d/p/cp-fix-symlink-target-permissions.patch: fixed upstream",
                            "      (LP: #2165041).",
                            "    - d/p/cp-fix-umask-permission-denied.patch: fixed upstream",
                            "      (LP: #2164777).",
                            "    - The 0.10 vendored-crate refresh: superseded by Debian's 0.11 refresh.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.11.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166225,
                            2152801,
                            2116290,
                            2130465,
                            2165041,
                            2164777
                        ],
                        "author": "Varun Varma <varun.varma@canonical.com>",
                        "date": "Mon, 07 Sep 2026 21:33:10 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Enable the upstream \"feat_diagnostics\" feature: errors are rendered",
                            "    against the argument list with a caret when stderr is a terminal.",
                            "    --no-default-features, so it has to be requested explicitly.",
                            "    https://uutils.org/blog/2026-08-error-diagnostics/",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.11.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Tue, 01 Sep 2026 22:43:12 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Update the l10n component tarball to 0.11.0.",
                            "  * d/p/fix-locale-path.patch: refreshed. Upstream now installs the shared",
                            "    error locales (src/uucore/locales/errors); install them under",
                            "    /usr/share/coreutils/locales/uucore/errors like the rest.",
                            "  * d/p/use-l10n-translations-in-makefile.patch: refreshed.",
                            "  * Build the checksum utilities against the system OpenSSL: enable the",
                            "    upstream \"openssl\" feature so cksum, md5sum and the sha*sum family use",
                            "    libcrypto instead of the pure-Rust digests, with OPENSSL_NO_VENDOR=1 so",
                            "    openssl-sys links Debian's shared libcrypto rather than building the",
                            "    vendored openssl-src copy. Build-Depends on libssl-dev and pkgconf.",
                            "  * Build with profile-guided optimization on amd64 and arm64: the",
                            "    instrumented binary is built with the package's own build command, then",
                            "    upstream's util/build-pgo.sh runs the training workloads and merges the",
                            "    profile, which the real build consumes through -Cprofile-use.",
                            "    d/p/pgo-use-prebuilt-binary.patch adds the --instrumented-binary option",
                            "    the script needs for that; using its own step 1 instead would train a",
                            "    binary built with a different feature set, whose profile -Cprofile-use",
                            "    then silently ignores. Restricted to those two",
                            "    arches because training has to run the instrumented binary and roughly",
                            "    doubles the build time (s390x already flirts with the buildd timeout,",
                            "    the 32-bit arches OOM). Disable with DEB_BUILD_OPTIONS=nopgo.",
                            "    Build-Depends on llvm [amd64 arm64].",
                            "  * Update the vendored crates.",
                            "  * Drop the Cargo.toml.orig cargo-vendor-filterer leaves in every vendored",
                            "    crate, and delete them in the 'vendor' target from now on: cargo never",
                            "    reads them and lintian reports them as debian-adds-patch-failure-file.",
                            "    Drops the override that used to hide the tag.",
                            "  * Blank the .cargo-checksum.json of every vendored crate, not just the",
                            "    ones matching the old sed: cargo-vendor-filterer now emits a \"$comment\"",
                            "    key, which the line-anchored regexp skipped. Left as it was,",
                            "    minimal-lexical failed to build because its checksum list mentions a",
                            "    .gitmodules that dpkg-source strips from the .debian.tar.",
                            "  * d/p/remove-workspace-members.patch: drop the workspace members array",
                            "    so dh-cargo stops walking the Cargo.toml of every crate in",
                            "    debian/rust-vendor/ (Ubuntu)",
                            "  * Re-enable stdbuf, disabled since 0.0.30-2: set LIBSTDBUF_DIR and",
                            "    ship /usr/libexec/rust-coreutils/libstdbuf.so instead of shipping a",
                            "    stdbuf link to a binary that did not implement it (Ubuntu)",
                            "  * Build with --features feat_systemd_logind so who, users, uptime and",
                            "    pinky read sessions from logind rather than an empty utmp; Build-",
                            "    Depends on libsystemd-dev (Ubuntu, LP: #2152801)",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.11.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2152801
                        ],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Tue, 01 Sep 2026 10:54:51 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon Johnsson ]",
                            "  * d/p/cp-fix-umask-permission-denied.patch: Fix an issue where cp would fail",
                            "    with \"Permission denied\" if umask masked the owner's write permission",
                            "    (LP: #2164777).",
                            "",
                            "  [ Varun Varma ]",
                            "  * d/p/cp-stop-resolving-cwd.patch: cp: avoid resolving cwd",
                            "    for absolute recursive copies (LP: #2130465).",
                            "  * Fix Lintian warnings.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.10.0-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164777,
                            2130465
                        ],
                        "author": "Varun Varma <varun.varma@canonical.com>",
                        "date": "Tue, 01 Sep 2026 12:04:54 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/cp-fix-symlink-target-permissions.patch: Fix an issue where cp",
                            "    would alter the permissions of the source file, such as stripping the",
                            "    setuid bit (LP: #2165041)",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.10.0-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165041
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Wed, 26 Aug 2026 16:29:49 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon Johnsson ]",
                            "  * Merge with Debian unstable. Remaining changes: (LP: #2163175)",
                            "    - Install libstdbuf.so: Modify d/rules to export LIBSTDBUF_DIR as to not",
                            "      skip stdbuf, fix libstdbuf.so permissions, and install it in",
                            "      rust-coreutils.install.",
                            "    - Install hardlinks: Rename rust-coreutils.links to",
                            "      rust-coreutils.hardlinks.",
                            "    - Enable feat_systemd_logind: This allows commands such as who and pinky",
                            "      to work correctly. Introduces libsystemd-dev as a dependency.",
                            "    - Remove Build-Depends on lld: Debian added it as the preferred linker,",
                            "      but some partial architectures like i386 may be missing it.",
                            "    - d/rules: Fix vendored sources field creation. Debian does not have",
                            "      access to dh-cargo-vendored-sources so it uses a script instead.",
                            "      Change it to use dh-cargo-vendored-sources on Ubuntu instead.",
                            "    - d/rules: Skip failing tests.",
                            "    - Add patches:",
                            "      + build-stty",
                            "      + dd-ensure-full-writes",
                            "      + require-utility-to-be-invoked-at-matching-path",
                            "      + Tweak-release-build-profile",
                            "      + rust-vendor/glibc-2.42",
                            "      + rustix-use-libc-backend",
                            "    - Remove upstream patches:",
                            "      + fix-ppc64el-baudrate.diff: Launchpad's builders instead fails on",
                            "        ppc64le for this patch, the original source code is correct.",
                            "    - Update vendored rust crates",
                            "    - debian/control: Update XS-Vendored-Sources-Rust field",
                            "  * Drop changes:",
                            "    - Remove patches fixed upstream:",
                            "      + cp-respect-composite-flag",
                            "      + fix-cp-parents",
                            "      + fix-incomplete-locale-bundles",
                            "      + fix-locale-path: Debian adopted this patch.",
                            "  * New changes:",
                            "    - debian/patches/remove-workspace-members.patch: Remove workspace member",
                            "      array to prevent dh-cargo bypassing workspace-exclude.patch. Otherwise",
                            "      vendored dependencies would still think that they're part of the",
                            "      workspace.",
                            "  * Fixes:",
                            "    - File ownership changes when a file is mv'ed by root to a different file",
                            "      system (LP: #2134860)",
                            "    - Failing to build images: mv resolv.conf.tmp",
                            "      /build/chroot/etc/resolv.conf mv: File exists (os error 17)",
                            "      (LP: #2159679)",
                            "    - unaligned plus in \"ls -l\" output (LP: #2132368)",
                            "    - git-buildpackage ftbfs on resolute-proposed due to rust coreutils",
                            "      (LP: #2137580)",
                            "    - env: signal flags do not understand RTMIN+n notation (LP: #2142900)",
                            "    - date: width prefix in %N format specifier is ignored",
                            "      ( %3N, %6N always output full 9 nanosecond digits) (LP: #2150342)",
                            "    - changes in behaviour of cp in coreutils-from-uutils break test case in",
                            "      util-linux (LP: #2157011)",
                            "    - systemd: TEST-45-TIMEDATE is flaky with rust coreutils (LP: #2157342)",
                            "",
                            "  [ Varun Varma ]",
                            "  * debian/patches/df-statfs-fallback.patch: Add a fallback to statfs if the",
                            "    mount path could not be found normally (LP: #2116290).",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.10.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163175,
                            2134860,
                            2159679,
                            2132368,
                            2137580,
                            2142900,
                            2150342,
                            2157011,
                            2157342,
                            2116290
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Tue, 11 Aug 2026 18:06:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Rework the source package to match the layout used by Ubuntu, so that",
                            "    merging Debian into Ubuntu no longer means undoing our repack:",
                            "    - Drop debian/repack.sh: the orig tarball is now the pristine GitHub tag.",
                            "    - d/watch: new, fetching the upstream tag plus the translations from",
                            "      uutils/coreutils-l10n as an l10n component tarball (unpacked in l10n/).",
                            "      Written in the version=4 syntax because devscripts in Debian does not",
                            "      support the newer \"Version: 5\" templates yet.",
                            "    - The vendored crates move out of the orig tarball into",
                            "      debian/rust-vendor/, generated by the new \"debian/rules vendor\" target",
                            "      with cargo-vendor-filterer (tier 2, *-*-linux-gnu* only). Vendor-only",
                            "      patches now have their own quilt series, debian/patches/rust-vendor/,",
                            "      applied by dh_quilt_patch; Build-Depends on quilt accordingly.",
                            "    - d/control: add the XS-Vendored-Sources-Rust field.",
                            "    - d/README.source: document the whole workflow.",
                            "  * debian/patches:",
                            "    - Drop use-vendor.diff, handled by \"cargo prepare-debian\" now.",
                            "    - Drop disable-utmp-classic.diff: utmp-classic is an OpenBSD-only target",
                            "      dependency, so it is never built on Linux; only its (unused) vendored",
                            "      copy remains. Ubuntu dropped the patch for the same reason.",
                            "    - Replace fix-locale-path.diff by Ubuntu's fix-locale-path.patch and add",
                            "      their use-l10n-translations-in-makefile.patch, the translations being",
                            "      installed from l10n/ instead of src/uu/*/locales/.",
                            "    - New workspace-exclude.patch, to keep debian/rust-vendor out of the",
                            "      cargo workspace.",
                            "    - Rebase the remaining patches on 0.10.0 and refresh the whole series",
                            "      with standard -p1 headers.",
                            "  * Ship debian/tldr.zip (English pages only): the pristine tarball does not",
                            "    carry the tldr archive that improve-man.diff turns into the EXAMPLES",
                            "    section of the manpages, and the build has no network access.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.10.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Thu, 06 Aug 2026 00:20:00 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Use the debian/changelog date (via SOURCE_DATE_EPOCH) for the",
                            "    generated manpage date instead of the current build date, so the",
                            "    package builds reproducibly. New patch reproducible-man-date.diff.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Thu, 04 Jun 2026 11:12:51 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon Johnsson ]",
                            "  * Remove lld as dependency as it is not available on i386:",
                            "    - d/control: Remove Build-Depends lld",
                            "    - d/rules: Change RUSTFLAGS to omit lld",
                            "  * debian/patches:",
                            "    - cp-respect-composite-flag: Cherry-pick fix from upstream for issue",
                            "      where the -a flag is not considered recursive due to flag stripping",
                            "      (LP: #2158691)",
                            "",
                            "  [ Varun Varma ]",
                            "  * debian/patches:",
                            "    - rustix-use-libc-backend: Switch rustix backend to libc to solve",
                            "      the error where tools that rely on LD_PRELOAD have altered",
                            "      behaviour with the default rustix backend (LP: #2160614).",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158691,
                            2160614
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Tue, 14 Jul 2026 17:15:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable. Remaining changes: (LP: #2153168)",
                            "    - Install libstdbuf.so",
                            "    - Install hardlinks",
                            "    - Refresh upstream patches",
                            "    - Use direct GitHub tarball instead of debian/repack.sh",
                            "    - d/rules:",
                            "      + Add vendoring targets",
                            "      + Build verbosely",
                            "      + Skip failing tests",
                            "    - d/watch: add watch file",
                            "    - d/patches:",
                            "      + Tweak-release-build-profile.patch",
                            "      + workspace-exclude.patch",
                            "      + build-stty.patch",
                            "      + require-utility-to-be-invoked-at-matching-path.patch",
                            "      + glibc-2.42.patch",
                            "      + dd-ensure-full-writes.patch",
                            "      + use-l10n-translations-in-makefile.patch",
                            "      + fix-locale-path.patch",
                            "      + fix-incomplete-locale-bundles.patch",
                            "    - d/control: update XS-Vendored-Sources-Rust field",
                            "    - vendor: update vendored deps",
                            "    - l10n/: update translations",
                            "  * Fixes:",
                            "    - xattrs break ls formatting (LP: #2154338)",
                            "    - ls: files are not sorted in alphabetical order when using",
                            "      --group-directories-first or if LC_ALL is unset (LP: #2154042)",
                            "  * Drop changes:",
                            "    - d/p/tee-fix-input-with-sleep.patch: The underlying issue was fixed",
                            "      upstream, so drop the patch.",
                            "  * New changes:",
                            "    - Enable feat_systemd_logind to fix who not showing output",
                            "      (LP: #2152801, LP: #2146819, LP: #2146818)",
                            "      + d/control: Add libsystemd-dev as a dependency.",
                            "      + d/rules: Link systemd and add feat_systemd_logind to CARGOFLAGS.",
                            "    - d/p/fix-cp-parents.patch: Cherry-pick fix from upstream for cp --parents",
                            "      bug resulting in build failures (LP: #2155763)",
                            "    - Remove unnecessary upstream patches:",
                            "      + disable-utmp-classic.diff",
                            "      + fix-locale-path.diff: Locale handling is different on Ubuntu, using",
                            "        l10n (see the new fix-locale-path.patch).",
                            "      + fix-man.diff: Uncommented in the upstream series.",
                            "      + fix-ppc64el-baudrate.diff: Launchpad's builders instead fails on",
                            "        ppc64le for this patch, the original source code is correct.",
                            "      + use-vendor.diff: Vendor handling is different on Ubuntu.",
                            "    - Remove docs/tldr.zip from Debian upstream",
                            "    - Delete locales shipped in Debian upstream under src/",
                            "    - Move vendored dependencies to debian/",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153168,
                            2154338,
                            2154042,
                            2152801,
                            2146819,
                            2146818,
                            2155763
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Thu, 04 Jun 2026 15:54:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix the i386 (32-bit) FTBFS (OOM): the test build did fat LTO +",
                            "    codegen-units=1 + full debuginfo on the giant all-utils crate and ran out",
                            "    of the ~3GB address space. Set CARGO_PROFILE_RELEASE_LTO=thin,",
                            "    CODEGEN_UNITS=16 and DEBUG=1 via env on all 32-bit arches so every cargo",
                            "    invocation honours them, replacing the sed hacks that missed the test step.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Sun, 31 May 2026 10:04:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.9.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Sat, 30 May 2026 17:07:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix the s390x FTBFS (150min buildd inactivity timeout). The previous",
                            "    sed only disabled LTO around dh_auto_install, so the default build and",
                            "    the test build still did fat LTO + codegen-units=1 + full debuginfo on",
                            "    the giant all-utils crate, which is what actually timed out. Now set",
                            "    CARGO_PROFILE_RELEASE_LTO=false, CODEGEN_UNITS=16 and DEBUG=1 via env so",
                            "    every cargo invocation honours them.",
                            "  * Skip the (non-gating) test suite on s390x: the release test build was",
                            "    the step hitting the timeout (killed at \"Compiling unindent\").",
                            "  * Use lld as the linker on every architecture when it is available, not",
                            "    just on s390x: ld.lld is detected at build time (via command -v) and",
                            "    -fuse-ld=lld is added when present, falling back to the default linker",
                            "    otherwise. lld links the multicall binary much faster than GNU ld.",
                            "    Build-Depend on lld on all architectures (it ships from the same",
                            "    llvm-toolchain source as the already-required libclang-dev).",
                            "  * Log the linker on every architecture: emit the -Wl,-v banner on every",
                            "    link and print rustc -vV / ld.lld / ld at configure time, so every build",
                            "    log records which linker ran. Previously the ld.lld check lived in",
                            "    dh_auto_install (never reached when the build timed out) and only on s390x.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Thu, 28 May 2026 08:08:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Disable LTO on s390x: thin LTO + lld in 0.8.0-4 still timed out on",
                            "    the buildd, so turn LTO off entirely on s390x.",
                            "  * Print ld.lld version and ask the linker to log itself (-Wl,-v) so",
                            "    the build log shows which linker was actually invoked.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Wed, 27 May 2026 23:11:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Use lld as the linker on s390x: thin LTO alone in 0.8.0-3 did not",
                            "    unblock the buildd timeout, so switch the final link to ld.lld.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Wed, 27 May 2026 08:04:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Use thin LTO on s390x to avoid linker timeouts on the buildd",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Wed, 27 May 2026 08:04:14 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * try to unbreak the ppc64 build",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Sun, 17 May 2026 14:58:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release (Closes: #1134876)",
                            "  * Improve the manpage (LP: #2115782)",
                            "  * Add manpage symlink for coreutils binary (no-manual-page)",
                            "  * Extend disable-utmp-classic.diff to cover the new",
                            "    [target.'cfg(target_os = \"openbsd\")'.dependencies] block in",
                            "    src/uucore/Cargo.toml introduced upstream in 0.8.0 (fixes FTBFS).",
                            "  * Disable fix-man.diff: it converts .ftl bullet markers from `-` to `*`",
                            "    and rewrites top-level `key = value` lines as markdown bullets, which",
                            "    is invalid Fluent syntax. uudoc loads each utility's locale via",
                            "    setup_localization_or_exit and was aborting manpage generation with",
                            "    a Localization parse error. Patch kept in debian/patches/ but",
                            "    commented out in series until it can be rewritten Fluent-cleanly.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.8.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2115782
                        ],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Wed, 06 May 2026 13:08:52 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * Move to https://salsa.debian.org/rust-team/coreutils",
                            "  * Improve the manpages example display",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.7.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Mon, 09 Mar 2026 06:59:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * Vendor dependencies. Too hard to maintain in Debian",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.6.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Tue, 17 Feb 2026 13:48:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "",
                            "  [ Jeremy Bícha]",
                            "  * remove unused Build-Depends: librust-unix-socket-dev",
                            "",
                            "  [ Peter Michael Green ]",
                            "  * Add patch for nix 0.30",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.0.30-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Peter Michael Green <plugwash@debian.org>",
                        "date": "Tue, 30 Sep 2025 12:45:34 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Bump the notify dependency to v8",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.0.30-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "NoisyCoil <noisycoil@debian.org>",
                        "date": "Wed, 24 Sep 2025 19:38:04 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Also ship with b3sum (Closes: #1107092)",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.0.30-3~exp1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Mon, 02 Jun 2025 20:43:15 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "sbsigntool",
                "from_version": {
                    "source_package_name": "sbsigntool",
                    "source_package_version": "0.9.5-1",
                    "version": "0.9.5-1"
                },
                "to_version": {
                    "source_package_name": "sbsigntool",
                    "source_package_version": "0.9.5-2build1",
                    "version": "0.9.5-2build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "sbsigntool",
                        "version": "0.9.5-2build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 16:16:41 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix OpenSSL 4 compatibility (Closes: #1138427)",
                            ""
                        ],
                        "package": "sbsigntool",
                        "version": "0.9.5-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Mate Kukri <mate.kukri@canonical.com>",
                        "date": "Tue, 21 Jul 2026 16:37:27 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "snapd",
                "from_version": {
                    "source_package_name": "snapd",
                    "source_package_version": "2.76.3+ubuntu26.10",
                    "version": "2.76.3+ubuntu26.10"
                },
                "to_version": {
                    "source_package_name": "snapd",
