{
    "summary": {
        "snap": {
            "added": [],
            "removed": [],
            "diff": []
        },
        "deb": {
            "added": [],
            "removed": [],
            "diff": [
                "libfreetype6",
                "libsgutils2-2",
                "sg3-utils",
                "snapd",
                "sudo"
            ]
        }
    },
    "diff": {
        "deb": [
            {
                "name": "libfreetype6",
                "from_version": {
                    "source_package_name": "freetype",
                    "source_package_version": "2.11.1+dfsg-1ubuntu0.3",
                    "version": "2.11.1+dfsg-1ubuntu0.3"
                },
                "to_version": {
                    "source_package_name": "freetype",
                    "source_package_version": "2.11.1+dfsg-1ubuntu0.4",
                    "version": "2.11.1+dfsg-1ubuntu0.4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-95512",
                        "url": "https://ubuntu.com/security/CVE-2026-95512",
                        "cve_description": "A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-10-02 09:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-95512",
                                "url": "https://ubuntu.com/security/CVE-2026-95512",
                                "cve_description": "A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-10-02 09:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: DoS in CID font loader",
                            "    - debian/patches/CVE-2026-95512.patch: * src/cid/cidload.c (cid_read_subrs):",
                            "      Limit overlaps. in src/cid/cidload.c.",
                            "    - CVE-2026-95512",
                            ""
                        ],
                        "package": "freetype",
                        "version": "2.11.1+dfsg-1ubuntu0.4",
                        "urgency": "medium",
                        "distributions": "jammy-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Mon, 05 Oct 2026 10:43:41 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsgutils2-2",
                "from_version": {
                    "source_package_name": "sg3-utils",
                    "source_package_version": "1.46-1ubuntu0.22.04.1",
                    "version": "1.46-1ubuntu0.22.04.1"
                },
                "to_version": {
                    "source_package_name": "sg3-utils",
                    "source_package_version": "1.46-1ubuntu0.22.04.2",
                    "version": "1.46-1ubuntu0.22.04.2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16313",
                        "url": "https://ubuntu.com/security/CVE-2026-16313",
                        "cve_description": "A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-28 17:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16313",
                                "url": "https://ubuntu.com/security/CVE-2026-16313",
                                "cve_description": "A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-28 17:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: command injection via udev property injection",
                            "    - debian/patches/CVE-2026-16313.patch: apply udev-conforming character",
                            "      encoding to the VPD 0x83 SCSI name string and T10 vendor ID ATA",
                            "      subfield output of sg_inq --export, so a crafted SCSI device cannot",
                            "      inject udev properties and execute commands as root (fix released",
                            "      upstream in sg3_utils 1.49).",
                            "    - debian/patches/CVE-2026-16313_2.patch: avoid including 0-bytes in SCSI",
                            "      name strings (upstream follow-up fix).",
                            "    - CVE-2026-16313",
                            ""
                        ],
                        "package": "sg3-utils",
                        "version": "1.46-1ubuntu0.22.04.2",
                        "urgency": "medium",
                        "distributions": "jammy-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Allen Huang <allen.huang@canonical.com>",
                        "date": "Thu, 01 Oct 2026 14:12:16 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "sg3-utils",
                "from_version": {
                    "source_package_name": "sg3-utils",
                    "source_package_version": "1.46-1ubuntu0.22.04.1",
                    "version": "1.46-1ubuntu0.22.04.1"
                },
                "to_version": {
                    "source_package_name": "sg3-utils",
                    "source_package_version": "1.46-1ubuntu0.22.04.2",
                    "version": "1.46-1ubuntu0.22.04.2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-16313",
                        "url": "https://ubuntu.com/security/CVE-2026-16313",
                        "cve_description": "A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-28 17:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-16313",
                                "url": "https://ubuntu.com/security/CVE-2026-16313",
                                "cve_description": "A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-28 17:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: command injection via udev property injection",
                            "    - debian/patches/CVE-2026-16313.patch: apply udev-conforming character",
                            "      encoding to the VPD 0x83 SCSI name string and T10 vendor ID ATA",
                            "      subfield output of sg_inq --export, so a crafted SCSI device cannot",
                            "      inject udev properties and execute commands as root (fix released",
                            "      upstream in sg3_utils 1.49).",
                            "    - debian/patches/CVE-2026-16313_2.patch: avoid including 0-bytes in SCSI",
                            "      name strings (upstream follow-up fix).",
                            "    - CVE-2026-16313",
                            ""
                        ],
                        "package": "sg3-utils",
                        "version": "1.46-1ubuntu0.22.04.2",
                        "urgency": "medium",
                        "distributions": "jammy-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Allen Huang <allen.huang@canonical.com>",
                        "date": "Thu, 01 Oct 2026 14:12:16 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "snapd",
                "from_version": {
                    "source_package_name": "snapd",
                    "source_package_version": "2.76.3+ubuntu22.04",
                    "version": "2.76.3+ubuntu22.04"
                },
                "to_version": {
                    "source_package_name": "snapd",
                    "source_package_version": "2.76.3+ubuntu22.04.1",
                    "version": "2.76.3+ubuntu22.04.1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No change rebuild due to golang-1.18 update",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76.3+ubuntu22.04.1",
                        "urgency": "medium",
                        "distributions": "jammy-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Jorge Sancho Larraz <jorge.sancho.larraz@canonical.com>",
                        "date": "Tue, 06 Oct 2026 10:21:48 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "sudo",
                "from_version": {
                    "source_package_name": "sudo",
                    "source_package_version": "1.9.9-1ubuntu2.6",
                    "version": "1.9.9-1ubuntu2.6"
                },
                "to_version": {
                    "source_package_name": "sudo",
                    "source_package_version": "1.9.9-1ubuntu2.7",
                    "version": "1.9.9-1ubuntu2.7"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-96512",
                        "url": "https://ubuntu.com/security/CVE-2026-96512",
                        "cve_description": "A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-23 14:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-96512",
                                "url": "https://ubuntu.com/security/CVE-2026-96512",
                                "cve_description": "A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-23 14:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: NOTBEFORE or NOTAFTER restrictions bypass via TZ",
                            "    - debian/patches/CVE-2026-96512-pre1.patch: sudo: ignore user-specified TZ",
                            "      environment variable in src/sudo.c.",
                            "    - debian/patches/CVE-2026-96512.patch: Remove TZ from sudo's working",
                            "      environment without modifying envp. in src/sudo.c.",
                            "    - CVE-2026-96512",
                            ""
                        ],
                        "package": "sudo",
                        "version": "1.9.9-1ubuntu2.7",
                        "urgency": "medium",
                        "distributions": "jammy-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Tue, 06 Oct 2026 10:05:40 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "added": {
        "deb": [],
        "snap": []
    },
    "removed": {
        "deb": [],
        "snap": []
    },
    "notes": "Changelog diff for Ubuntu 22.04 jammy image from daily image serial 20261001 to 20261007",
    "from_series": "jammy",
    "to_series": "jammy",
    "from_serial": "20261001",
    "to_serial": "20261007",
    "from_manifest_filename": "daily_manifest.previous",
    "to_manifest_filename": "manifest.current"
}