{
    "summary": {
        "snap": {
            "added": [],
            "removed": [],
            "diff": []
        },
        "deb": {
            "added": [
                "linux-headers-5.15.0-1093-kvm",
                "linux-image-5.15.0-1093-kvm",
                "linux-kvm-headers-5.15.0-1093",
                "linux-modules-5.15.0-1093-kvm"
            ],
            "removed": [
                "linux-headers-5.15.0-1092-kvm",
                "linux-image-5.15.0-1092-kvm",
                "linux-kvm-headers-5.15.0-1092",
                "linux-modules-5.15.0-1092-kvm"
            ],
            "diff": [
                "libssh-4",
                "linux-headers-kvm",
                "linux-image-kvm",
                "linux-kvm"
            ]
        }
    },
    "diff": {
        "deb": [
            {
                "name": "libssh-4",
                "from_version": {
                    "source_package_name": "libssh",
                    "source_package_version": "0.9.6-2ubuntu0.22.04.5",
                    "version": "0.9.6-2ubuntu0.22.04.5"
                },
                "to_version": {
                    "source_package_name": "libssh",
                    "source_package_version": "0.9.6-2ubuntu0.22.04.6",
                    "version": "0.9.6-2ubuntu0.22.04.6"
                },
                "cves": [
                    {
                        "cve": "CVE-2025-8277",
                        "url": "https://ubuntu.com/security/CVE-2025-8277",
                        "cve_description": "A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability.",
                        "cve_priority": "low",
                        "cve_public_date": "2025-09-09 12:15:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-0964",
                        "url": "https://ubuntu.com/security/CVE-2026-0964",
                        "cve_description": "[Improper sanitation of paths received from SCP servers]",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-02-13"
                    },
                    {
                        "cve": "CVE-2026-0965",
                        "url": "https://ubuntu.com/security/CVE-2026-0965",
                        "cve_description": "[Denial of Service via improper configuration file handling]",
                        "cve_priority": "low",
                        "cve_public_date": "2026-02-13"
                    },
                    {
                        "cve": "CVE-2026-0966",
                        "url": "https://ubuntu.com/security/CVE-2026-0966",
                        "cve_description": "[Buffer underflow in ssh_get_hexa() on invalid input]",
                        "cve_priority": "low",
                        "cve_public_date": "2026-02-13"
                    },
                    {
                        "cve": "CVE-2026-0967",
                        "url": "https://ubuntu.com/security/CVE-2026-0967",
                        "cve_description": "[Denial of Service via inefficient regular expression processing]",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-02-13"
                    },
                    {
                        "cve": "CVE-2026-0968",
                        "url": "https://ubuntu.com/security/CVE-2026-0968",
                        "cve_description": "[Denial of Service due to malformed SFTP message]",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-02-13"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2025-8277",
                                "url": "https://ubuntu.com/security/CVE-2025-8277",
                                "cve_description": "A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability.",
                                "cve_priority": "low",
                                "cve_public_date": "2025-09-09 12:15:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-0964",
                                "url": "https://ubuntu.com/security/CVE-2026-0964",
                                "cve_description": "[Improper sanitation of paths received from SCP servers]",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-02-13"
                            },
                            {
                                "cve": "CVE-2026-0965",
                                "url": "https://ubuntu.com/security/CVE-2026-0965",
                                "cve_description": "[Denial of Service via improper configuration file handling]",
                                "cve_priority": "low",
                                "cve_public_date": "2026-02-13"
                            },
                            {
                                "cve": "CVE-2026-0966",
                                "url": "https://ubuntu.com/security/CVE-2026-0966",
                                "cve_description": "[Buffer underflow in ssh_get_hexa() on invalid input]",
                                "cve_priority": "low",
                                "cve_public_date": "2026-02-13"
                            },
                            {
                                "cve": "CVE-2026-0967",
                                "url": "https://ubuntu.com/security/CVE-2026-0967",
                                "cve_description": "[Denial of Service via inefficient regular expression processing]",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-02-13"