                    "source_package_version": "2.77.1+ubuntu26.10.1",
                    "version": "2.77.1+ubuntu26.10.1"
                },
                "cves": [
                    {
                        "cve": "CVE-2024-5300",
                        "url": "https://ubuntu.com/security/CVE-2024-5300",
                        "cve_description": "An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns \"complete\" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-21 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-3888",
                        "url": "https://ubuntu.com/security/CVE-2026-3888",
                        "cve_description": "Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-03-17 14:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2024-5300",
                        "url": "https://ubuntu.com/security/CVE-2024-5300",
                        "cve_description": "An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns \"complete\" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-21 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-3888",
                        "url": "https://ubuntu.com/security/CVE-2026-3888",
                        "cve_description": "Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-03-17 14:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2158102,
                    2072331,
                    2110510,
                    2143934,
                    2160691,
                    2161982,
                    2158301,
                    2159940,
                    2157692,
                    2067006,
                    2157692,
                    2067006,
                    2154498,
                    2147606,
                    2148544,
                    2139213,
                    2125344,
                    2150683,
                    2152908,
                    1966067,
                    2110368,
                    2110368,
                    2144666,
                    2146337,
                    2147207
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2158102",
                            "    - Fix undo of unlink-component after its snap revision was discarded",
                            "    - interfaces: power-control | allow reading all battery state files",
                            "    - fix 26.04+ snapd deb versioning",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.77.1+ubuntu26.10.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158102
                        ],
                        "author": "Ernest Lotter <ernest.lotter@canonical.com>",
                        "date": "Wed, 02 Sep 2026 14:39:12 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "    - Account for differences in names of the binaries in the snapd FIPS",
                            "      build",
                            "    - Add code to calculate canonical subject name hash",
                            "    - Add commands for debugging or accessing snap mount namespaces",
                            "    - Add helpers for listing and iterating device mediation groups",
                            "    - Add package ebpf with helpers wrapping eBPF exposed objects with",
                            "      dependency on github.com/cilium/ebpf",
                            "    - Add secondary prerequisites task that acts as the synchronization",
                            "      point, which ensures that a snap's prerequisites are available",
                            "      before it's installed",
                            "    - Add support for shell conditional syntax in envs",
                            "    - Added /usr/share/{man,help,info} to system-packages-doc",
                            "    - asserts: add validation-sets confdb-schema builtin",
                            "    - asserts: ensure that compatibility labels are strings",
                            "    - asserts: extend on-classic constraints to accept \"distro/variant\",",
                            "      \"distro/*\", and \"distro/\" under a new snap-declaration format 7",
                            "    - asserts: validate serial in newDeviceIDFromString",
                            "    - Bump github.com/canonical/go-efilib to v1.8.0 to include fixes for",
                            "      efivars probe",
                            "    - confdb: add validation-sets handler and fix data loss when writing",
                            "      to new schemas or accounts",
                            "    - confdb: fix bug on reading uneven lists",
                            "    - confdb: literal subkeys are sorted after placeholders",
                            "    - confdb: run observe-view-* hooks after commit",
                            "    - confdb: support Encode/Decode for builtins",
                            "    - confdb: support sign-only external keypair backends",
                            "    - core-initrd: add missing libbpf and systemd dlopen dependencies,",
                            "      and increase mount burst",
                            "    - Drop task logs for delayed effects",
                            "    - During snap removal, clear-snap task errors early if there are",
                            "      user mounts in snap data dirs",
                            "    - Enable reverts to trigger a seed refresh",
                            "    - Ensure profiles are setup before running prepare-{slot, plug}*",
                            "      hooks",
                            "    - Ensure that prereqs created by initial refresh run before create-",
                            "      recovery-system",
                            "    - Exclude Georgian from translation linting",
                            "    - experimental features: graduate layouts, classic-preserves-xdg-",
                            "      runtime-dir, refresh-app-awareness, and dbus-activation features",
                            "    - experimental features: warn when setting graduated or default-",
                            "      enabled experimental features and do not store settings for",
                            "      graduated features",
                            "    - Expose individual certs as well as c_rehash emulation",
                            "    - Extend autogen with explicit --sysconfdir",
                            "    - External keypair manager: add shared external key manager",
                            "      implementation",
                            "    - External keypair manager: refactor GPG and external keypair",
                            "      managers to use extKeypairMgrImpl",
                            "    - External keypair manager: support external OPENPGP signing in",
                            "      ExternalKeypairManager",
                            "    - FDE: add post install actions API",
                            "    - FDE: add reprovision API",
                            "    - FDE: add reprovision recovery key generation API",
                            "    - FDE: add reseal check after snapd refresh",
                            "    - FDE: allow reprovision without factory reset",
                            "    - FDE: change makebootable part of the boot package to not take",
                            "      install observers as parameters",
                            "    - FDE: extend storage-encrypted system information",
                            "    - FDE: make reprovision only seal",
                            "    - FDE: remove all tmp keyslots on error",
                            "    - FDE: remove check for unchanged authentication options",
                            "    - FDE: run post install checks during auto repair",
                            "    - Filter seed-refresh based on model and seed presence",
                            "    - Fix failing snap remove when there are snapctl created mounts",
                            "      under snap global data dirs",
                            "    - Fix postNotices to validate before locking state",
                            "    - Guard the ensure check from running on classic",
                            "    - Implement remodeling fully in terms of updates",
                            "    - Implement ShutDown for HookManager",
                            "    - Include variables SNAP_APP_NAME, and when applicable",
                            "      SNAP_APP_COMMON_ID, SNAP_APP_DESKTOP_FILE and SNAP_APP_BUS_NAME in",
                            "      snap application environments",
                            "    - interfaces: add xdg-portal-permission-store interface",
                            "    - interfaces: allow gtk css in subdirectories",
                            "    - interfaces: allow systemd networkd link property changes via D-Bus",
                            "    - interfaces: allow the systemd networkctl command",
                            "    - interfaces: allow Wine to execute files accessed via the Document",
                            "      Portal",
                            "    - interfaces: apparmor-observe | add interface",
                            "    - interfaces: attempt to fix content with parallel installs",
                            "    - interfaces: devlxd | fix access for LXD containers",
                            "    - interfaces: docker | allow connecting to system-wide docker on",
                            "      classic",
                            "    - interfaces: grant default access to memory.high in a snap's cgroup",
                            "    - interfaces: iscsi-initiator | allow access to /var/lib/iscsi/nodes",
                            "    - interfaces: kernel-sched-ext-control | add the kernel sched-ext",
                            "      control interface implementation",
                            "    - interfaces: make polkit and upower implicit on Core systems only",
                            "    - interfaces: open-iscsi | add missing state paths",
                            "    - interfaces: opengl | expose wsl libraries",
                            "    - interfaces: u2f-devices | add atkey PID and relative VID support",
                            "    - List dir contents on failure to remove snap base data dir",
                            "    - List non-snapctl mounts in snap data dirs",
                            "    - LP: #2072331 Validate map keys in JSON config values",
                            "    - LP: #2110510 Interfaces: allow reading of /proc/self/smaps_rollup",
                            "    - LP: #2143934 Interfaces: network-control, network-manager | allow",
                            "      missing resolve1 link setters",
                            "    - LP: #2160691 Security logging: strip trailing whitespace from",
                            "      audit netlink message payload",
                            "    - LP: #2161982 Interfaces: vsock | add interface for VM guest",
                            "      services",
                            "    - Make arguments of debug mount-namespace consistent with other",
                            "      debug commands",
                            "    - Make bootloader logging less verbose",
                            "    - Make cert manager garbage check run after symlink migration",
                            "    - Make secondary prerequisite synchronization task handle same-",
                            "      change retries",
                            "    - mkversion.sh: do describe in worktrees too",
                            "    - multi-entry snapd: merge snap and snapd binaries",
                            "    - multi-entry snapd: move debug device-cgroup implementation file",
                            "      under cmd/snapd/cli",
                            "    - multi-entry snapd: move snap-gpio-helper sources around before",
                            "      transitioning to multi-entry dispatch",
                            "    - multi-entry snapd: move snapd-apparmor sources to a dedicated tool",
                            "      location",
                            "    - multi-entry snapd: move source files around in preparation for",
                            "      snapd/snap merge",
                            "    - multi-entry snapd: move the snap-preseed sources around in",
                            "      preparation",
                            "    - multi-entry snapd: move the sources of snapctl and snap-exec in",
                            "      preparation for the multi-entry dispatch",
                            "    - Never create seed refresh tasks during a remodel",
                            "    - packaging: assign a default label for /tmp/snap-private-tmp and",
                            "      set it during installation",
                            "    - packaging: build deb with Go 1.23 for noble and jammy, Go 1.22 for",
                            "      focal",
                            "    - packaging: drop SNAP_TAGS",
                            "    - packaging: drop symlinks for opensuse 15.5/15.6 packaging",
                            "    - packaging: fix service startup during install and session-agent",
                            "      socket handling on Ubuntu 26.04+",
                            "    - packaging: fix stderr redirection",
                            "    - packaging: restore gbp.conf output directory for Ubuntu 26.04",
                            "      builds",
                            "    - packaging: switch to apparmor 5.x with 5 ABI",
                            "    - packaging: update bundled AppArmor to 5.0.2 and accept the 5.0 ABI",
                            "      when running as deb",
                            "    - packaging: use a relative symlink for snapctl and update steam-",
                            "      support udev rules",
                            "    - Preserve component in hook security tags",
                            "    - Prevent removal of seed-refresh snaps when seed-refresh is enabled",
                            "    - Refactor base-declaration into 1st class builtin assertion",
                            "    - Refactor how the is-originating-from-snap-command advisory check",
                            "      works",
                            "    - Refactor prerequisites task handler to enable proper seed-refresh",
                            "      integration",
                            "    - Reintroduce fdstore helpers",
                            "    - remote device management: add task to validate request messages",
                            "    - remote device management: apply management messages, queue",
                            "      response messages, and improve sequencing and redelivery handling",
                            "    - Remove osutil unused AtomicWriteFollow flag",
                            "    - Remove xerrors dependency",
                            "    - Reuse existing seed-refresh implementation for free during single-",
                            "      path installation",
                            "    - Rework how SnapSetup.SnapPath is used",
                            "    - seccomp: allow rseq_slice_yield",
                            "    - security logging: add seclog API for administrative actions and",
                            "      token create/remove events",
                            "    - security logging: add security logging for adding, updating and",
                            "      removing a snapd user",
                            "    - Set target hostname from install-mode",
                            "    - snap-confine: improve loading of BPF programs, retry on failures",
                            "      to collect verifier logs",
                            "    - snap-confine: use profile and flags= in snap-confine and snap-",
                            "      update-ns' AppArmor profiles",
                            "    - snap-confine: work around kernel mnt_ns_loop() ordering bug on",
                            "      6.18.x",
                            "    - snap: add debug command for listing currently mediated devices for",
                            "      a given snap",
                            "    - snap: fix self-managed cgroup support checks",
                            "    - snap: report hidden file access for paths allowed by home when",
                            "      prompting is active",
                            "    - snap: report read-only file access for paths allowed by system-",
                            "      package-doc",
                            "    - snapctl async support: add --format json to snap tasks to be",
                            "      consistent with snapctl",
                            "    - snapctl async support: add snapctl tasks command",
                            "    - snapctl async support: async feature negotiation between snap",
                            "      client and daemon",
                            "    - snapctl async support: fix snapctl is-ready exit codes",
                            "    - snapctl async support: re-enable snapctl async functionality",
                            "    - snapshots: restore preserves snapctl created mounts",
                            "    - snapshots: save excludes all mount points",
                            "    - Support ca-certificate.crt only systems like core26",
                            "    - Turn on quota-groups by default",
                            "    - Use 0755 for certificate generation directories",
                            "    - Use CreateTemp for NewAtomicFile tmp file creation",
                            "    - Verify cached downloads in the do path and detect obvious",
                            "      corruption",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.77+ubuntu26.10",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2072331,
                            2110510,
                            2143934,
                            2160691,
                            2161982
                        ],
                        "author": "Sergio Cazzolato <sergio.cazzolato@canonical.com>",
                        "date": "Fri, 24 Jul 2026 20:45:05 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2158301",
                            "    - FDE: support keyboard configuration at install-time for first-boot",
                            "    - FDE: re-enable passphrases/PINs at install-time",
                            "    - FDE: require volumes authentication if HWROT is missing",
                            "    - FDE: bump secboot to rev 457b03a16d19",
                            "    - FDE: use new secboot API for reprovision TPM",
                            "    - Cross-distro: modify SELinux policy to use",
                            "      init_named_socket_activation() for allowing systemd to start snapd",
                            "      through socket activation",
                            "    - packaging: make sure that usr/bin/snap is built with correct build",
                            "      tags on debian sid",
                            "    - Ensure profiles are setup before running prepare-{slot, plug}*",
                            "      hooks",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76.3",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2158301
                        ],
                        "author": "Katie May <katie.may@canonical.com>",
                        "date": "Tue, 07 Jul 2026 10:06:48 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2159940",
                            "    - interfaces: steam-support, docker-support | fix mountinfo denial",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76.2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2159940
                        ],
                        "author": "Katie May <katie.may@canonical.com>",
                        "date": "Tue, 07 Jul 2026 08:38:51 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2024-5300",
                                "url": "https://ubuntu.com/security/CVE-2024-5300",
                                "cve_description": "An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns \"complete\" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-21 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-3888",
                                "url": "https://ubuntu.com/security/CVE-2026-3888",
                                "cve_description": "Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-03-17 14:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2157692",
                            "    - LP: #2067006 CVE-2024-5300",
                            "    - CVE-2026-3888",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76.1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2157692,
                            2067006
                        ],
                        "author": "Ernest Lotter <ernest.lotter@canonical.com>",
                        "date": "Thu, 25 Jun 2026 13:09:05 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2024-5300",
                                "url": "https://ubuntu.com/security/CVE-2024-5300",
                                "cve_description": "An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns \"complete\" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-21 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-3888",
                                "url": "https://ubuntu.com/security/CVE-2026-3888",
                                "cve_description": "Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-03-17 14:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2157692",
                            "    - LP: #2067006 CVE-2024-5300",
                            "    - CVE-2026-3888",
                            "    - SNAPDENG-36017",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76.1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2157692,
                            2067006
                        ],
                        "author": "Ernest Lotter <ernest.lotter@canonical.com>",
                        "date": "Sat, 20 Jun 2026 10:27:54 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2154498",
                            "    - assertions: add helper for validating integrity data",
                            "    - assertions: drop incorrect/non-standard Ed25519 support",
                            "    - confdb: allow only API admin read access to confdb secrets",
                            "    - confdb: block concurrent confdb accesses",
                            "    - confdb: block concurrent snapctl accesses to configuration",
                            "      database",
                            "    - confdb: check for ephemeral data when missing save-view hook on",
                            "      commit",
                            "    - confdb: ignore not-found errors in confdb-schema refreshes",
                            "    - confdb: support --wait-for timeouts when accessing confdb",
                            "    - core-initrd: add group referenced in udev rules",
                            "    - core-initrd: add libbpf dependency to initramfs",
                            "    - core-initrd: add missing libbpf dependency in 24.04 packaging",
                            "    - core-initrd: ensure audio is a system group",
                            "    - core-initrd: fix /boot/uboot mount with u-boot env in dedicated",
                            "      partition",
                            "    - core-initrd: increase mount burst from 5 to 128 for faster boot",
                            "    - core-initrd: sync partition udev rules with the ones in core-base",
                            "    - core-initrd: sync with latest upload to snappy-dev PPA",
                            "    - core-initrd: synchronize changelogs with latest PPA upload",
                            "    - core-initrd: update changelog with latest PPA upload",
                            "    - core-initrd: add nfnetlink module to fix nf netlink",
                            "      socket speed regression (Ubuntu Core only)",
                            "    - cross-distro: allow snapd to manipulate systemd unit files in",
                            "      SELinux policy",
                            "    - cross-distro: FIPS bootstrap and dispatch via snap-fips-dispatch",
                            "    - desktop: fix common ID selection with multiple desktop plugs",
                            "    - FDE: allow user mode on core in secboot TPM handling",
                            "    - FDE: bump go-efilib dependency",
                            "    - FDE: bump secboot to rev cdcb64992e54 for FDE fixes",
                            "    - FDE: deprecate check-pin/passphrase API endpoints",
                            "    - LP: #2147606 FDE: give inactive state on classic",
                            "    - FDE: improve tracing for OP-TEE probing",
                            "    - FDE: move auto-repair logic to overlord/fdestate and provide state",
                            "    - FDE: update secboot for TPM/FDE bug fixes including Intel HAP and",
                            "      recovery key parsing",
                            "    - FDE: use any primary key matching digest when adding a keyslot",
                            "    - FDE: use ignore action for preinstall check in VM",
                            "    - interfaces: bluez | drop explicit deny send_destination in D-Bus",
                            "      configuration",
                            "    - interfaces: conditionally deny /proc/self/mountinfo to suppress Go",
                            "      1.25+ denials",
                            "    - interfaces: custom-device | fix for-device validation panic on",
                            "      non-string value",
                            "    - interfaces: disallow auto-connect to parallel installs",
                            "    - interfaces: docker | make plug implicit on classic systems",
                            "    - interfaces: ignore errors in disconnect hooks during explicit snap",
                            "      disconnect",
                            "    - interfaces: mediatek-accel | add plug interface base declaration",
                            "    - interfaces: microceph-support | suppress noisy sudo denial audit",
                            "      logs",
                            "    - interfaces: podman | add new interface for podman socket access",
                            "    - interfaces: pulseaudio | fix security tag syntax inconsistency",
                            "    - interfaces: raw-usb | allow USB device enumeration on Fairphone 5",
                            "      with NexDock",
                            "    - interfaces: restore auto-connections on failed refresh undo",
                            "    - LP: #2148544 interfaces: bool-file | support deep SoC sysfs paths",
                            "      for LED brightness",
                            "    - LP: #2139213 packaging: make Ubuntu 16.04 packaging dep17",
                            "      compliant",
                            "    - packaging: add cross-distro build script and instructions",
                            "    - packaging: add openSUSE 16.0 spread support",
                            "    - packaging: Debian build improvements",
                            "    - packaging: default openSUSE to /var/lib/snapd/snap and sync from",
                            "      downstream",
                            "    - packaging: drop transitional packages only for Ubuntu 26.04",
                            "      (Resolute)",
                            "    - packaging: fix Launchpad FIPS build detection for snapd-fips job",
                            "    - packaging: refactor and clean up snapd.mk, standardize test-data",
                            "      directories",
                            "    - packaging: switch to golang-github-chai2010-gettext-go-dev",
                            "    - packaging: update bundled AppArmor 4.1.7 (snapd snap only)",
                            "    - prompting: escape paths in prompt constraints",
                            "    - prompting: improve API error handling and validation",
                            "    - prompting: improve error message when no handler service is",
                            "      present",
                            "    - prompting: re-enable the prompting notice backend",
                            "    - prompting: respond with full user-allowed permission set",
                            "    - prompting: validate permissions while unmarshalling",
                            "    - remote device management: implement dispatch-mgmt-messages task",
                            "      with sequencing support",
                            "    - LP: #2125344 snap: avoid empty channel forwarding message",
                            "    - LP: #2150683 snap: clarify snap install help text for --classic",
                            "      and --devmode",
                            "    - LP: #2152908 snap: print complex attributes in snap interface",
                            "      --attrs output",
                            "    - snap: add run-inhibit hint and inhibit info when a snap is",
                            "      disabled",
                            "    - snap: allow removing a snap and its base at the same time",
                            "    - snap: display detailed component information in snap info",
                            "    - snap: extend AlreadyInstalledError to multiple snaps and",
                            "      components",
                            "    - snap: extend set-quota command options description with accepted",
                            "      value formats",
                            "    - snap: implement snap delta command for computing snap deltas",
                            "    - snap: improve consistency for snap install when some snaps are",
                            "      already installed",
                            "    - snap: show hint in snap list that a snap has components",
                            "    - snap-confine: allow inheriting unix sockets from snaps",
                            "    - snap-confine: allow linking to libm in AppArmor profile",
                            "    - snap-confine: fix out-of-bounds read in mountinfo parser for",
                            "      partial escape sequences",
                            "    - snap-confine: harden bpffs mount with nosuid, nodev, noexec flags",
                            "    - snap-confine: remove experimental persistent per-user mount",
                            "      namespace feature",
                            "    - snap-confine: set FD_CLOEXEC on file descriptors returned by BPF",
                            "      helpers",
                            "    - snap-confine: support transparent_hugepage in AppArmor profile",
                            "    - snap-confine: use strchr after NUL-terminating in infofile parser",
                            "    - snap-update-ns: switch to a multi-pass process for constructing",
                            "      and updating mount namespaces",
                            "    - RemoveMountUnitFile now unmounts even if mount unit file is",
                            "      missing",
                            "    - Add explicit mount phase during single-reboot refresh to fix undo",
                            "      of kernel refreshes",
                            "    - Add security audit logging subsystem",
                            "    - Add base prioritized AppArmmor snippets for strictly confined or",
                            "      jailed snaps",
                            "    - Allow openshell snap to use experimental daemon-scope: user",
                            "    - Allow configuring mount unit options based on filesystem type",
                            "    - Allow equals signs in uevent values in netlink parser",
                            "    - Also bind-mount directories modified by kmod backend during",
                            "      preseed",
                            "    - Clean up potentially corrupted files during snap download undo",
                            "    - Complete the bootloader environment implementation",
                            "    - Copy integrity data files during snap install",
                            "    - Create hook for seed refresh mode",
                            "    - Create removal tasks for old seed-refresh seeds",
                            "    - Dispatch systemctl commands asynchronously when calling Stop()",
                            "    - Ensure /tmp/.X11-unix created inside mount namespace has correct",
                            "      permissions",
                            "    - Ensure exclusive changes conflict with refresh/revert",
                            "    - Ensure existing snap confinement flags are not dropped when",
                            "      installing or removing components",
                            "    - Export ubuntu-boot-state filename constant from bootloader package",
                            "    - Fix duplicate removal of apps under $SNAP_MOUNT_DIR/bin",
                            "    - Fix integration between prerequisites task and seed-refresh mode",
                            "    - Fix split-refresh overwriting provided lane",
                            "    - Fix use of umask in GetListener for socket activation",
                            "    - Ignore net.ErrClosed during daemon shutdown",
                            "    - Implement ResolveValidationSetsEnforcementError in terms of one",
                            "      call",
                            "    - Improve snapctl install consistency when components are already",
                            "      installed",
                            "    - Inject seed creation tasks into snap refresh flow",
                            "    - Introduce system options for custom certificates on Ubuntu Core",
                            "    - Keep idle services with activation units stopped on reload",
                            "    - List snap components in snap-debug-info via debug-tools",
                            "    - Look at gadget.yaml instead of marker file to determine ubootpart",
                            "      usage",
                            "    - LP: #1966067 Skip redundant xdg-settings confirmation prompt when",
                            "      setting is already correct",
                            "    - LP: #2110368 Fix component installation for private snaps via",
                            "      snapctl",
                            "    - LP: #2110368 Fix download of private snap components by setting",
                            "      UserID",
                            "    - LP: #2144666 Fix mount namespace updates with synthetic bind",
                            "      mounts on same target paths",
                            "    - LP: #2146337 Improve handling of failed downloads and retain",
                            "      partial files for resume",
                            "    - LP: #2147207 Fix snap enable/disable cycle forgetting components",
                            "    - Make run-inhibit hint for kill-snap-apps task based on kill reason",
                            "    - Merge content-provider prerequisite updates into seed-refresh",
                            "    - Move SortServices into Backend.StartServices",
                            "    - Move state to client change conversion to ctlcmd package",
                            "    - Omit misleading \"try to refresh snapd\" suggestion for ISA-related",
                            "      errors",
                            "    - Only create link-component tasks when needed during refresh to",
                            "      existing revision",
                            "    - Reconfigure piboot bootloader on gadget refreshes to preserve",
                            "      os_prefix",
                            "    - Reduce the number of AppArmor profile regenerations during snap",
                            "      operations",
                            "    - Refactor seed-refresh ownership to devicestate",
                            "    - Regenerate certificate database on remodels",
                            "    - Remove obsolete FIXME comment in VersionCompare",
                            "    - Remove unused GenerateDmVerityData helper from snap/integrity",
                            "    - Rename and document error type for ISA assumes flags",
                            "    - Restart snapd from daemon.Stop to improve restart reliability",
                            "    - Restart stopped services on error in stopSnapServices for",
                            "      transactionality",
                            "    - Simplify certificate-db updates on model-base refresh/installs",
                            "    - Support racing Loop and Stop correctly in overlord",
                            "    - Support sending file descriptors to systemd via sd_notify",
                            "    - Unroll CPU-heavy recursive function in snap state handlers",
                            "    - Update seccomp syscalls list for kernel 7.1.0",
                            "    - Use change ID to prevent nested seed-refresh spawned by",
                            "      prerequisites",
                            "    - Validate content interface plug target directories exist for",
                            "      core26+ snaps",
                            "    - Validate layout paths exist in snap tree for snaps using bare or",
                            "      core26+",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2154498,
                            2147606,
                            2148544,
                            2139213,
                            2125344,
                            2150683,
                            2152908,
                            1966067,
                            2110368,
                            2110368,
                            2144666,
                            2146337,
                            2147207
                        ],
                        "author": "Ernest Lotter <ernest.lotter@canonical.com>",
                        "date": "Thu, 28 May 2026 20:00:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "sudo-rs",
                "from_version": {
                    "source_package_name": "rust-sudo-rs",
                    "source_package_version": "0.2.13-0ubuntu1",
                    "version": "0.2.13-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "rust-sudo-rs",
                    "source_package_version": "0.2.14-1ubuntu2",
                    "version": "0.2.14-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2159633,
                    2156983,
                    2153817,
                    2158541,
                    2152220,
                    2146860
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/04-getroot-sssd: Fix test by restarting slapd with systemd",
                            "    and add some more robustness",
                            ""
                        ],
                        "package": "rust-sudo-rs",
                        "version": "0.2.14-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Grayson Wolf <grayson.wolf@canonical.com>",
                        "date": "Mon, 13 Jul 2026 10:42:31 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2159633). Remaining changes:",
                            "    - drop unnecessary upstream patches:",
                            "      + auto/auto-remove-features",
                            "      + disable-test-timeout",
                            "    - d/rules:",
                            "      + add vendoring targets",
                            "      + set setuid bit after dh_fixperms",
                            "      + change DEB_CARGO_INSTALL_PREFIX",
                            "      + set features and skip tests in dh_auto_test",
                            "      + set SUDO_RS_VERSION",
                            "    - Add autopkgtest and centralize cargo build features",
                            "    - Remove librust-sudo-rs-dev",
                            "    - debian/control:",
                            "      + add Depends sudo-common",
                            "      + add Recommends apport",
                            "      + add Recommends libapparmor1",
                            "      + remove vendored librust Build-Depends",
                            "      + update XS-Vendored-Sources-Rust field",
                            "    - debian/README.source: add vendoring instructions",
                            "    - debian/copyright: update information",
                            "    - rust-vendor: update vendored dependencies",
                            "    - Skip pandoc on i386",
                            "    - Add and modify sudo.ws tests",
                            "    - Add sudo alternatives",
                            "    - Add apport package hook",
                            "    - Add cargo-auditable metadata",
                            "  * Fixes:",
                            "    - Remove unnecessary python dependency: Replace Depends python3:any with",
                            "      Recommends apport as that better aligns with the apport hook intent",
                            "      (LP: #2156983)",
                            "    - PAM_TTY is wrongly computed by sudo-rs (LP: #2153817)",
                            "    - sudo-rs fails with \"I'm sorry\" message in systems with large groups",
                            "      (LP: #2158541)",
                            "    - [security] sudo-rs ≤ 0.2.13: silent drop of argument restrictions on",
                            "      \\<newline> line continuation (LPE) (LP: #2152220)",
                            "    - command permanently stop (LP: #2146860)",
                            "  * New Changes:",
                            "    - Use debian/rust-vendor for vendoring as this allows changing the",
                            "      versions of vendored dependencies without bumping the upstream version.",
                            "  * Drop Changes:",
                            "    - debian/patches:",
                            "      + fix-toggle-pwfeedback-tab: Fixed upstream.",
                            "    - wrap-and-sort debian/ files: Dropped as it created unnecessary delta",
                            "      with Debian.",
                            ""
                        ],
                        "package": "rust-sudo-rs",
                        "version": "0.2.14-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159633,
                            2156983,
                            2153817,
                            2158541,
                            2152220,
                            2146860
                        ],
                        "author": "Simon Johnsson <simon.johnsson@canonical.com>",
                        "date": "Wed, 08 Jul 2026 11:50:23 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Package sudo-rs 0.2.14 from crates.io using debcargo 2.8.3",
                            "  * Notable upstream changes:",
                            "    - timestamp files created with sudo-rs <= 0.2.10 are invalidated",
                            "    - `Defaults pwfeedback` is now on by default, TAB will turn off visual",
                            "    feedback during password prompts",
                            "    - `su` will allow changing to an account that has no password set, making",
                            "    su-rs consistent with util-linux and FreeBSD `su`",
                            ""
                        ],
                        "package": "rust-sudo-rs",
                        "version": "0.2.14-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Fabian Grünbichler <debian@fabian.gruenbichler.email>",
                        "date": "Sun, 05 Jul 2026 20:24:59 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/tests: Add test suit from sudo.ws and change expected outputs",
                            "    to match sudo-rs output formats.",
                            ""
                        ],
                        "package": "rust-sudo-rs",
                        "version": "0.2.13-0ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Varun Varma <varun.varma@canonical.com>",
                        "date": "Wed, 01 Apr 2026 09:56:32 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "systemd",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "systemd-resolved",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "systemd-sysv",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "tzdata",
                "from_version": {
                    "source_package_name": "tzdata",
                    "source_package_version": "2026b-1ubuntu2",
                    "version": "2026b-1ubuntu2"
                },
                "to_version": {
                    "source_package_name": "tzdata",
                    "source_package_version": "2026c-1ubuntu1",
                    "version": "2026c-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2161092
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2161092). Remaining changes:",
                            "    - Ship 2026b ICU timezone data which are utilized by PHP in tzdata-icu",
                            "    - Add autopkgtest test case for ICU timezone data",
                            "    - Point Vcs-Browser/Git to Launchpad",
                            "  * Dropped changes:",
                            "    - Declare breaking rust-coreutils before version 0.5.0.",
                            "      Ubuntu 26.04 \"resolute\" has rust-coreutils 0.8.0.",
                            "  * Update the ICU timezone data to 2026c",
                            "  * Add autopkgtest test case for ICU timezone data 2026c",
                            ""
                        ],
                        "package": "tzdata",
                        "version": "2026c-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161092
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Fri, 17 Jul 2026 14:34:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 2026c:",
                            "    - Alberta moved to permanent -06 on 2026-06-18, so it will not fall back",
                            "      from -06 to -07 on 2026-11-01.",
                            "    - Morocco moves to permanent +00 on 2026-09-20.",
                            "  * Add autopkgtest test case for 2026c release",
                            ""
                        ],
                        "package": "tzdata",
                        "version": "2026c-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 13 Jul 2026 22:18:20 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-cloud-minimal",
                "from_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.573",
                    "version": "1.573"
                },
                "to_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.576",
                    "version": "1.576"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167086,
                    2162040,
                    2156756
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Refreshed dependencies",
                            "  * Removed busybox-static from standard (LP: #2167086)",
                            "  * Removed cpio from standard",
                            "  * Moved gnupg to server-raspi-recommends, server-recommends",
                            "  * Bump Standards-Version to 4.7.4",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "ubuntu-meta",
                        "version": "1.576",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167086
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Wed, 16 Sep 2026 19:56:52 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Kat Kuo ]",
                            "  * Refreshed dependencies",
                            "  * Removed ubuntu-report from desktop-minimal-recommends, desktop-",
                            "    raspi-recommends, desktop-recommends",
                            ""
                        ],
                        "package": "ubuntu-meta",
                        "version": "1.575",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Didier Roche-Tolomelli <didrocks@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 16:23:44 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Gauthier Jolly ]",
                            "  * Refreshed dependencies",
                            "  * Added curl to cloud-minimal, server-minimal (LP: #2162040)",
                            "",
                            "  [ Sergio Costas Rodriguez ]",
                            "  * Removed hwctl from desktop-minimal-recommends [amd64], desktop-",
                            "    raspi-recommends [amd64], desktop-recommends [amd64], server-",
                            "    minimal-recommends [amd64] (LP: #2156756)",
                            ""
                        ],
                        "package": "ubuntu-meta",
                        "version": "1.574",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2162040,
                            2156756
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 31 Jul 2026 13:16:40 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-drivers-common",
                "from_version": {
                    "source_package_name": "ubuntu-drivers-common",
                    "source_package_version": "1:0.10.9",
                    "version": "1:0.10.9"
                },
                "to_version": {
                    "source_package_name": "ubuntu-drivers-common",
                    "source_package_version": "1:0.10.10",
                    "version": "1:0.10.10"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Ashton Nelson ]",
                            "  * Add D-Bus service for Ubuntu Drivers",
                            "",
                            "  [ Michael Hudson-Doyle ]",
                            "  * Remove outdated ubiquity integration",
                            "  * Fix various lintian warnings",
                            "  * Various cleanups",
                            ""
                        ],
                        "package": "ubuntu-drivers-common",
                        "version": "1:0.10.10",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Mitchell Augustin <mitchell.augustin@canonical.com>",
                        "date": "Tue, 11 Aug 2026 13:58:42 -0500"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-keyring",
                "from_version": {
                    "source_package_name": "ubuntu-keyring",
                    "source_package_version": "2023.11.28.1build1",
                    "version": "2023.11.28.1build1"
                },
                "to_version": {
                    "source_package_name": "ubuntu-keyring",
                    "source_package_version": "2026.08.18",
                    "version": "2026.08.18"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2163397
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop ubuntu-keyring-udeb",
                            "  * Remove obsolete postinst scripts",
                            "  * Remove cdimage fragment and add ubuntu-cdimage-keyring.gpg",
                            "  * Rename GnuPG to OpenPGP",
                            "  * Remove transitional ubuntu-cloudimage-keyring",
                            "  * ubuntu-archive-keyring: Remove the cdimage key",
                            "  * Update keys with new self-signatures (LP: #2163397)",
                            "    - ubuntu-cloudimage-keyring",
                            "    - ubuntu-dbgsym-keyring",
                            "  * Regenerate fragments with `sq`",
                            ""
                        ],
                        "package": "ubuntu-keyring",
                        "version": "2026.08.18",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163397
                        ],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 23:33:48 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-pro-client",
                "from_version": {
                    "source_package_name": "ubuntu-advantage-tools",
                    "source_package_version": "37.2ubuntu",
                    "version": "37.2ubuntu"
                },
                "to_version": {
                    "source_package_name": "ubuntu-advantage-tools",
                    "source_package_version": "38ubuntu0",
                    "version": "38ubuntu0"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-12391",
                        "url": "https://ubuntu.com/security/CVE-2026-12391",
                        "cve_description": "An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11386",
                        "url": "https://ubuntu.com/security/CVE-2026-11386",
                        "cve_description": "An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-9494",
                        "url": "https://ubuntu.com/security/CVE-2026-9494",
                        "cve_description": "An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153472,
                    2143251,
                    2163406,
                    2144693
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-12391",
                                "url": "https://ubuntu.com/security/CVE-2026-12391",
                                "cve_description": "An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11386",
                                "url": "https://ubuntu.com/security/CVE-2026-11386",
                                "cve_description": "An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-9494",
                                "url": "https://ubuntu.com/security/CVE-2026-9494",
                                "cve_description": "An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * d/apparmor/ubuntu_pro_esm_cache.jinja2:",
                            "    - fix denied audit messages when devicetree exists (LP #2131292)",
                            "    - add cap perfmon to cloud_id AppArmor profile (LP: #2153472)",
                            "    - add perfmon systemctl unix socket in AppArmor profiles (LP: #2143251)",
                            "    - include PID directory in ubuntu_pro_esm_cache profile",
                            "    - allow /usr/share/coreutils/locales/** in ubuntu_pro_esm_cache profile",
                            "  * New upstream release 38 (LP: #2163406):",
                            "    - security:",
                            "      + fix CVE-2026-12391",
                            "      + fix CVE-2026-11386",
                            "      + fix CVE-2026-9494",
                            "    - clouds:",
                            "      + add GCP license IDs for Base and Minimal images for resolute",
                            "      + add GCP Base Marketplace and Minimal Marketplace license IDs for",
                            "        bionic, focal, jammy, noble, and resolute",
                            "      + map aws-gov to aws for correct FIPS flavor (LP: #2144693)",
                            ""
                        ],
                        "package": "ubuntu-advantage-tools",
                        "version": "38ubuntu0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153472,
                            2143251,
                            2163406,
                            2144693
                        ],
                        "author": "Spencer Runde <spencer.runde@canonical.com>",
                        "date": "Fri, 28 Aug 2026 16:09:28 -0500"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-release-upgrader-core",
                "from_version": {
                    "source_package_name": "ubuntu-release-upgrader",
                    "source_package_version": "1:26.10.3",
                    "version": "1:26.10.3"
                },
                "to_version": {
                    "source_package_name": "ubuntu-release-upgrader",
                    "source_package_version": "1:26.10.8",
                    "version": "1:26.10.8"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158525,
                    2166785,
                    2154822,
                    2154822