                            },
                            {
                                "cve": "CVE-2026-0968",
                                "url": "https://ubuntu.com/security/CVE-2026-0968",
                                "cve_description": "[Denial of Service due to malformed SFTP message]",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-02-13"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: memory leak in key exchange",
                            "    - debian/patches/CVE-2025-8277-1.patch: adjust packet filter to work",
                            "      when DH-GEX is guessed wrongly in src/packet.c.",
                            "    - debian/patches/CVE-2025-8277-2.patch: fix memory leak of unused",
                            "      ephemeral key pair after client's wrong KEX guess in src/dh_crypto.c,",
                            "      src/dh_key.c, src/ecdh_crypto.c, src/ecdh_gcrypt.c,",
                            "      src/ecdh_mbedcrypto.c.",
                            "    - debian/patches/CVE-2025-8277-3.patch: free previously allocated",
                            "      pubkeys in src/ecdh_crypto.c, src/ecdh_gcrypt.c.",
                            "    - debian/patches/CVE-2025-8277-4.patch: avoid leaking ecdh keys in",
                            "      src/ecdh_mbedcrypto.c, src/wrapper.c.",
                            "    - CVE-2025-8277",
                            "  * SECURITY UPDATE: Improper sanitation of paths received from SCP servers",
                            "    - debian/patches/CVE-2026-0964.patch: reject invalid paths received",
                            "      through scp in src/scp.c.",
                            "    - CVE-2026-0964",
                            "  * SECURITY UPDATE: DoS via improper configuration file handling",
                            "    - debian/patches/CVE-2026-0965.patch: do not attempt to read",
                            "      non-regular and too large configuration files in",
                            "      include/libssh/misc.h, include/libssh/priv.h, src/bind_config.c,",
                            "      src/config.c, src/dh-gex.c, src/known_hosts.c, src/knownhosts.c,",
                            "      src/misc.c, tests/unittests/torture_config.c.",
                            "    - CVE-2026-0965",
                            "  * SECURITY UPDATE: Buffer underflow in ssh_get_hexa() on invalid input",
                            "    - debian/patches/CVE-2026-0966-1.patch: avoid heap buffer underflow in",
                            "      ssh_get_hexa in src/misc.c.",
                            "    - debian/patches/CVE-2026-0966-2.patch: test coverage for ssh_get_hexa",
                            "      in tests/unittests/torture_misc.c.",
                            "    - debian/patches/CVE-2026-0966-3.patch: update guided tour to use",
                            "      SHA256 fingerprints in doc/guided_tour.dox.",
                            "    - CVE-2026-0966",
                            "  * SECURITY UPDATE: DoS via inefficient regular expression processing",
                            "    - debian/patches/CVE-2026-0967.patch: avoid recursive matching (ReDoS)",
                            "      in src/match.c, tests/unittests/torture_config.c.",
                            "    - CVE-2026-0967",
                            "  * SECURITY UPDATE: DoS due to malformed SFTP message",
                            "    - debian/patches/CVE-2026-0968-1.patch: sanitize input handling in",
                            "      sftp_parse_longname() in src/sftp.c.",
                            "    - debian/patches/CVE-2026-0968-2.patch: reproducer for invalid longname",
                            "      data in tests/unittests/CMakeLists.txt,",
                            "      tests/unittests/torture_unit_sftp.c.",
                            "    - CVE-2026-0968",
                            ""
                        ],
                        "package": "libssh",
                        "version": "0.9.6-2ubuntu0.22.04.6",
                        "urgency": "medium",
                        "distributions": "jammy-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Fri, 13 Feb 2026 10:22:49 -0500"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-headers-kvm",
                "from_version": {
                    "source_package_name": "linux-meta-kvm",
                    "source_package_version": "5.15.0.1092.88",
                    "version": "5.15.0.1092.88"
                },
                "to_version": {
                    "source_package_name": "linux-meta-kvm",
                    "source_package_version": "5.15.0.1093.89",
                    "version": "5.15.0.1093.89"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Bump ABI 5.15.0-1093",
                            ""
                        ],
                        "package": "linux-meta-kvm",
                        "version": "5.15.0.1093.89",
                        "urgency": "medium",
                        "distributions": "jammy",
                        "launchpad_bugs_fixed": [],
                        "author": "Thibault Ferrante <thibault.ferrante@canonical.com>",
                        "date": "Fri, 13 Feb 2026 17:24:25 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-image-kvm",