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * DistUpgradeQuirks: Add check for mysql_native_password use (LP: #2158525).",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.8",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158525
                        ],
                        "author": "Lena Voytek <lena.voytek@canonical.com>",
                        "date": "Tue, 08 Sep 2026 13:38:26 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * tests: test against recent releases",
                            "  * Use `sqv` instead of `gpgv` (LP: #2166785)",
                            "  * Run pre-build.sh to update templates and version",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.7",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166785
                        ],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 08 Sep 2026 17:18:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fixes for LP: #2154822:",
                            "    - DistUpgradeController: Fix rewriteMirrorUri to strip the country mirror",
                            "      on archs served by ports.u.c",
                            "    - test_sources_list: Disable test_apt_cacher_and_apt_bittorent on archs",
                            "      served by ports.u.c (rewriteMirrorUri now correctly causes changes that",
                            "      differ by architecture, and the test will only pass on archs served by",
                            "      archive.u.c)",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.6",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154822
                        ],
                        "author": "Dave Jones <dave.jones@canonical.com>",
                        "date": "Tue, 08 Sep 2026 12:09:21 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * DistUpgradeController: Split entries when the architecture(s) of the",
                            "    entry now reside on a different host, e.g. 26.04 where arm64 migrated",
                            "    from ports.u.c to archive.u.c (LP: #2154822)",
                            "  * DistUpgradeQuirks: minor changes to fix autopkgtest errors",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154822
                        ],
                        "author": "Dave Jones <dave.jones@canonical.com>",
                        "date": "Tue, 01 Sep 2026 20:33:49 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Florent 'Skia' Jacquet ]",
                            "  * test_pycodestyle: give a more verbose output upon failure",
                            "  * Add .launchpad.yaml to run at least some basic checks directly from git",
                            "  * Fix Stonking version number in announcements",
                            "",
                            "  [ kkuo ]",
                            "  * Remove unnecessary Ubuntu Insights consent migration logic",
                            "",
                            "  [ Oliver Reiche ]",
                            "  * DistUpgrade: fix release announcements for stonking",
                            "",
                            "  [ Alessandro Astone ]",
                            "  * Add quirk for installing dbus-broker",
                            ""
                        ],
                        "package": "ubuntu-release-upgrader",
                        "version": "1:26.10.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Mon, 31 Aug 2026 12:01:33 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "udev",
                "from_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "259.5-0ubuntu3",
                    "version": "259.5-0ubuntu3"
                },
                "to_version": {
                    "source_package_name": "systemd",
                    "source_package_version": "261.2-1ubuntu1",
                    "version": "261.2-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153359,
                    2158686,
                    2153900,
                    2153359,
                    2158686,
                    2153359,
                    2153359,
                    2153359,
                    2125614,
                    2150773,
                    2148619
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "      + d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-reduce-number-of-disks-in-TEST-64-UDEV-STORAGE-simul.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/9836c4ab8c",
                            "    - mkosi-pull-new-split-out-packages-for-deb-ubuntu.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/06f2b81cc9",
                            "  * Dropped changes, included in Debian:",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "  * Dropped changes, no longer needed:",
                            "    - d/systemd.postinst: drop systemd-tmpfiles --create call.",
                            "      This exists expressly so that 00rsyslog.conf is included when upgrading",
                            "      systemd. But, Ubuntu now builds so that /var/log has a default access",
                            "      mode of 0755, which will not clobber the changes in 00rsyslog.conf.",
                            "  * New changes:",
                            "    - Fix conflict with 00rsyslog.conf (LP: #2158686)",
                            "      + meson: add build option for /var/log mode",
                            "      + d/rules: set /var/log mode to 0775 on ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 28 Jul 2026 08:48:53 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.2' Update to upstream",
                            "    version '261.2' with Debian dir",
                            "    b19b2fcdbda652d584359be6707c14432386680c",
                            "",
                            "  [ Daniel Lewart ]",
                            "  * Make systemd-networkd example consistent with systemd.network(5)",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/systemd.links: drop procps.service alias (LP: #2153900)",
                            "  * d/control: clarify systemd-imds Description. Thanks to Andreas Metzler",
                            "    for the suggestion. (Closes: #1142173)",
                            "  * d/libnss-systemd.nss: install after files and compat in nsswitch.conf",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2153900
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Thu, 23 Jul 2026 14:31:52 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Move modules-load from systemd package to udev package. This depends",
                            "    on libkmod to work, and it's something that is needed on a host, but",
                            "    not in a container, just like udev (on both counts).",
                            "  * systemd-tpm: depend on tpm-udev for rules and tmpfiles.d",
                            "  * systemd: downgrade systemd-tpm and mount to recommends. With these",
                            "    changes the only dependencies in the systemd packages are libmount1,",
                            "    libblkd1 and glibc, which are all in the essential set anyway. This",
                            "    makes the systemd package suitable for minimal and contained images",
                            "    too.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/upstream: use mkosi from archive for Ubuntu autopkgtest",
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * debian/libpam-systemd.postinst: run pam-auth-update with",
                            "    --root=$DPKG_ROOT.",
                            "",
                            "  [ Roy Briggs ]",
                            "  * debian/extra/network: use NamePolicy=keep mac on USB wifi devices.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 13 Jul 2026 12:38:07 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/upstream: skip remaining problematic tests",
                            "  * mkosi: pull new split-out packages for deb/ubuntu",
                            "  * d/control: do not Depends: systemd-tpm on i386",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 16:10:34 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - debian/control: Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "  * New changes:",
                            "    - d/control: do not build systemd-{tpm,report,imds} on i386",
                            "    - d/systemd.postinst: fix triggering of all tmpfiles.",
                            "      The intent in systemd.postinst is to trigger _all_ tmpfiles, not just",
                            "      those owned by systemd. Move the call after #DEBHELPER# to fix this.",
                            "      (LP: #2158686)",
                            "    - test: reduce number of disks in TEST-64-UDEV-STORAGE-simultaneous_events on Debian/Ubuntu",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359,
                            2158686
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 01 Jul 2026 09:07:58 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Make systemd actually temporarily depend on systemd-tpm. This was",
                            "    mentioned in NEWS but forgotten, add it for a while to ease transition",
                            "  * d/t/control: pull new packages in upstream test suite",
                            "  * d/t/control: pull in cpio for upstream suite. Needed by mkosi",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 27 Jun 2026 19:50:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: demote libnss-{myhostname,resolve} to Suggests for systemd-",
                            "    resolved",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261.1' Update to upstream",
                            "    version '261.1' with Debian dir",
                            "    7b147cc676313eab49521f545f0f752c15704667",
                            "  * Override new Lintian false positive",
                            "  * d/copyright: update to add new licenses",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 26 Jun 2026 21:23:40 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/t/control: do not install xserver-xorg-video-dummy on loong64",
                            "  * Split imds tools into new systemd-imds package. These depend on curl",
                            "    and provide advanced functionality, so split into a new package to",
                            "    make the main package lighter",
                            "  * Split metrics reporting tools into new systemd-report package. These",
                            "    depend on curl and provide advanced functionality, so split into a new",
                            "    package to make the main package lighter",
                            "  * Split tpm tools into new systemd-tpm package. These depend on",
                            "    libcrypto and tpm2-tss libraries and provide advanced functionality,",
                            "    so splilt into a new package to make the main package lighter",
                            "  * Note new package split in NEWS",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 24 Jun 2026 22:15:24 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, fixed in Debian:",
                            "    - d/control: Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      [ Fixed in Debian by restricting the build profiles ]",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 19 Jun 2026 16:06:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/control: do not build systemd-boot-efi-*-signed-template on ubuntu",
                            "  * lintian-overrides: override error about derivative.ubuntu build",
                            "    profile",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Update upstream source from tag 'upstream/261' Update to upstream",
                            "    version '261' with Debian dir ae08f24a821ff100eddf715f70140ae1f18bf647",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v261",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 19 Jun 2026 19:29:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped changes, included upstream:",
                            "    - test-fix-check-for-updatectl.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/55ba38cefc",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 16 Jun 2026 15:59:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/261_rc4' Update to upstream",
                            "    version '261~rc4' with Debian dir",
                            "    d6033b9a00158baafde8fe96aa575f68f4776cec",
                            "  * Install new files from v264~rc4",
                            "  * Override bogus Lintian warnings",
                            "  * Drop skip-not-installable autopkgtest restriction, deprecated",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 16 Jun 2026 19:02:25 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153359). Remaining changes:",
                            "    - debian/systemd.postinst:",
                            "      + manually call systemd-tmpfiles --create in postinst",
                            "    - debian/control:",
                            "      + Add Recommends: systemd-resolved to systemd package",
                            "      + Make systemd-cryptsetup Priority: important",
                            "      + Give systemd-resolved Priority: important",
                            "      + Add Recommends: systemd-hwe-hwdb to udev package",
                            "      + Drop Recommends: libnss-myhostname libnss-resolve from systemd-resolved",
                            "      + Do not build systemd-boot-efi-{amd64,arm64}-signed-template",
                            "      + d/control: demote systemd-userdbd to Suggests for libnss-systemd",
                            "    - d/rules: disable bpf support on riscv64 for now (LP #2099864)",
                            "    - d/extra/dbus-1: remove SetLocale restriction from dbus policy (LP #2102028)",
                            "    - Delta for i386:",
                            "      + debian/systemd.install: exclude files that are not built for i386",
                            "      + debian/systemd.manpages: do not ship un-built manpages on i386",
                            "      + debian/rules,debian/control:",
                            "        Do not build with tpm libraries or libqrencode on i386",
                            "      + debian/rules: Remove unneeded efi artifacts on i386 to avoid debugedit errors",
                            "    - debian/libnss-systemd.nss:",
                            "      + Install systemd service after files.",
                            "        As suggested by upstream the systemd NSS service should come just after",
                            "        files",
                            "      - Install after 'compat' too (LP #2125403)",
                            "    - debian/tests:",
                            "      + Drop needs-internet restriction and fix test failures masked by this (LP #2148202)",
                            "      + d/t/upstream: use mkosi from the archive to drop needs-internet",
                            "      + d/t/control: add Depends: libcrypt-dev for upstream test",
                            "    - debian/patches:",
                            "      + switch-root: use MS_MOVE for /run when switchig from initrd",
                            "      + test: use gnuenv to workaround broken --block-signal= (LP #2142900)",
                            "  * Dropped, included in Debian:",
                            "    - d/t/boot-and-services: use coreutils tunable in apparmor test (LP #2125614)",
                            "  * Dropped, included upstream:",
                            "    - lp2148619-units-order-networkd-resolve-hook-After-network-pre.targe.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/37adb410a2",
                            "    - lp2141588/ether-addr-util-introduce-hw_addr_is_valid.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/caeec0de6d",
                            "    - lp2141588/network-generator-support-BOOTIF-and-rd.bootif-0-options.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/cceddc41fd",
                            "    - lp2150773-core-Open-netfilter-socket-only-when-needed.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4a11c5edeb",
                            "    - lp2143010_tag_kfd_accel.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/e30c044c23",
                            "    - test-do-not-use-nanoseconds-width-specifier-in-date-comma.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/da18a5cfd6",
                            "    - lp2077538/xaccess-Rework-from-boolean-into-a-list-of-tags.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/1f7f2bc610",
                            "    - lp2077538/rules-Tag-DRM-render-nodes-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/753341a221",
                            "    - lp2077538/udev-Grant-sessions-access-to-devices-tagged-with-xaccess.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/5a198ad6f8",
                            "    - lp2077538/login-Add-XDG_SESSION_EXTRA_DEVICE_ACCESS-variable-for-ad.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/87840e144b",
                            "    - lp2077538/udev-Tag-GPU-render-nodes-as-xaccess-render.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/2f5279d34b",
                            "    - lp2077538/udev-Trigger-uaccess-builtin-on-xaccess-prefix.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/d0ad8f1175",
                            "    - lp2145027/socket-util-filter-out-VMADDR_CID_ANY-in-vsock_get_local_.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/83359c4da0",
                            "    - lp2145027/ssh-proxy-return-an-error-if-user-supplies-VMADDR_CID_ANY.patch.",
                            "      Applied upstream: https://github.com/systemd/systemd/commit/4341ba091d",
                            "  * Dropped, no longer needed:",
                            "    - lp2141588/network-generator-initramfs-tools-compat-for-empty-DHCP-type.patch.",
                            "      This was a temporary downstream patch for 26.04 LTS only.",
                            "    - tmpfiles-remove-duplicate-run-lock-definition.patch.",
                            "      The patched file is no longer shipped, as it is guarded behind",
                            "      -Dcompat-sysv-interfaces.",
                            "    - lp2077538/Move-new-symbol-out-of-public-library.patch.",
                            "      No longer needed since relevant patches are included in new upstream",
                            "      version.",
                            "    - test-skip-TEST-50-DISSECT.dissect.patch.",
                            "      Test passes now.",
                            "    - lp2136413-test-skip-TEST-13-NSPAWN.machined.patch.",
                            "      Test passes now.",
                            "    - d/libnss-systemd.preinst: drop no longer needed migration.",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/systemd.preinst: Reinstate upgrade workaround (LP #2144032)\".",
                            "      Upgrades to stonking onward will be from at least resolute, hence this",
                            "      can be dropped now.",
                            "    - Revert \"d/control: Add missing dh-dlopenlibdeps to b-d\".",
                            "      Unnecessary delta.",
                            "    - d/t/control: drop i386 delta.",
                            "      We don't care about the i386 tests, and they are beyond broken there, so",
                            "      there is no need to carry this delta.",
                            "    - d/t/control: drop extra udev depends",
                            "    - d/t/control: drop gdm3 arch restriction delta",
                            "  * New changes:",
                            "    - test: fix check for updatectl",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153359
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Fri, 12 Jun 2026 10:01:30 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add ${dlopen:Depends} placeholder to all packages shipping ELF",
                            "    binaries",
                            "  * Drop now-autogenerated dlopen recommends/suggests",
                            "  * Update upstream source from tag 'upstream/261_rc3' Update to upstream",
                            "    version '261~rc3' with Debian dir",
                            "    59e0c1c8fc3108a25d35e810f181ffad2c509246",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 04 Jun 2026 12:37:51 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Clean up autovt@ alias on purge. (Closes: #1137522)",
                            "  * Workaround piuparts issue with / permissions. (Closes: #1137429)",
                            "  * Update upstream source from tag 'upstream/261_rc2' Update to upstream",
                            "    version '261~rc2' with Debian dir",
                            "    5514a46d042723c403871455547bb889f465f396",
                            "  * Drop patches, all merged upstream",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc2-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 26 May 2026 22:10:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * d/t/control: pull libfdisk-dev for test suites. It will be a dlopen",
                            "    library soon",
                            "  * d/t/control: pull libmicrohttpd-dev for unit-tests suite. It will be a",
                            "    dlopen library soon",
                            "  * autopkgtest: add dependency on procps (Closes: #1136595)",
                            "  * Conflict with sysuser-helper. Incompatible implementation specific for",
                            "    runit, make the systemd package conflict with it to ensure it's never",
                            "    installed in the default setup",
                            "  * Downgrade dependency on dbus to recommends in sd-container. This",
                            "    package is useful in the initrd, and dbus is no longer a hard",
                            "    requirement for nspawn",
                            "  * Update upstream source from tag 'upstream/261_rc1' Update to upstream",
                            "    version '261~rc1' with Debian dir",
                            "    dab9908c937b5e70158151b2bbec44d40817023e",
                            "  * Bump Standards-version to 4.7.4, no changes",
                            "  * Install new files for upstream release",
                            "  * Backport patch to fix unit test in gitlab CI",
                            "  * Update symbols file for new version",
                            "  * Backport patch to skip test-pressure in autopkgtest",
                            "  * Force linking against libm. Programs linking against libsystemd0.so",
                            "    crash due to libm ifunc shenanigans when the linking was removed, so",
                            "    force it back. This makes every binary link against libm rather than",
                            "    just libsystemd.so.",
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/t/boot-and-services: use coreutils tunable in apparmor test (LP:",
                            "    #2125614)",
                            "",
                            "  [ Alexandre Detiste ]",
                            "  * use dh-cruft to register & purge volatile files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "261~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2125614
                        ],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Sat, 23 May 2026 12:02:22 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add lpadmin group to basic.conf sysusers.d as requested by CUPS",
                            "    maintainer",
                            "  * Install basic.conf in sd-standalone-sysusers package",
                            "  * Update upstream source from tag 'upstream/260.1' Update to upstream",
                            "    version '260.1' with Debian dir",
                            "    38d56d2e92a70e3fb25e78976e8b0382e2b1a70a",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Mon, 23 Mar 2026 13:27:09 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Luca Boccassi ]",
                            "  * Switch from libselinux1-dev to libselinux-dev",
                            "  * Update upstream source from tag 'upstream/260' Update to upstream",
                            "    version '260' with Debian dir ffda0e8c4d24fb5963cbd3123c86a0047d3d0856",
                            "    For more information, see:",
                            "    https://github.com/systemd/systemd/releases/tag/v260",
                            "",
                            "  [ Michael Biebl ]",
                            "  * Do not run \"systemctl enable getty@.service\" unconditionally. This",
                            "    creates autovt@.service and getty@tty1.service which conflicts with",
                            "    kmscon. So do not run it on every upgrade but only on new installs and",
                            "    as a one-time upgrade for versions older than v260. (Closes: #1130765)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Tue, 17 Mar 2026 20:10:01 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc4' Update to upstream",
                            "    version '260~rc4' with Debian dir",
                            "    12b11c935aadac455a5c179ea9e18eeefc79011d",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Fri, 13 Mar 2026 23:11:28 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update upstream source from tag 'upstream/260_rc3' Update to upstream",
                            "    version '260~rc3' with Debian dir",
                            "    f6c43648041c7fb3cf25ec3a0ff83157bcbf9c17",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862",
                            "  * Really enable getty@ via packaging scriptlets (Closes: #1130457)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Thu, 12 Mar 2026 18:19:48 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove build-depend on rsync, meson is new enough",
                            "  * Enable getty@ via packaging scriptlets, not static anymore (Closes:",
                            "    #1129276)",
                            "  * Update upstream source from tag 'upstream/260_rc2' Update to upstream",
                            "    version '260~rc2' with Debian dir",
                            "    9c39b1f4781cb5ab95271453bfa0b453e971da5b",
                            "    Fixes:",
                            "    https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m",
                            "  * Install new files",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc2-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 04 Mar 2026 13:40:07 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * sd-boot-efi: do not pick up hwids, they are shipped by sd-ukify.",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 20:10:27 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Nick Rosbrook ]",
                            "  * d/libsystemd-shared.preinst: refuse to upgrade without unified",
                            "    cgroupv2 hierarchy",
                            "",
                            "  [ Luca Boccassi ]",
                            "  * homed: drop dependency satisfied since bookworm/noble",
                            "  * systemd.postinst: update journal catalog after reexecing managers",
                            "  * initramfs-tools: copy udev link files from",
                            "    /usr/local/lib/systemd/network too (Closes: #1128930)",
                            "  * Update upstream source from tag 'upstream/260_rc1' Update to upstream",
                            "    version '260~rc1' with Debian dir",
                            "    6b709802e9ad49539cd2d746ca50f6ecfec3dde7",
                            "  * Install new files for v260~rc1",
                            "  * Disable remaining deprecated sysv interfaces",
                            "  * Update symbols file for v260~rc1",
                            "  * Drop unused Lintian overrides",
                            ""
                        ],
                        "package": "systemd",
                        "version": "260~rc1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Luca Boccassi <bluca@debian.org>",
                        "date": "Wed, 25 Feb 2026 19:20:58 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/gbp.conf: update for stonking",
                            "  * core: Open netfilter socket only when needed (LP: #2150773)",
                            "  * units: order networkd resolve hook After=network-pre.target (LP: #2148619)",
                            ""
                        ],
                        "package": "systemd",
                        "version": "259.5-0ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150773,
                            2148619
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Wed, 20 May 2026 16:19:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "wget",
                "from_version": {
                    "source_package_name": "wget",
                    "source_package_version": "1.25.0-2ubuntu4",
                    "version": "1.25.0-2ubuntu4"
                },
                "to_version": {
                    "source_package_name": "wget",
                    "source_package_version": "1.25.0-3ubuntu1",
                    "version": "1.25.0-3ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-58469",
                        "url": "https://ubuntu.com/security/CVE-2026-58469",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58470",
                        "url": "https://ubuntu.com/security/CVE-2026-58470",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58471",
                        "url": "https://ubuntu.com/security/CVE-2026-58471",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58472",
                        "url": "https://ubuntu.com/security/CVE-2026-58472",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15146",
                        "url": "https://ubuntu.com/security/CVE-2026-15146",
                        "cve_description": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-10 19:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58472",
                        "url": "https://ubuntu.com/security/CVE-2026-58472",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58469",
                        "url": "https://ubuntu.com/security/CVE-2026-58469",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58470",
                        "url": "https://ubuntu.com/security/CVE-2026-58470",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58471",
                        "url": "https://ubuntu.com/security/CVE-2026-58471",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58472",
                        "url": "https://ubuntu.com/security/CVE-2026-58472",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163536,
                    2163754
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58469",
                                "url": "https://ubuntu.com/security/CVE-2026-58469",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58470",
                                "url": "https://ubuntu.com/security/CVE-2026-58470",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58471",
                                "url": "https://ubuntu.com/security/CVE-2026-58471",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58472",
                                "url": "https://ubuntu.com/security/CVE-2026-58472",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2163536). Remaining changes:",
                            "    - d/rules: pass --with-ssl=openssl",
                            "    - d/p/wget-maybe-prepend-scheme-only-in-verbose-mode: Print message only in",
                            "      verbose mode (LP #2122484).",
                            "    - SECURITY UPDATE: Buffer overflow in metalink.",
                            "      + debian/patches/CVE-2026-58469.patch: Fix buffer overflow in",
                            "        src/metalink.c",
                            "      + CVE-2026-58469",
                            "    - SECURITY UPDATE: Integer overflow in http",
                            "      + debian/patches/CVE-2026-58470.patch: Fix integer overflow in src/http.c",
                            "      + CVE-2026-58470",
                            "    - SECURITY UPDATE: Buffer overflow in convert_fname.",
                            "      + debian/patches/CVE-2026-58471.patch: Fix buffer overflow in src/url.c",
                            "      + CVE-2026-58471",
                            "    - SECURITY UPDATE: Integer and buffer overflow in html_quote_string.",
                            "      + debian/patches/CVE-2026-58472.patch: Fix integer+buffer overflow in",
                            "        src/convert.c",
                            "      + CVE-2026-58472",
                            "    - SECURITY REGRESSION: Incomplete fix for CVE-2026-58472 (LP #2163754)",
                            "      + debian/patches/CVE-2026-58472-post1.patch: Fix buffer overflow in",
                            "        src/convert.c",
                            ""
                        ],
                        "package": "wget",
                        "version": "1.25.0-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163536
                        ],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 17:45:24 -0700"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15146",
                                "url": "https://ubuntu.com/security/CVE-2026-15146",
                                "cve_description": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-10 19:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * patch from upstream git to fix CVE-2026-15146 a problem with IP validation in FTP PASV. closes: Bug#1142284",
                            ""
                        ],
                        "package": "wget",
                        "version": "1.25.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Noël Köthe <noel@debian.org>",
                        "date": "Fri, 24 Jul 2026 15:53:14 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58472",
                                "url": "https://ubuntu.com/security/CVE-2026-58472",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY REGRESSION: Incomplete fix for CVE-2026-58472 (LP: #2163754)",
                            "    - debian/patches/CVE-2026-58472-post1.patch: Fix buffer overflow in",
                            "      src/convert.c",
                            ""
                        ],
                        "package": "wget",
                        "version": "1.25.0-2ubuntu7",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163754
                        ],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:56:06 -0600"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58469",
                                "url": "https://ubuntu.com/security/CVE-2026-58469",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58470",
                                "url": "https://ubuntu.com/security/CVE-2026-58470",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58471",
                                "url": "https://ubuntu.com/security/CVE-2026-58471",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58472",
                                "url": "https://ubuntu.com/security/CVE-2026-58472",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Buffer overflow in metalink.",
                            "    - debian/patches/CVE-2026-58469.patch: Fix buffer overflow in",
                            "      src/metalink.c",
                            "    - CVE-2026-58469",
                            "  * SECURITY UPDATE: Integer overflow in http",
                            "    - debian/patches/CVE-2026-58470.patch: Fix integer overflow in src/http.c",
                            "    - CVE-2026-58470",
                            "  * SECURITY UPDATE: Buffer overflow in convert_fname.",
                            "    - debian/patches/CVE-2026-58471.patch: Fix buffer overflow in src/url.c",
                            "    - CVE-2026-58471",
                            "  * SECURITY UPDATE: Integer and buffer overflow in html_quote_string.",
                            "    - debian/patches/CVE-2026-58472.patch: Fix integer+buffer overflow in",
                            "      src/convert.c",
                            "    - CVE-2026-58472",
                            ""
                        ],
                        "package": "wget",
                        "version": "1.25.0-2ubuntu6",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Fri, 10 Jul 2026 17:22:16 -0600"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "wireless-regdb",
                "from_version": {
                    "source_package_name": "wireless-regdb",
                    "source_package_version": "2026.02.04-0ubuntu1",
                    "version": "2026.02.04-0ubuntu1"
                },
                "to_version": {
                    "source_package_name": "wireless-regdb",
                    "source_package_version": "2026.05.30-0ubuntu1",
                    "version": "2026.05.30-0ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2163172
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 2026.05.30 (LP: #2163172)",
                            "    - debian/control: Exchange python3-m2crypto build dependency for",
                            "      python3-cryptography",
                            ""
                        ],
                        "package": "wireless-regdb",
                        "version": "2026.05.30-0ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163172
                        ],
                        "author": "Jacob Martin <jacob.martin@canonical.com>",
                        "date": "Mon, 10 Aug 2026 10:02:11 -0500"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "xkb-data",
                "from_version": {
                    "source_package_name": "xkeyboard-config",
                    "source_package_version": "2.47-1",
                    "version": "2.47-1"
                },
                "to_version": {
                    "source_package_name": "xkeyboard-config",
                    "source_package_version": "2.48-1",
                    "version": "2.48-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * control: Add Conflicts on keyboards-rg (Closes: #1133239)",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "xkeyboard-config",
                        "version": "2.48-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <tjaalton@debian.org>",
                        "date": "Wed, 05 Aug 2026 10:41:18 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "added": {
        "deb": [
            {
                "name": "curl",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "curl",
                    "source_package_version": "8.20.0-2ubuntu3",
                    "version": "8.20.0-2ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-8932",
                        "url": "https://ubuntu.com/security/CVE-2026-8932",
                        "cve_description": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-07-03 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153275
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-8932",
                                "url": "https://ubuntu.com/security/CVE-2026-8932",
                                "cve_description": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-07-03 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Authentication Bypass in connection reuse.",
                            "    - debian/patches/CVE-2026-8932.patch: Fix incomplete mTLS config in",
                            "      lib/ldap.c, lib/urldata.h, lib/vssh/libssh.c, lib/vssh/libssh2.c,",
                            "      lib/vtls/gtls.c, lib/vtls/mbedtls.c, lib/vtls/openssl.c,",
                            "      lib/vtls/rustls.c, lib/vtls/schannel.c, lib/vtls/vtls.c,",
                            "      lib/vtls/vtls_scache.c, and lib/vtls/wolfssl.c.",
                            "    - CVE-2026-8932",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.20.0-2ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Tue, 08 Sep 2026 12:31:08 -0600"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.20.0-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:19 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153275). Remaining changes:",
                            "    - d/{control,rules}: drop nghttp3 and ngtcp2 dependencies in universe",
                            "    - d/control: don't build-depend on python3-impacket and stunnel on i386",
                            "  * Dropped delta removed earlier:",
                            "    - d/control: do not use gnutls for the curl binary",
                            "      [Dropped in 8.13.0-2]",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.20.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153275
                        ],
                        "author": "Ural Tunaboyu <ural.tunaboyu@canonical.com>",
                        "date": "Fri, 29 May 2026 09:10:13 -0700"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libcurl4t64",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "curl",
                    "source_package_version": "8.20.0-2ubuntu3",
                    "version": "8.20.0-2ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-8932",
                        "url": "https://ubuntu.com/security/CVE-2026-8932",
                        "cve_description": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-07-03 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2153275
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-8932",
                                "url": "https://ubuntu.com/security/CVE-2026-8932",
                                "cve_description": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-07-03 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Authentication Bypass in connection reuse.",
                            "    - debian/patches/CVE-2026-8932.patch: Fix incomplete mTLS config in",
                            "      lib/ldap.c, lib/urldata.h, lib/vssh/libssh.c, lib/vssh/libssh2.c,",
                            "      lib/vtls/gtls.c, lib/vtls/mbedtls.c, lib/vtls/openssl.c,",
                            "      lib/vtls/rustls.c, lib/vtls/schannel.c, lib/vtls/vtls.c,",
                            "      lib/vtls/vtls_scache.c, and lib/vtls/wolfssl.c.",
                            "    - CVE-2026-8932",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.20.0-2ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Tue, 08 Sep 2026 12:31:08 -0600"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.20.0-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:19 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153275). Remaining changes:",
                            "    - d/{control,rules}: drop nghttp3 and ngtcp2 dependencies in universe",
                            "    - d/control: don't build-depend on python3-impacket and stunnel on i386",
                            "  * Dropped delta removed earlier:",
                            "    - d/control: do not use gnutls for the curl binary",
                            "      [Dropped in 8.13.0-2]",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.20.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153275
                        ],
                        "author": "Ural Tunaboyu <ural.tunaboyu@canonical.com>",
                        "date": "Fri, 29 May 2026 09:10:13 -0700"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libldap-common",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "openldap",
                    "source_package_version": "2.6.13+dfsg-1ubuntu3",
                    "version": "2.6.13+dfsg-1ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158806
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "openldap",
                        "version": "2.6.13+dfsg-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 11:06:14 -0700"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "openldap",
                        "version": "2.6.13+dfsg-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:00:29 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2158806). Remaining changes:",
                            "    - Enable AppArmor support:",
                            "      + d/apparmor-profile: add AppArmor profile",
                            "      + d/rules: use dh_apparmor",
                            "      + d/control: Build-Depends on dh-apparmor",
                            "      + d/slapd.README.Debian: add note about AppArmor",
                            "    - Enable ufw support:",
                            "      + d/control: suggest ufw.",
                            "      + d/rules: install ufw profile.",
                            "      + d/slapd.ufw.profile: add ufw profile.",
                            "    - d/{rules,slapd.py}: Add apport hook.",
                            "    - d/t/smbk5pwd: Allow the openldap user to read the Heimdal master",
                            "      key in the smbk5pwd DEP8 test (LP #2004560)",
                            "      [ Partially incorporated by Debian. ]",
                            "    - d/control: make libldap2 depend on libldap-common.",
                            "      (LP #2063161)",
                            "    - d/rules: remove override_dh_auto_build target",
                            "      + dh_auto_build-indep isn't run because of this leftover.",
                            "      + it was removed in debian in 2.6.9+dfsg-1",
                            "    - d/rules: fix dh_apparmor being skipped in -indep for -arch slapd package (LP #2119884)",
                            "    - d/apparmor-profile: add systemd-notify support (LP #2119884)",
                            "    - d/t/slapd: test if running in apparmor enforce mode (LP #2119884)",
                            "    - pbkdf2 changes:",
                            "      + d/p/lp2125685-pbkdf2-configurable-rounds: make iterations configurable (LP #2125685)",
                            "      + d/p/lp2125685-pbkdf2-fix-iteration-arg: fix iteration argument index (LP #2125685)",
                            "        [ The above upstream but unreleased (openldap) ]",
                            "      + d/t/pbkdf2-contrib: test if pbkdf2 hashing rounds are adjustable (LP #2125685)",
                            "  * Dropped changes:",
                            "    - d/t/ppm-contrib: test ppm password quality module (LP #2121816)",
                            "      [ Upstream in 2.6.13+dfsg-1 ]",
                            "    - d/slapd.config: fix infinite loop for invalid initial config (LP #12470)",
                            "      [ Upstream in 2.6.13+dfsg-1 ]",
                            ""
                        ],
                        "package": "openldap",
                        "version": "2.6.13+dfsg-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158806
                        ],
                        "author": "Grayson Wolf <grayson.wolf@canonical.com>",
                        "date": "Mon, 06 Jul 2026 15:09:19 -0400"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libldap2",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "openldap",
                    "source_package_version": "2.6.13+dfsg-1ubuntu3",
                    "version": "2.6.13+dfsg-1ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2158806
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "openldap",
                        "version": "2.6.13+dfsg-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 11:06:14 -0700"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "openldap",
                        "version": "2.6.13+dfsg-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 08:00:29 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2158806). Remaining changes:",
                            "    - Enable AppArmor support:",
                            "      + d/apparmor-profile: add AppArmor profile",
                            "      + d/rules: use dh_apparmor",
                            "      + d/control: Build-Depends on dh-apparmor",
                            "      + d/slapd.README.Debian: add note about AppArmor",
                            "    - Enable ufw support:",
                            "      + d/control: suggest ufw.",
                            "      + d/rules: install ufw profile.",
                            "      + d/slapd.ufw.profile: add ufw profile.",
                            "    - d/{rules,slapd.py}: Add apport hook.",
                            "    - d/t/smbk5pwd: Allow the openldap user to read the Heimdal master",
                            "      key in the smbk5pwd DEP8 test (LP #2004560)",
                            "      [ Partially incorporated by Debian. ]",
                            "    - d/control: make libldap2 depend on libldap-common.",
                            "      (LP #2063161)",
                            "    - d/rules: remove override_dh_auto_build target",
                            "      + dh_auto_build-indep isn't run because of this leftover.",
                            "      + it was removed in debian in 2.6.9+dfsg-1",
                            "    - d/rules: fix dh_apparmor being skipped in -indep for -arch slapd package (LP #2119884)",
                            "    - d/apparmor-profile: add systemd-notify support (LP #2119884)",
                            "    - d/t/slapd: test if running in apparmor enforce mode (LP #2119884)",
                            "    - pbkdf2 changes:",
                            "      + d/p/lp2125685-pbkdf2-configurable-rounds: make iterations configurable (LP #2125685)",
                            "      + d/p/lp2125685-pbkdf2-fix-iteration-arg: fix iteration argument index (LP #2125685)",
                            "        [ The above upstream but unreleased (openldap) ]",
                            "      + d/t/pbkdf2-contrib: test if pbkdf2 hashing rounds are adjustable (LP #2125685)",
                            "  * Dropped changes:",
                            "    - d/t/ppm-contrib: test ppm password quality module (LP #2121816)",
                            "      [ Upstream in 2.6.13+dfsg-1 ]",
                            "    - d/slapd.config: fix infinite loop for invalid initial config (LP #12470)",
                            "      [ Upstream in 2.6.13+dfsg-1 ]",
                            ""
                        ],
                        "package": "openldap",
                        "version": "2.6.13+dfsg-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158806
                        ],
                        "author": "Grayson Wolf <grayson.wolf@canonical.com>",
                        "date": "Mon, 06 Jul 2026 15:09:19 -0400"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libnghttp2-14",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "nghttp2",
                    "source_package_version": "1.70.0-1",
                    "version": "1.70.0-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-27135",
                        "url": "https://ubuntu.com/security/CVE-2026-27135",
                        "cve_description": "nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-18 18:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New release",
                            "  * d/control: update debhelper to 14",
                            ""
                        ],
                        "package": "nghttp2",
                        "version": "1.70.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Tomasz Buchert <tomasz@debian.org>",
                        "date": "Sun, 02 Aug 2026 14:47:03 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New release",
                            ""
                        ],
                        "package": "nghttp2",
                        "version": "1.69.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Tomasz Buchert <tomasz@debian.org>",
                        "date": "Wed, 22 Apr 2026 18:48:44 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-27135",
                                "url": "https://ubuntu.com/security/CVE-2026-27135",
                                "cve_description": "nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-18 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Addresses #1131369 for unstable (CVE-2026-27135)",
                            ""
                        ],
                        "package": "nghttp2",
                        "version": "1.68.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Tomasz Buchert <tomasz@debian.org>",
                        "date": "Sun, 29 Mar 2026 12:59:35 +0200"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libproc2-1",
                "from_version": {
                    "source_package_name": "procps",
                    "source_package_version": "2:4.0.4-9ubuntu1",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "procps",
                    "source_package_version": "2:4.0.6-3ubuntu1",
                    "version": "2:4.0.6-3ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153347
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from Debian unstable (LP: #2153347). Remaining changes:",
                            "    - debian/sysctl.d:",
                            "      + 55-console-messages.conf: stop low-level kernel messages on console.",
                            "      + 55-kernel-hardening.conf: add the kptr_restrict setting",
                            "      + 55-ipv6-privacy.conf: add a file to sysctl.d to apply the defaults",
                            "        for IPv6 privacy extensions for interfaces. (LP #176125, #841353)",
                            "      + 55-magic-sysrq.conf: Disable most magic sysrq by default, allowing",
                            "        critical sync, remount, reboot functions. (LP #194676, #1025467)",
                            "      + 55-network-security.conf: enable rp_filter.",
                            "      + 55-ptrace.conf: describe new PTRACE setting.",
                            "      + 55-zeropage.conf: safe mmap_min_addr value for graceful fall-back",
                            "        for armhf and arm64.",
                            "      + 55-qemu.conf.s390x for qemu.",
                            "      + 55-bufferbloat.conf: set default qdisc to fq_codel",
                            "      + 55-map-count.conf: Increase vm.max_map_count to 1048576",
                            "    - d/t/stack-limit: add basic autopkgtest to validate limits",
                            "    - d/tests: Add basic autopkgtest to validate sysctl-defaults (LP #1962038)",
                            "    - d/t/stack-limit: call 'pgrep systemd' instead of 'pgrep bash'",
                            "      The autopkgtest currently fails because there is no bash session, and",
                            "      pgrep returns non-zero. Use systemd because that will match for pid1.",
                            "    - d/tests: make sysctl-defaults test comprehensive",
                            "    - d/t/test_sysctl_defaults.py: skip test if sysctl key invalid",
                            "    - d/t/control: show all sysctl.d configs before test",
                            "    - d/t/control: make sysctl-defaults test Restrictions: isolation-machine",
                            "      (LP #2115346)",
                            "  * Dropped changes (applied upstream):",
                            "    - d/p/ignore_eaccess.patch: ignore EACCES when opening sysctl file (LP #1903351)",
                            "    - d/p/ignore_erofs.patch: ignore EROFS when opening sysctl file (LP #1419554)",
                            "    - d/p/0010-testsuite-ps-etime-ELAPSED-doesn-t-match-full-format.patch:",
                            "      Fix test failure (FTBFS) in testsuite/ps.test/ps_output.exp due to",
                            "      invalid regex match inside LXD containers.",
                            "    - d/p/lp2120904-openat.patch: utilize file descriptors and openat (LP #2120904)",
                            "    - d/p/lp2120904-nullpointer.patch: fix a race when 'status' is unavailable",
                            "      in /proc/<pid> resulting in NULL pointer (LP #2120904)",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153347
                        ],
                        "author": "Carter Hawthorne <carter.hawthorne@canonical.com>",
                        "date": "Thu, 13 Aug 2026 15:27:14 -0700"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Break & Replace manpages-zh Closes: #1141435",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Tue, 28 Jul 2026 21:10:17 +1000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Mattias Ellert ]",
                            "  * Fix compilation and installation on GNU/Hurd (Closes: #1138217)",
                            "",
                            "  [ Craig Small ]",
                            "  * Only include linux-sysctl-defaults on Linux systems Closes: #1129174",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Tue, 30 Jun 2026 19:23:38 +1000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            "    library and w: Don't check for sd_booted Closes: #1108549",
                            "    pgrep: Match on process ID Closes: #612146",
                            "    pgrep: Add --quiet option",
                            "    pmap: add -k option to print raw names from kernel",
                            "    ps.1: cols and collums alias width option Closes: #926361",
                            "    ps.1: Add format equivalents Closes: #925437",
                            "    slabtop: Increase column width Closes: #959375",
                            "    sysctl: Use options after --system  Closes: #978989",
                            "    w: Add terminal mode to show all terminal sessions",
                            "    w: Use process TTY as backup for user TTY Closes: #1080335",
                            "    w: Use correct return value for sd_get_sessions Closes: #1068904",
                            "    watch: Add --follow option Closes: #469156",
                            "    watch: 256 color support",
                            "    watch.1: Warn about -d permanent option Closes: #883638",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.6-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Thu, 29 Jan 2026 21:34:30 +1100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            "    library: Recover from meminfo seek using LXC Closes: #1072831",
                            "    ps.1: Update man page to standards Closes: #1081801",
                            "    snice: Minor fix for help screen Closes: #1086441",
                            "    sysctl: --all skips stat_refresh Closes: #978688",
                            "    vmstat.8: si/so are changed by --unit Closes: #1061944",
                            "    w.1: Note utmp is for non-systemd Closes: #1080333",
                            "    w.1: Update man page to standards Closes: #1077367",
                            "    w: Don't segfault with -s option",
                            "    watch.1: --chgexit only works for visible changes Closes: #729569",
                            "  * Remove ps_not_path_max patch as upstream has it",
                            "  * Remove makefile_w_link_systemd as its fixed upstream",
                            ""
                        ],
                        "package": "procps",
                        "version": "2:4.0.5-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Craig Small <csmall@debian.org>",
                        "date": "Thu, 19 Dec 2024 13:09:01 +1100"
                    }
                ],
                "notes": "libproc2-1 version '2:4.0.6-3ubuntu1' (source package procps version '2:4.0.6-3ubuntu1') was added. libproc2-1 version '2:4.0.6-3ubuntu1' has the same source package name, procps, as removed package libproc2-0. As such we can use the source package version of the removed package, '2:4.0.4-9ubuntu1', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "libsasl2-2",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "cyrus-sasl2",
                    "source_package_version": "2.1.28+dfsg1-11ubuntu2",
                    "version": "2.1.28+dfsg1-11ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153186
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:30 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153186). Remaining changes:",
                            "    - Disable postgresql support in the libsasl2-modules-sql on i386 since",
                            "      postgresql is no longer build for that architecture (LP #2142320):",
                            "      + d/control: don't build-depend on libpq-dev on i386",
                            "      + d/rules: only enable pgsql if not on i386",
                            "    - d/t/saslauthd: refactor how tests are run, and run them a second time",
                            "      with a new socket path (LP #2098601)",
                            "  * Added:",
                            "    - d/sasl2-bin.saslauthd.service: simpler way to have saslauthd honor the",
                            "      settings from /etc/default/saslauthd (part of LP #2098601 adapted to the",
                            "      new debian upload)",
                            "  * Dropped:",
                            "    - d/sasl2-bin.saslauthd.service: drop hardcoded PIDFile",
                            "      [In 2.1.28+dfsg1-11]",
                            "    - d/rules: add -std=gnu17 to build it with gcc-15 on questing",
                            "      (LP #2124256)",
                            "      [Code fix in 2.1.28+dfsg1-10]",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153186
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 01 Jul 2026 09:58:30 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "",
                            "  [ Praveen Arimbrathodiyil ]",
                            "  * Update file sasl2-bin.saslauthd.service",
                            "",
                            "  [ Peter Wienemann ]",
                            "  * d/rules: Build and install saslcache (Closes: #1132010)",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Germann <bage@debian.org>",
                        "date": "Sat, 04 Apr 2026 21:56:58 +0200"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libsasl2-modules-db",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "cyrus-sasl2",
                    "source_package_version": "2.1.28+dfsg1-11ubuntu2",
                    "version": "2.1.28+dfsg1-11ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2153186
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:30 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2153186). Remaining changes:",
                            "    - Disable postgresql support in the libsasl2-modules-sql on i386 since",
                            "      postgresql is no longer build for that architecture (LP #2142320):",
                            "      + d/control: don't build-depend on libpq-dev on i386",
                            "      + d/rules: only enable pgsql if not on i386",
                            "    - d/t/saslauthd: refactor how tests are run, and run them a second time",
                            "      with a new socket path (LP #2098601)",
                            "  * Added:",
                            "    - d/sasl2-bin.saslauthd.service: simpler way to have saslauthd honor the",
                            "      settings from /etc/default/saslauthd (part of LP #2098601 adapted to the",
                            "      new debian upload)",
                            "  * Dropped:",
                            "    - d/sasl2-bin.saslauthd.service: drop hardcoded PIDFile",
                            "      [In 2.1.28+dfsg1-11]",
                            "    - d/rules: add -std=gnu17 to build it with gcc-15 on questing",
                            "      (LP #2124256)",
                            "      [Code fix in 2.1.28+dfsg1-10]",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2153186
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 01 Jul 2026 09:58:30 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload",
                            "",
                            "  [ Praveen Arimbrathodiyil ]",
                            "  * Update file sasl2-bin.saslauthd.service",
                            "",
                            "  [ Peter Wienemann ]",
                            "  * d/rules: Build and install saslcache (Closes: #1132010)",
                            ""
                        ],
                        "package": "cyrus-sasl2",
                        "version": "2.1.28+dfsg1-11",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Germann <bage@debian.org>",
                        "date": "Sat, 04 Apr 2026 21:56:58 +0200"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libssh2-1t64",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "libssh2",
                    "source_package_version": "1.11.1-4ubuntu3",
                    "version": "1.11.1-4ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-66032",
                        "url": "https://ubuntu.com/security/CVE-2026-66032",
                        "cve_description": "libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-24 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-66033",
                        "url": "https://ubuntu.com/security/CVE-2026-66033",
                        "cve_description": "libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-24 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-66035",
                        "url": "https://ubuntu.com/security/CVE-2026-66035",
                        "cve_description": "libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-24 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5805",
                        "url": "https://ubuntu.com/security/CVE-2026-5805",
                        "cve_description": "",
                        "cve_priority": "n/a",
                        "cve_public_date": ""
                    },
                    {
                        "cve": "CVE-2026-58051",
                        "url": "https://ubuntu.com/security/CVE-2026-58051",
                        "cve_description": "libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-28 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58050",
                        "url": "https://ubuntu.com/security/CVE-2026-58050",
                        "cve_description": "libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-28 02:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-66032",
                                "url": "https://ubuntu.com/security/CVE-2026-66032",
                                "cve_description": "libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-24 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-66033",
                                "url": "https://ubuntu.com/security/CVE-2026-66033",
                                "cve_description": "libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-24 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-66035",
                                "url": "https://ubuntu.com/security/CVE-2026-66035",
                                "cve_description": "libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-24 17:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: double-free vulnerability in sftp_open()",
                            "    - debian/patches/CVE-2026-66032.patch: Prevent dangling pointer by",
                            "      nullifying data in src/sftp.c.",
                            "    - CVE-2026-66032",
                            "  * SECURITY UPDATE: pre-authentication integer underflow vulnerability",
                            "    - debian/patches/CVE-2026-66033.patch: fix potential OOB read/write with",
                            "      AES-GCM in `ssh2_cipher_crypt()` in src/openssl.c.",
                            "    - CVE-2026-66033",
                            "  * SECURITY UPDATE: pre-authentication heap buffer overflow vulnerability",
                            "    - debian/patches/CVE-2026-66035.patch: transport: fix potential heap",
                            "      overflow on ETM decrypt in src/transport.c.",
                            "    - CVE-2026-66035",
                            ""
                        ],
                        "package": "libssh2",
                        "version": "1.11.1-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Wed, 02 Sep 2026 07:45:31 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "libssh2",
                        "version": "1.11.1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:50:24 +0000"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-5805",
                                "url": "https://ubuntu.com/security/CVE-2026-5805",
                                "cve_description": "",
                                "cve_priority": "n/a",
                                "cve_public_date": ""
                            },
                            {
                                "cve": "CVE-2026-58051",
                                "url": "https://ubuntu.com/security/CVE-2026-58051",
                                "cve_description": "libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-28 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58050",
                                "url": "https://ubuntu.com/security/CVE-2026-58050",
                                "cve_description": "libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-28 02:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Multiple security issues in publickey",
                            "    - debian/patches/CVE-2026-5805x-pre1.patch: fix potential arbitrary free",
                            "      in libssh2_publickey_list_fetch().",
                            "    - debian/patches/CVE-2026-5805x-pre2.patch: fix potential multiplication",
                            "      overflow in 32-bit libssh2_publickey_list_fetch().",
                            "    - debian/patches/CVE-2026-5805x-pre3.patch: cap packet size in",
                            "      publickey_packet_receive().",
                            "    - debian/patches/CVE-2026-5805x-pre4.patch: fix leaks when",
                            "      publickey_response_success() received <8 bytes.",
                            "    - debian/patches/CVE-2026-5805x-pre5.patch: fix potential OOB read in",
                            "      publickey_response_success().",
                            "    - debian/patches/CVE-2026-58051.patch: fix potential OOB read in",
                            "      libssh2_publickey_list_fetch().",
                            "    - debian/patches/CVE-2026-5805x-pre6.patch: fix potential OOB read.",
                            "    - debian/patches/CVE-2026-5805x-pre7.patch: flatten bounds check if blocks",
                            "      (tidy-up).",
                            "    - debian/patches/CVE-2026-5805x-pre8.patch: rework bounds checks to avoid",
                            "      pointer comparisons.",
                            "    - debian/patches/CVE-2026-58050.patch: cap variable-length packet element",
                            "      sizes.",
                            "    - CVE-2026-58050",
                            "    - CVE-2026-58051",
                            ""
                        ],
                        "package": "libssh2",
                        "version": "1.11.1-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Tue, 07 Jul 2026 14:23:05 -0400"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "libssl4",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "openssl",
                    "source_package_version": "4.0.1-1ubuntu4",
                    "version": "4.0.1-1ubuntu4"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2163146,
                    2158026,
                    2158026
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/default-configuration-read-dropins-and-crypto-config.patch:",
                            "    partially restore patch, needed by src:crypto-policies",
                            "    (LP: #2163146)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163146
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 12 Aug 2026 15:20:38 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert \"Add Depends on libjitterentropy3-dev, zlib1g-dev, and libzstd-dev.",
                            "    (LP: #2158026)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158026
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Mon, 10 Aug 2026 11:49:51 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add Depends on libjitterentropy3-dev, zlib1g-dev, and libzstd-dev.",
                            "    libcrypto.pc declares these as static private dependencies",
                            "    (Libs.private) but libssl-dev did not pull them in, breaking static",
                            "    linking against libcrypto. (LP: #2158026)",
                            ""
                        ],
                        "package": "openssl",
                        "version": "4.0.1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158026
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Mon, 03 Aug 2026 16:49:15 +0200"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-image-7.3.0-5-generic",
                "from_version": {
                    "source_package_name": "linux-signed",
                    "source_package_version": "7.0.0-14.14",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux-signed",
                    "source_package_version": "7.3.0-5.5",
                    "version": "7.3.0-5.5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1786013,
                    1786013,
                    1786013,
                    1786013,
                    1786013,
                    1786013,
                    1786013,
                    1786013,
                    1786013,
                    1786013,
                    1786013,
                    1786013,
                    1786013,
                    1786013
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.3.0-5.5",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            ""
                        ],
                        "package": "linux-signed",
                        "version": "7.3.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 14 Sep 2026 11:39:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry; drop unstable suffix",
                            ""
                        ],
                        "package": "linux-signed",
                        "version": "7.3.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Canonical Kernel Team <kernel-team@lists.ubuntu.com>",
                        "date": "Mon, 14 Sep 2026 10:19:01 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.3.0-4.4",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            ""
                        ],
                        "package": "linux-signed-unstable",
                        "version": "7.3.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 07 Sep 2026 12:34:47 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.3.0-3.3",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            ""
                        ],
                        "package": "linux-signed-unstable",
                        "version": "7.3.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 07 Sep 2026 08:58:40 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.3.0-2.2",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            ""
                        ],
                        "package": "linux-signed-unstable",
                        "version": "7.3.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 31 Aug 2026 11:50:55 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.3.0-1.1",
                            ""
                        ],
                        "package": "linux-signed-unstable",
                        "version": "7.3.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Fri, 28 Aug 2026 15:02:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-signed-unstable",
                        "version": "7.3.0-0.0+1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Fri, 28 Aug 2026 11:58:34 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry: rename to linux-signed-unstable and bump to 7.3.0",
                            "    (major-version bootstrap for the unstable family)",
                            ""
                        ],
                        "package": "linux-signed-unstable",
                        "version": "7.3.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 25 Aug 2026 10:03:26 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-5.5",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            ""
                        ],
                        "package": "linux-signed",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 22:11:16 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry; drop unstable suffix",
                            ""
                        ],
                        "package": "linux-signed",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Canonical Kernel Team <kernel-team@lists.ubuntu.com>",
                        "date": "Tue, 18 Aug 2026 22:09:59 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-4.4",
                            ""
                        ],
                        "package": "linux-signed-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:50:19 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-3.3",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Packaging] Re-enable signing for s390x",
                            ""
                        ],
                        "package": "linux-signed-unstable",
                        "version": "7.2.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Thu, 13 Aug 2026 22:02:22 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-2.2",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            ""
                        ],
                        "package": "linux-signed-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:30:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.2.0-1.1",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            ""
                        ],
                        "package": "linux-signed-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:08:30 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            ""
                        ],
                        "package": "linux-signed-unstable",
                        "version": "7.2.0-0.0+1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:38 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry: rename to linux-signed-unstable and bump to 7.2.0",
                            "    (major-version bootstrap for the unstable family)",
                            ""
                        ],
                        "package": "linux-signed-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 13:14:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Packaging] disable signing for s390x",
                            ""
                        ],
                        "package": "linux-signed",
                        "version": "7.1.0-5.5+1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Mon, 22 Jun 2026 15:01:10 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-5.5",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            ""
                        ],
                        "package": "linux-signed",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:39:57 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-4.4",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] resync debian/templates",
                            ""
                        ],
                        "package": "linux-signed",
                        "version": "7.1.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Sat, 06 Jun 2026 14:34:24 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-3.3",
                            ""
                        ],
                        "package": "linux-signed",
                        "version": "7.1.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Wed, 03 Jun 2026 20:13:38 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-2.2",
                            ""
                        ],
                        "package": "linux-signed",
                        "version": "7.1.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Wed, 03 Jun 2026 16:03:54 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.1.0-1.1",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] resync debian/templates",
                            "    - [Packaging] update variants",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            ""
                        ],
                        "package": "linux-signed",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:19:26 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux-signed",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:11:52 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.0.0-15.15",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            ""
                        ],
                        "package": "linux-signed",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:05:57 +0200"
                    }
                ],
                "notes": "linux-image-7.3.0-5-generic version '7.3.0-5.5' (source package linux-signed version '7.3.0-5.5') was added. linux-image-7.3.0-5-generic version '7.3.0-5.5' has the same source package name, linux-signed, as removed package linux-image-7.0.0-14-generic. As such we can use the source package version of the removed package, '7.0.0-14.14', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-main-modules-zfs-7.3.0-5-generic",
                "from_version": {
                    "source_package_name": "linux-main-signed",
                    "source_package_version": "7.0.0-14.14+3",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux-main-signed",
                    "source_package_version": "7.3.0-5.5",
                    "version": "7.3.0-5.5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1786013,
                    1786013,
                    1786013,
                    1786013
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "",
                            "  * Miscellaneous upstream changes",
                            "    - Revert \"lmm: Add synthetic dependency for LMM package, to stop early",
                            "      promotion\"",
                            ""
                        ],
                        "package": "linux-main-signed",
                        "version": "7.0.0-14.14+3",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 14 Apr 2026 13:38:00 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/dkms-versions -- update from kernel-versions",
                            "      (main/d2026.04.13)",
                            ""
                        ],
                        "package": "linux-main-signed",
                        "version": "7.0.0-14.14+2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 14 Apr 2026 09:23:27 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/dkms-versions -- update from kernel-versions",
                            "      (main/d2026.04.13)",
                            ""
                        ],
                        "package": "linux-main-signed",
                        "version": "7.0.0-14.14+1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Mon, 13 Apr 2026 20:03:08 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.0.0-14.14",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            "",
                            "  * Miscellaneous upstream changes",
                            "    - Cleanup d/package.config from LRM config options",
                            "    - lmm: cleanup and add copyright notice",
                            "    - lmm: Fix an issue for the in-series copy phase",
                            "    - lmm: Make off_series the default mechanism",
                            "    - lmm: Allow skipping specific DKMS for specific flavours at build time",
                            "    - lmm: move final artifacts from /ubuntu to /kernel",
                            "    - lmm: Fix DKMS build for chroot environments",
                            "    - lmm: Add synthetic dependency for LMM package, to stop early promotion",
                            ""
                        ],
                        "package": "linux-main-signed",
                        "version": "7.0.0-14.14",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Apr 2026 11:36:59 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 7.0.0-13.13",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            "    - [Packaging] debian/dkms-versions -- update from kernel-versions",
                            "      (main/d2026.04.07)",
                            ""
                        ],
                        "package": "linux-main-signed",
                        "version": "7.0.0-13.13",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 08 Apr 2026 06:59:33 +0200"
                    }
                ],
                "notes": "linux-main-modules-zfs-7.3.0-5-generic version '7.3.0-5.5' (source package linux-main-signed version '7.3.0-5.5') was added. linux-main-modules-zfs-7.3.0-5-generic version '7.3.0-5.5' has the same source package name, linux-main-signed, as removed package linux-main-modules-zfs-7.0.0-14-generic. As such we can use the source package version of the removed package, '7.0.0-14.14+3', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-modules-7.3.0-5-generic",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.3.0-5.5",
                    "version": "7.3.0-5.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-47337",
                        "url": "https://ubuntu.com/security/CVE-2026-47337",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47334",
                        "url": "https://ubuntu.com/security/CVE-2026-47334",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47333",
                        "url": "https://ubuntu.com/security/CVE-2026-47333",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47332",
                        "url": "https://ubuntu.com/security/CVE-2026-47332",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47330",
                        "url": "https://ubuntu.com/security/CVE-2026-47330",
                        "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47329",
                        "url": "https://ubuntu.com/security/CVE-2026-47329",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47327",
                        "url": "https://ubuntu.com/security/CVE-2026-47327",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47328",
                        "url": "https://ubuntu.com/security/CVE-2026-47328",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-47326",
                        "url": "https://ubuntu.com/security/CVE-2026-47326",
                        "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-28 19:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2167199,
                    2147533,
                    1786013,
                    1990064,
                    2144679,
                    2142956,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2166675,
                    2166643,
                    2165893,
                    1786013,
                    2163667,
                    2163401,
                    2147533,
                    1990064,
                    2144679,
                    2142956,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2160302,
                    2161304,
                    2160497,
                    1786013,
                    2159617,
                    1786013,
                    2156849,
                    2155837,
                    2146517,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2151747,
                    2148809,
                    2151747,
                    2151747,
                    2151747,
                    1990064,
                    2144679,
                    2142956,
                    2139664,
                    2142956,
                    2141298,
                    2028253,
                    2028253,
                    2102680,
                    2028253,
                    2032602,
                    2154256,
                    1786013,
                    2154174,
                    2152714,
                    2148866,
                    2149808,
                    2148718
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.3.0-5.5 -proposed tracker (LP: #2167199)",
                            "",
                            "  * AA: disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED (LP: #2147533)",
                            "    - [Config] disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.1.0 [24/25]: apparmor: skb: add the ability to use",
                            "      interface in network mediation.",
                            "    - SAUCE: apparmor5.1.0 [25/25]: apparmor: skb: switch to using sk_ctx crit",
                            "      section",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.1.0 [23/25]: apparmor: skb: fix",
                            "      apparmor_secmark_check() when !inet and secmark defined.",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.1.0 [1/25]: apparmor-next: apparmor: fix implicit",
                            "      declaration of function 'decompress_zstd'",
                            "    - SAUCE: apparmor5.1.0 [2/25]: apparmor-next: apparmor: Fix warning:",
                            "      'decompress_zstd' defined but not used",
                            "    - SAUCE: apparmor5.1.0 [3/25]: apparmor-next-next: apparmor: setup slab",
                            "      cache for audit data",
                            "    - SAUCE: apparmor5.1.0 [4/25]: apparmor-next-next: apparmor: add the",
                            "      ability for profiles to have a learning cache",
                            "    - SAUCE: apparmor5.1.0 [5/25]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.1.0 [6/25]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.1.0 [7/25]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.1.0 [8/25]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.1.0 [9/25]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.1.0 [10/25]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [11/25]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [12/25]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.1.0 [14/25]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.1.0 [15/25]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.1.0 [16/25]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.1.0 [17/25]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.1.0 [18/25]: apparmor: mqueue: prevent",
                            "      profile->disconnected double free in aa_free_profile",
                            "    - SAUCE: apparmor5.1.0 [19/25]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.1.0 [22/25]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.1.0 [20/25]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.1.0 [21/25]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.1.0 [13/25]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] enable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "    - SAUCE: apparmor: fix unterminated prompt string in Kconfig",
                            "    - [Packaging] Migrate to pkgconf",
                            "    - SAUCE: Revert \"ceph: move mdsmap.h to fs/ceph/\"",
                            "    - SAUCE: Revert \"Revert \"rfkill: make new event layout opt-in\"\"",
                            "    - SAUCE: Revert \"ACPICA: avoid accessing operands out-of-bounds\"",
                            "    - SAUCE: Revert \"Revert \"net/tls(TLS_SW): Add selftest for 'chunked'",
                            "      sendfile test\"\"",
                            "    - SAUCE: Revert \"net: ena: fix too long default tx interrupt moderation",
                            "      interval\"",
                            "    - SAUCE: Revert \"(no-up) Input: Cypress PS/2 Trackpad simulated",
                            "      multitouch\"",
                            "    - Changes.md: record the seven SAUCE patches dropped for the linux handoff",
                            "    - [Packaging] update Ubuntu.md",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.3.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167199,
                            2147533,
                            1786013,
                            1990064,
                            2144679,
                            2142956,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 14 Sep 2026 11:01:34 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.3.0-4.4 -proposed tracker (LP: #2166675)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - SAUCE: kbuild: fix dtbs_install race when parents are shared",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.3.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166675
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 07 Sep 2026 12:33:31 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.3.0-3.3 -proposed tracker (LP: #2166643)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.3.0-3.3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166643
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 07 Sep 2026 08:57:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.3.0-2.2 -proposed tracker (LP: #2165893)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] updateconfigs after v7.3-rc1 rebase",
                            "    - [Config] Enable RTC_DRV_RZN1 as a module on arm64",
                            "    - [Config] update toolchain-derived symbols for rustc 1.97.1",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.3.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165893
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 31 Aug 2026 12:13:09 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - SAUCE: Revert \"media: ipu-bridge: add TBE20A0 ACPI id for Sony IMX471\"",
                            "    - SAUCE: Revert \"media: ipu-bridge: Support imx471 sensor\"",
                            "    - SAUCE: Revert \"arm64: dts: qcom: sc8280xp-x13s: Enable Venus\"",
                            "    - Changes.md: record the three SAUCE patches dropped after v7.3",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.3.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Fri, 28 Aug 2026 15:01:22 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] debian.master/dkms-versions -- remove dkms-versions",
                            "      (main/d2026.08.19)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.3 rebase",
                            "    - [Config] updateconfigs after v7.3 rebase",
                            "    - [Config] enable new v7.3 drivers as modules",
                            "    - [Config] new feature options for v7.3",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.3.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Fri, 28 Aug 2026 11:50:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.2.0-5.5 -proposed tracker (LP: #2163667)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.2.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163667
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 18 Aug 2026 16:59:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-4.4 -proposed tracker (LP: #2163401)",
                            "",
                            "  * AA: disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED (LP: #2147533)",
                            "    - [Config] disable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.1.0 [60/61]: apparmor: skb: add the ability to use",
                            "      interface in network mediation.",
                            "    - SAUCE: apparmor5.1.0 [61/61]: apparmor: skb: switch to using sk_ctx crit",
                            "      section",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.1.0 [59/61]: apparmor: skb: fix",
                            "      apparmor_secmark_check() when !inet and secmark defined.",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.1.0 [1/61]: apparmor-next: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.1.0 [2/61]: apparmor-next: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.1.0 [3/61]: apparmor-next: apparmor: Initial support",
                            "      for compressed policies",
                            "    - SAUCE: apparmor5.1.0 [4/61]: apparmor-next: apparmor: fix alternate",
                            "      loaders ability to load compressed policy",
                            "    - SAUCE: apparmor5.1.0 [5/61]: apparmor-next: apparmor: replace",
                            "      decompress_zstd() prototype with its entity",
                            "    - SAUCE: apparmor5.1.0 [6/61]: apparmor-next: apparmor: leverage",
                            "      audit_log_n_untrustedstring() when possible",
                            "    - SAUCE: apparmor5.1.0 [7/61]: apparmor-next: apparmor: switch website",
                            "      link to https",
                            "    - SAUCE: apparmor5.1.0 [8/61]: apparmor-next: apparmor: compressed_data",
                            "      not described in aa_get_data_from_compressed",
                            "    - SAUCE: apparmor5.1.0 [9/61]: apparmor-next: apparmor: Fix build failure",
                            "      when ZSTD_DECOMPRESS is not enabled",
                            "    - SAUCE: apparmor5.1.0 [10/61]: apparmor-next: apparmor: fix implicit",
                            "      declaration of function 'decompress_zstd'",
                            "    - SAUCE: apparmor5.1.0 [11/61]: apparmor-next: apparmor: Fix warning:",
                            "      'decompress_zstd' defined but not used",
                            "    - SAUCE: apparmor5.1.0 [12/61]: apparmor-next: apparmor: use",
                            "      SEND_SIG_NOINFO instead of NULL in aa_audit()",
                            "    - SAUCE: apparmor5.1.0 [13/61]: apparmor-next: apparmor: fix cred UAF",
                            "      caused by begin_current_label_crit_section()",
                            "    - SAUCE: apparmor5.1.0 [14/61]: apparmor-next: apparmor: optimize",
                            "      current_label_crit_section() with needput",
                            "    - SAUCE: apparmor5.1.0 [15/61]: apparmor-next: apparmor: fix integer",
                            "      overflow in verify_tags() bounds check",
                            "    - SAUCE: apparmor5.1.0 [16/61]: apparmor-next: apparmor: fix out-of-bounds",
                            "      write when null terminating a label vec",
                            "    - SAUCE: apparmor5.1.0 [17/61]: apparmor-next: apparmor: fix error",
                            "      handling for copy_from_user in policy_update",
                            "    - SAUCE: apparmor5.1.0 [18/61]: apparmor-next: apparmor: make",
                            "      MEDIATES_AF_UNIX its own fn",
                            "    - SAUCE: apparmor5.1.0 [19/61]: apparmor-next: apparmor: refactor network",
                            "      sock mediation in preparation for inet mediation",
                            "    - SAUCE: apparmor5.1.0 [20/61]: apparmor-next: apparmor: push inet",
                            "      mediation into profile callbacks, and improve auditing",
                            "    - SAUCE: apparmor5.1.0 [21/61]: apparmor-next: apparmor: refactor network",
                            "      socket mediation to support compatibility",
                            "    - SAUCE: apparmor5.1.0 [22/61]: apparmor-next: apparmor: move netfilter",
                            "      functions next to the LSM network operations",
                            "    - SAUCE: apparmor5.1.0 [23/61]: apparmor-next: apparmor: move",
                            "      sock_rcv_skb() next to inet_conn_request",
                            "    - SAUCE: apparmor5.1.0 [24/61]: apparmor-next: apparmor: reserve mediation",
                            "      class for packet mediation",
                            "    - SAUCE: apparmor5.1.0 [25/61]: apparmor-next: apparmor: fix unconfined",
                            "      user namespace restriction forced stack",
                            "    - SAUCE: apparmor5.1.0 [26/61]: apparmor-next: apparmor: refactor xattr",
                            "      attachment, to take the file path",
                            "    - SAUCE: apparmor5.1.0 [27/61]: apparmor-next: apparmor: fix race",
                            "      condition in label replacement",
                            "    - SAUCE: apparmor5.1.0 [28/61]: apparmor-next: apparmor: make table entry",
                            "      count last enum for static tables",
                            "    - SAUCE: apparmor5.1.0 [29/61]: apparmor-next: apparmor: fix error debug",
                            "      output in fn_label_build",
                            "    - SAUCE: apparmor5.1.0 [30/61]: apparmor-next: apparmor: mark static",
                            "      tables and structs as read only",
                            "    - SAUCE: apparmor5.1.0 [31/61]: apparmor-next: apparmor: add audit mode to",
                            "      provide a mechanism to silence complain messages",
                            "    - SAUCE: apparmor5.1.0 [32/61]: apparmor-next: apparmor: fix auditing of",
                            "      mount binary data",
                            "    - SAUCE: apparmor5.1.0 [33/61]: apparmor-next: apparmor: refactory mount",
                            "      to use check_perms",
                            "    - SAUCE: apparmor5.1.0 [34/61]: apparmor-next: apparmor: drop use of",
                            "      _confined variant for iteration",
                            "    - SAUCE: apparmor5.1.0 [35/61]: apparmor-next: apparmor: constify aa_perms",
                            "      parameters that are read-only",
                            "    - SAUCE: apparmor5.1.0 [36/61]: apparmor-next: apparmor: constify",
                            "      aa_profile parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [37/61]: apparmor-next: apparmor: constify aa_dfa",
                            "      parameters on read-only compute paths",
                            "    - SAUCE: apparmor5.1.0 [38/61]: apparmor-next: apparmor: constify aa_label",
                            "      parameters on read-only query helpers",
                            "    - SAUCE: apparmor5.1.0 [39/61]: apparmor-next-next: apparmor: setup slab",
                            "      cache for audit data",
                            "    - SAUCE: apparmor5.1.0 [40/61]: apparmor-next-next: apparmor: add the",
                            "      ability for profiles to have a learning cache",
                            "    - SAUCE: apparmor5.1.0 [41/61]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.1.0 [42/61]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.1.0 [43/61]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.1.0 [44/61]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.1.0 [45/61]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.1.0 [46/61]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [47/61]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.1.0 [48/61]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.1.0 [50/61]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.1.0 [51/61]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.1.0 [52/61]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.1.0 [53/61]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.1.0 [54/61]: apparmor: mqueue: prevent",
                            "      profile->disconnected double free in aa_free_profile",
                            "    - SAUCE: apparmor5.1.0 [55/61]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.1.0 [58/61]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.1.0 [56/61]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.1.0 [57/61]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.1.0 [49/61]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Drop DEP-8 tests from kernel packages (LP: #2160302)",
                            "    - [Packaging] Drop DEP-8 tests from kernel source",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] updateconfigs after rebase to v7.2-rc6",
                            "    - [Config] Enable SECURITY_APPARMOR_COMPRESSED_POLICY",
                            "    - [Config] toolchain version update",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-4.4",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163401,
                            2147533,
                            1990064,
                            2144679,
                            2142956,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602,
                            2160302
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Fri, 14 Aug 2026 15:46:26 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-2.2 -proposed tracker (LP: #2161304)",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Changes.md: dropping reboot=pci quirks for sandy bridge hw",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-2.2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161304
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Tue, 21 Jul 2026 13:29:36 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-1.1 -proposed tracker (LP: #2160497)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2160497,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 13 Jul 2026 14:07:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux-unstable: 7.2.0-0.0 -proposed tracker (LP: #2159617)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "    - [Packaging] update annotations scripts",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.2-rc1 rebase",
                            "    - [Config] updateconfigs after v7.2-rc1 rebase",
                            "    - SAUCE: thunderbolt: fixup move of pci_device out of tb_nhi",
                            "    - [Packaging] integrate SBOM generation into the build",
                            "    - SAUCE: fixup s/strncpy/strscpy/ in compat_uts_machine= kernel command",
                            "      line override",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: igh-ecat: replace strncpy with strscpy",
                            "    - SAUCE: media: venus: core: guard SC8280XP/SM8350 resources behind !IRIS",
                            ""
                        ],
                        "package": "linux-unstable",
                        "version": "7.2.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2159617,
                            1786013
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Mon, 06 Jul 2026 14:01:01 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-47337",
                                "url": "https://ubuntu.com/security/CVE-2026-47337",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47334",
                                "url": "https://ubuntu.com/security/CVE-2026-47334",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47333",
                                "url": "https://ubuntu.com/security/CVE-2026-47333",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47332",
                                "url": "https://ubuntu.com/security/CVE-2026-47332",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47330",
                                "url": "https://ubuntu.com/security/CVE-2026-47330",
                                "cve_description": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47329",
                                "url": "https://ubuntu.com/security/CVE-2026-47329",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47327",
                                "url": "https://ubuntu.com/security/CVE-2026-47327",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47328",
                                "url": "https://ubuntu.com/security/CVE-2026-47328",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-47326",
                                "url": "https://ubuntu.com/security/CVE-2026-47326",
                                "cve_description": "Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-28 19:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-5.5 -proposed tracker (LP: #2156849)",
                            "",
                            "  * MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260",
                            "    renders upside-down (LP: #2155837)",
                            "    - SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14",
                            "      Premium PA14260",
                            "",
                            "  * ov08x40 module mounted upside down on a certain DELL platforms",
                            "    (LP: #2146517)",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for new Dell XPS laptops with",
                            "      upside down sensors",
                            "    - SAUCE: media: ipu-bridge: Add DMI quirk for Dell 14 laptops with upside",
                            "      down sensors",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747)",
                            "    - SAUCE: apparmor: pass big_resp to handler",
                            "    - SAUCE: apparmor: remove redundant kref_init for listener->count",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47337",
                            "    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47334",
                            "    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47333",
                            "    - SAUCE: apparmor: fix dfa unpacking size of the notification filter",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47332",
                            "    - SAUCE: apparmor: fix size check against type instead of pointer",
                            "",
                            "  * apparmor: LLVM/clang build failure due to uninitialized variable in",
                            "    notify.c (LP: #2148809) // CVE-2026-47330",
                            "    - SAUCE: apparmor: initialize variable used in uninitialized context",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47329",
                            "    - SAUCE: apparmor: fix name validation bypass on notification",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47327 //",
                            "    CVE-2026-47328",
                            "    - SAUCE: apparmor: fix glob memory leak after kstrdup",
                            "",
                            "  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47326",
                            "    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer",
                            "",
                            "  * unconfined profile denies userns_create for chromium based processes",
                            "    (LP: #1990064)",
                            "    - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS",
                            "",
                            "  * FFe: add network interface mediation to 26.04 (LP: #2144679)",
                            "    - SAUCE: apparmor5.0.0 [57/57]: apparmor: add the ability to use interface",
                            "      in network mediation.",
                            "",
                            "  * Jellyfin Desktop Flatpak doesn't work with the current AppArmor profile",
                            "    (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [29/57]: apparmor: fix fine grained inet mediation",
                            "      sock_file_perm",
                            "    - SAUCE: apparmor5.0.0 [32/57]: apparmor-next 7.1: apparmor: enable",
                            "      differential encoding",
                            "    - SAUCE: apparmor5.0.0 [33/57]: apparmor-next 7.1: apparmor: propagate",
                            "      -ENOMEM correctly in unpack_table",
                            "    - SAUCE: apparmor5.0.0 [36/57]: apparmor-next 7.1: apparmor: use",
                            "      __label_make_stale in __aa_proxy_redirect",
                            "    - SAUCE: apparmor5.0.0 [37/57]: apparmor-next 7.1: apparmor: fix net.h and",
                            "      policy.h circular include pattern",
                            "    - SAUCE: apparmor5.0.0 [39/57]: apparmor-next 7.1: apparmor: make include",
                            "      headers self-contained",
                            "    - SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1: apparmor: fix",
                            "      rawdata_f_data implicit flex array",
                            "    - SAUCE: apparmor5.0.0 [42/57]: apparmor-next 7.1: apparmor: free rawdata",
                            "      as soon as possible",
                            "    - SAUCE: apparmor5.0.0 [43/57]: apparmor-next 7.1: apparmor: Initial",
                            "      support for compressed policies",
                            "    - SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1: apparmor: fix potential",
                            "      UAF in aa_replace_profiles",
                            "    - SAUCE: apparmor5.0.0 [45/57]: apparmor-next 7.1: apparmor: hide unused",
                            "      get_loaddata_common_ref() function",
                            "    - SAUCE: apparmor5.0.0 [47/57]: apparmor: fix packed tag on v5 header",
                            "      struct",
                            "    - SAUCE: apparmor5.0.0 [48/57]: apparmor: add temporal caching to audit",
                            "      responses.",
                            "    - SAUCE: apparmor5.0.0 [49/57]: apparmor: change fn_label_build() call to",
                            "      not return NULL",
                            "    - SAUCE: apparmor5.0.0 [50/57]: apparmor: make fn_label_build() capable of",
                            "      handling not supported",
                            "    - SAUCE: apparmor5.0.0 [51/57]: apparmor: move netfilter functions next to",
                            "      the LSM network operations",
                            "    - SAUCE: apparmor5.0.0 [52/57]: apparmor: move sock_rvc_skb() next to",
                            "      inet_conn_request",
                            "    - SAUCE: apparmor5.0.0 [53/57]: apparmor: fix af_unix local addr mediation",
                            "      binding",
                            "    - SAUCE: apparmor5.0.0 [54/57]: cleanups of apparmor af_unix mediation",
                            "    - SAUCE: apparmor5.0.0 [55/57]: apparmor: fix apparmor_secmark_check()",
                            "      when !inet and secmark defined.",
                            "    - SAUCE: apparmor5.0.0 [56/57]: apparmor: fix auditing of non-mediation",
                            "      falures",
                            "",
                            "  * snap service cannot change apparmor hat (LP: #2139664) // Jellyfin Desktop",
                            "    Flatpak doesn't work with the current AppArmor profile (LP: #2142956)",
                            "    - SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1: apparmor: grab ns lock",
                            "      and refresh when looking up changehat child profiles",
                            "",
                            "  * AppArmor blocks write(2) to network sockets with Linux 6.19 (LP: #2141298)",
                            "    - SAUCE: apparmor5.0.0 [28/57]: apparmor: fix aa_label_sk_perm to check",
                            "      for RULE_MEDIATES_NET",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253)",
                            "    - SAUCE: apparmor5.0.0 [1/57]: Stacking: LSM: Single calls in secid hooks",
                            "    - SAUCE: apparmor5.0.0 [2/57]: Stacking: LSM: Exclusive secmark usage",
                            "    - SAUCE: apparmor5.0.0 [3/57]: Stacking: AppArmor: Remove the exclusive",
                            "      flag",
                            "    - SAUCE: apparmor5.0.0 [4/57]: Revert \"apparmor: fix dbus permission",
                            "      queries to v9 ABI\"",
                            "    - SAUCE: apparmor5.0.0 [5/57]: Revert \"apparmor: gate make fine grained",
                            "      unix mediation behind v9 abi\"",
                            "    - SAUCE: apparmor5.0.0 [6/57]: apparmor: net: patch to provide",
                            "      compatibility with v2.x net rules",
                            "    - SAUCE: apparmor5.0.0 [7/57]: apparmor: net: add fine grained ipv4/ipv6",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [8/57]: apparmor: lift compatibility check out of",
                            "      profile_af_perm",
                            "    - SAUCE: apparmor5.0.0 [9/57]: apparmor: userns: add unprivileged user ns",
                            "      mediation",
                            "    - SAUCE: apparmor5.0.0 [10/57]: apparmor: userns: Add sysctls for",
                            "      additional controls of unpriv userns restrictions",
                            "    - SAUCE: apparmor5.0.0 [12/57]: apparmor: userns: open userns related",
                            "      sysctl so lxc can check if restriction are in place",
                            "    - SAUCE: apparmor5.0.0 [13/57]: apparmor: userns: allow profile to be",
                            "      transitioned when a userns is created",
                            "    - SAUCE: apparmor5.0.0 [14/57]: apparmor: mqueue: call",
                            "      security_inode_init_security on inode creation",
                            "    - SAUCE: apparmor5.0.0 [15/57]: apparmor: mqueue: add fine grained",
                            "      mediation of posix mqueues",
                            "    - SAUCE: apparmor5.0.0 [16/57]: apparmor: uring: add io_uring mediation",
                            "    - SAUCE: apparmor5.0.0 [19/57]: apparmor: prompt: setup slab cache for",
                            "      audit data",
                            "    - SAUCE: apparmor5.0.0 [20/57]: apparmor: prompt: add the ability for",
                            "      profiles to have a learning cache",
                            "    - SAUCE: apparmor5.0.0 [21/57]: apparmor: prompt: enable userspace upcall",
                            "      for mediation",
                            "    - SAUCE: apparmor5.0.0 [22/57]: apparmor: prompt: pass prompt boolean",
                            "      through into path_name as well",
                            "    - SAUCE: apparmor5.0.0 [23/57]: apparmor: check for supported version in",
                            "      notification messages.",
                            "    - SAUCE: apparmor5.0.0 [24/57]: apparmor: refactor building notice so it",
                            "      is easier to extend",
                            "    - SAUCE: apparmor5.0.0 [25/57]: apparmor: switch from ENOTSUPP to",
                            "      EPROTONOSUPPORT",
                            "    - SAUCE: apparmor5.0.0 [26/57]: apparmor: add support for meta data tags",
                            "    - SAUCE: apparmor5.0.0 [27/57]: apparmor: prevent profile->disconnected",
                            "      double free in aa_free_profile",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // Installation",
                            "    of AppArmor on a 6.14 kernel produces error message \"Illegal number: yes\"",
                            "    (LP: #2102680)",
                            "    - SAUCE: apparmor5.0.0 [17/57]: apparmor: create an",
                            "      AA_SFS_TYPE_BOOLEAN_INTPRINT sysctl variant",
                            "    - SAUCE: apparmor5.0.0 [18/57]: apparmor: Use AA_SFS_FILE_BOOLEAN_INTPRINT",
                            "      for userns and io_uring sysctls",
                            "",
                            "  * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe]",
                            "    apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in",
                            "    mantic (LP: #2032602)",
                            "    - SAUCE: apparmor5.0.0 [11/57]: apparmor: userns - make it so special",
                            "      unconfined profiles can mediate user namespaces",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - [Config] enable SECURITY_APPARMOR_PACKET_MEDIATION_ENABLED",
                            "    - [Packaging] Fix cross-builds",
                            "    - [Config] updateconfigs after v7.1 rebase",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-5.5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2156849,
                            2155837,
                            2146517,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2151747,
                            2148809,
                            2151747,
                            2151747,
                            2151747,
                            1990064,
                            2144679,
                            2142956,
                            2139664,
                            2142956,
                            2141298,
                            2028253,
                            2028253,
                            2102680,
                            2028253,
                            2032602
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 16 Jun 2026 11:38:33 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * stonking/linux: 7.1.0-1.1 -proposed tracker (LP: #2154256)",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] update variants",
                            "",
                            "  * resolute ubuntu_kernel_selftests:seccomp_build test compilation issue",
                            "    (LP: #2154174)",
                            "    - SAUCE: selftests/seccomp fix compilation issue for amd64",
                            "",
                            "  * Kernel 6.19-rc8 does not include GPIB driver (LP: #2152714)",
                            "    - [Config] Enable CONFIG_GPIB for amd64",
                            "",
                            "  * Miscellaneous Ubuntu changes",
                            "    - Update Changes.md after v7.1-rc4 rebase",
                            "    - [packaging] Install gdb scripts again",
                            "    - [Config] updateconfigs after v7.1-rc5 rebase",
                            "    - [Packaging] templates: Use a for-loop for run-parts",
                            "    - [Packaging] Remove dead debian.master/rules.d/x32.mk",
                            "    - [Packaging] Remove orphaned debian/v4l2loopback-modules.ignore",
                            "    - [Packaging] Remove orphaned debian/zfs-modules.ignore",
                            "    - [Packaging] Remove deprecated linux-doc transitional stub",
                            "    - [Packaging] Remove dead comment referencing gcc-4.7 in control.stub.in",
                            "    - [Packaging] Remove dead comment in ppc64el.mk",
                            "    - [Packaging] Remove stale legacy code",
                            "    - [Packaging] rules: Drop an obsolete check for do_zstd_ko",
                            "    - [Config] toolchain version update",
                            "    - [Packaging] update Ubuntu.md",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-1.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2154256,
                            1786013,
                            2154174,
                            2152714
                        ],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 16:08:55 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Dummy entry.",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.1.0-0.0",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <timo.aaltonen@canonical.com>",
                        "date": "Tue, 26 May 2026 09:59:13 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * resolute/linux: 7.0.0-15.15 -proposed tracker (LP: #2148866)",
                            "",
                            "  * Qualcomm X1E: Speaker overdrive causes hardware protection shutdown",
                            "    (LP: #2149808)",
                            "    - SAUCE: ASoC: qcom: x1e80100: limit speaker volumes",
                            "",
                            "  * intel-ipu7 / intel-ipu7-isys modules are shipped unsigned in latest",
                            "    Resolute kernels, breaking Secure Boot systems  (LP: #2148718)",
                            "    - [packaging] add intel-ipu7 to signature inclusion list",
                            ""
                        ],
                        "package": "linux",
                        "version": "7.0.0-15.15",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2148866,
                            2149808,
                            2148718
                        ],
                        "author": "Paolo Pisati <paolo.pisati@canonical.com>",
                        "date": "Wed, 22 Apr 2026 16:02:19 +0200"
                    }
                ],
                "notes": "linux-modules-7.3.0-5-generic version '7.3.0-5.5' (source package linux version '7.3.0-5.5') was added. linux-modules-7.3.0-5-generic version '7.3.0-5.5' has the same source package name, linux, as removed package linux-modules-7.0.0-14-generic. As such we can use the source package version of the removed package, '7.0.0-14.14', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "openssh-common",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.5p1-1ubuntu2",
                    "version": "1:10.5p1-1ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-73281",
                        "url": "https://ubuntu.com/security/CVE-2026-73281",
                        "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73282",
                        "url": "https://ubuntu.com/security/CVE-2026-73282",
                        "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73283",
                        "url": "https://ubuntu.com/security/CVE-2026-73283",
                        "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2150273,
                    2166924,
                    2166081
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2150273-openssh-pam-upn: Fix PAM user mismatch with",
                            "    alternative UPN suffixes by comparing account UIDs instead of",
                            "    username strings (LP: #2150273)",
                            "  * d/t/password-auth-no-pam: create /run/sshd for the custom test",
                            "    service (LP: #2166924)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150273,
                            2166924
                        ],
                        "author": "Finn Rayk Gartner <finn.gartner@canonical.com>",
                        "date": "Wed, 09 Sep 2026 21:08:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2166081). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "      [Not needed since 1:10.5p1-1]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166081
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 01 Sep 2026 14:45:43 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-73281",
                                "url": "https://ubuntu.com/security/CVE-2026-73281",
                                "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73282",
                                "url": "https://ubuntu.com/security/CVE-2026-73282",
                                "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73283",
                                "url": "https://ubuntu.com/security/CVE-2026-73283",
                                "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1144192):",
                            "    - CVE-2026-73281: ssh-agent(1): fix an interaction between agent locking",
                            "      and the session-bind@openssh.com extension that is used to identify",
                            "      forwarded agents. These binding requests were refused when the agent",
                            "      was locked, with the result that operations that were intended to be",
                            "      limited to local use only could be performed remotely, including the",
                            "      ability to add PKCS#11 tokens and make use of keys that had",
                            "      destination restrictions applied.",
                            "    - CVE-2026-73282: ssh(1): avoid potential realloc use-after-free in the",
                            "      client if a remote forwarding is added via the local session",
                            "      multiplexing socket while a remote forwarding open request is pending",
                            "      with the server.",
                            "    - CVE-2026-73283: sshd(8): make the authorized_keys \"restrict\" keyword",
                            "      apply correctly to tunnel forwarding too (which is administratively",
                            "      disabled by default).",
                            "    - ssh-keygen(1): add ability to set or clear the touch-required and",
                            "      verify-required flags on FIDO private keys when resetting a private",
                            "      key's passphrase.",
                            "    - ssh(1): tweak ordering of certificates tried during pubkey",
                            "      authentication to prefer FIDO keys that do not require user presence",
                            "      (touch) first, and FIDO keys that require user verification via PIN or",
                            "      biometrics last. This effectively tries low-friction authenticators",
                            "      before higher friction ones.",
                            "    - ssh(1): add a \"ssh -Z user@host\" mode that prints the keys that will",
                            "      be tried for public key authentication in the order that they will be",
                            "      used.",
                            "    - sshd(8) use setproctitle(3) to identify sshd-session when it's acting",
                            "      as a post-authentication monitor.",
                            "    - ssh-keyscan(1): make reading the server banner a non-blocking",
                            "      operation to prevent a stuck server from blocking a many-host keyscan",
                            "      from proceeding.",
                            "    - sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the",
                            "      packet code as this provides context of the failing peer (address,",
                            "      port, user, etc).",
                            "    - sshd(8): when signing hostkey proofs for a client UpdateHostKeys",
                            "      request, allow each hostkey to perform at most one signature",
                            "      operation.",
                            "    - ssh-keygen(1): pass back errors from ed25519 key generation, which",
                            "      theoretically can fail.",
                            "    - sshd(8): move check of public key type against allowed algorithms to",
                            "      before parsing of the key sent by the peer. This removes at least some",
                            "      key parsing and verification paths from the pre-auth attack surface.",
                            "    - ssh-keygen(1): fix double frees (impossible to reach outside of a test",
                            "      harness), and also use freezero where possible.",
                            "    - sshd(8): fix ChannelTimeout and RekeyLimit not being applied in",
                            "      sshd_config Match blocks.",
                            "    - sshd(8): in sshd config dump mode, write all directives in mixed case",
                            "      for consistency.",
                            "    - sshd(8): re-allow PAMServiceName inside a Match block, which was",
                            "      incorrectly disabled during a refactoring in openssh-10.4.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 31 Aug 2026 20:53:27 +0100"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "python3-charset-normalizer",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "python-charset-normalizer",
                    "source_package_version": "3.4.7-2",
                    "version": "3.4.7-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Add debian/salsa-ci.yml to test <nodoc> profile",
                            "  * Tag Sphinx build-deps as <!nodoc>",
                            "  * Bump Standards-Version to 4.7.4, drop Priority: tag",
                            "  * Rewrite d/watch in v5 format",
                            ""
                        ],
                        "package": "python-charset-normalizer",
                        "version": "3.4.7-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sun, 05 Jul 2026 14:33:21 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * New upstream release:",
                            "    - Correctly propagate bytes|bytearray support in functions",
                            "      (Closes: #1135452).",
                            ""
                        ],
                        "package": "python-charset-normalizer",
                        "version": "3.4.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Wed, 06 May 2026 14:49:29 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Explicitly check that mypyc works for each supported Python version",
                            "    (closes: #1121820).",
                            ""
                        ],
                        "package": "python-charset-normalizer",
                        "version": "3.4.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Wed, 03 Dec 2025 11:42:51 +0000"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "sqv",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "rust-sequoia-sqv",
                    "source_package_version": "1.4.0-1ubuntu2",
                    "version": "1.4.0-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "rust-sequoia-sqv",
                        "version": "1.4.0-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 16:15:33 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable. Remaining changes:",
                            "    - debian/rules:",
                            "      + enable build size optimizations on 32-bit",
                            "      + add vendor targets",
                            "    - debian/patches:",
                            "      + remove unused deps from Cargo.toml",
                            "      + run cargo update",
                            "    - debian/control:",
                            "      + remove vendored Build-Depends-Arch",
                            "      + add libssl-dev and pkgconf Depends",
                            "      + Build-Depend on libclang-dev for bindgen",
                            "      + Update XS-Vendored-Sources-Rust field",
                            "    - d/README.source: add vendoring instructions",
                            "    - Update vendored rust crates",
                            "    - Update debian/source/include-binaries",
                            ""
                        ],
                        "package": "rust-sequoia-sqv",
                        "version": "1.4.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Mon, 13 Jul 2026 11:51:26 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Package sequoia-sqv 1.4.0 from crates.io using debcargo 2.8.3",
                            "    - update d/copyright years.",
                            ""
                        ],
                        "package": "rust-sequoia-sqv",
                        "version": "1.4.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Holger Levsen <holger@debian.org>",
                        "date": "Sun, 28 Jun 2026 11:20:20 +0200"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "removed": {
        "deb": [
            {
                "name": "gpgv",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu1",
                    "version": "2.4.9-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgcrypt20",
                "from_version": {
                    "source_package_name": "libgcrypt20",
                    "source_package_version": "1.12.2-1ubuntu1",
                    "version": "1.12.2-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgpg-error0",
                "from_version": {
                    "source_package_name": "libgpg-error",
                    "source_package_version": "1.61-3",
                    "version": "1.61-3"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libproc2-0",
                "from_version": {
                    "source_package_name": "procps",
                    "source_package_version": "2:4.0.4-9ubuntu1",
                    "version": "2:4.0.4-9ubuntu1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-image-7.0.0-14-generic",
                "from_version": {
                    "source_package_name": "linux-signed",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-main-modules-zfs-7.0.0-14-generic",
                "from_version": {
                    "source_package_name": "linux-main-signed",
                    "source_package_version": "7.0.0-14.14+3",
                    "version": "7.0.0-14.14+3"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-modules-7.0.0-14-generic",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.0.0-14.14",
                    "version": "7.0.0-14.14"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-autocommand",
                "from_version": {
                    "source_package_name": "python-autocommand",
                    "source_package_version": "2.2.2-4",
                    "version": "2.2.2-4"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-inflect",
                "from_version": {
                    "source_package_name": "python-inflect",
                    "source_package_version": "7.5.0-2",
                    "version": "7.5.0-2"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-jaraco.context",
                "from_version": {
                    "source_package_name": "jaraco.context",
                    "source_package_version": "6.0.1-2",
                    "version": "6.0.1-2"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-jaraco.functools",
                "from_version": {
                    "source_package_name": "python-jaraco.functools",
                    "source_package_version": "4.1.0-1build1",
                    "version": "4.1.0-1build1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-jaraco.text",
                "from_version": {
                    "source_package_name": "jaraco.text",
                    "source_package_version": "4.0.0-1build1",
                    "version": "4.0.0-1build1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-more-itertools",
                "from_version": {
                    "source_package_name": "more-itertools",
                    "source_package_version": "10.8.0-1build1",
                    "version": "10.8.0-1build1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-pkg-resources",
                "from_version": {
                    "source_package_name": "setuptools",
                    "source_package_version": "78.1.1-0.1build1",
                    "version": "78.1.1-0.1build1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-setuptools",
                "from_version": {
                    "source_package_name": "setuptools",
                    "source_package_version": "78.1.1-0.1build1",
                    "version": "78.1.1-0.1build1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-typeguard",
                "from_version": {
                    "source_package_name": "python-typeguard",
                    "source_package_version": "4.4.4-3",
                    "version": "4.4.4-3"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-typing-extensions",
                "from_version": {
                    "source_package_name": "python-typing-extensions",
                    "source_package_version": "4.15.0-2",
                    "version": "4.15.0-2"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-zipp",
                "from_version": {
                    "source_package_name": "python-zipp",
                    "source_package_version": "3.23.0-1build1",
                    "version": "3.23.0-1build1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "notes": "Changelog diff for Ubuntu 26.10 stonking image from daily image serial 20260727 to 20260918",
    "from_series": "stonking",
    "to_series": "stonking",
    "from_serial": "20260727",
    "to_serial": "20260918",
    "from_manifest_filename": "daily_manifest.previous",
    "to_manifest_filename": "manifest.current"
}