                "from_version": {
                    "source_package_name": "linux-meta-kvm",
                    "source_package_version": "5.15.0.1092.88",
                    "version": "5.15.0.1092.88"
                },
                "to_version": {
                    "source_package_name": "linux-meta-kvm",
                    "source_package_version": "5.15.0.1093.89",
                    "version": "5.15.0.1093.89"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Bump ABI 5.15.0-1093",
                            ""
                        ],
                        "package": "linux-meta-kvm",
                        "version": "5.15.0.1093.89",
                        "urgency": "medium",
                        "distributions": "jammy",
                        "launchpad_bugs_fixed": [],
                        "author": "Thibault Ferrante <thibault.ferrante@canonical.com>",
                        "date": "Fri, 13 Feb 2026 17:24:25 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-kvm",
                "from_version": {
                    "source_package_name": "linux-meta-kvm",
                    "source_package_version": "5.15.0.1092.88",
                    "version": "5.15.0.1092.88"
                },
                "to_version": {
                    "source_package_name": "linux-meta-kvm",
                    "source_package_version": "5.15.0.1093.89",
                    "version": "5.15.0.1093.89"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Bump ABI 5.15.0-1093",
                            ""
                        ],
                        "package": "linux-meta-kvm",
                        "version": "5.15.0.1093.89",
                        "urgency": "medium",
                        "distributions": "jammy",
                        "launchpad_bugs_fixed": [],
                        "author": "Thibault Ferrante <thibault.ferrante@canonical.com>",
                        "date": "Fri, 13 Feb 2026 17:24:25 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "added": {
        "deb": [
            {
                "name": "linux-headers-5.15.0-1093-kvm",
                "from_version": {
                    "source_package_name": "linux-kvm",
                    "source_package_version": "5.15.0-1092.97",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux-kvm",
                    "source_package_version": "5.15.0-1093.98",
                    "version": "5.15.0-1093.98"
                },
                "cves": [
                    {
                        "cve": "CVE-2022-49267",
                        "url": "https://ubuntu.com/security/CVE-2022-49267",
                        "cve_description": "In the Linux kernel, the following vulnerability has been resolved:  mmc: core: use sysfs_emit() instead of sprintf()  sprintf() (still used in the MMC core for the sysfs output) is vulnerable to the buffer overflow.  Use the new-fangled sysfs_emit() instead.  Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.",
                        "cve_priority": "medium",
                        "cve_public_date": "2025-02-26 07:01:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-21780",
                        "url": "https://ubuntu.com/security/CVE-2025-21780",
                        "cve_description": "In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()  It malicious user provides a small pptable through sysfs and then a bigger pptable, it may cause buffer overflow attack in function smu_sys_set_pp_table().",
                        "cve_priority": "high",
                        "cve_public_date": "2025-02-27 03:15:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2140890,
                    2140905
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2022-49267",
                                "url": "https://ubuntu.com/security/CVE-2022-49267",
                                "cve_description": "In the Linux kernel, the following vulnerability has been resolved:  mmc: core: use sysfs_emit() instead of sprintf()  sprintf() (still used in the MMC core for the sysfs output) is vulnerable to the buffer overflow.  Use the new-fangled sysfs_emit() instead.  Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.",
                                "cve_priority": "medium",
                                "cve_public_date": "2025-02-26 07:01:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-21780",
                                "url": "https://ubuntu.com/security/CVE-2025-21780",
                                "cve_description": "In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()  It malicious user provides a small pptable through sysfs and then a bigger pptable, it may cause buffer overflow attack in function smu_sys_set_pp_table().",
                                "cve_priority": "high",
                                "cve_public_date": "2025-02-27 03:15:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * jammy/linux-kvm: 5.15.0-1093.98 -proposed tracker (LP: #2140890)",
                            "",
                            "  [ Ubuntu: 5.15.0-171.181 ]",
                            "",
                            "  * jammy/linux: 5.15.0-171.181 -proposed tracker (LP: #2140905)",
                            "  * CVE-2022-49267",
                            "    - mmc: core: use sysfs_emit() instead of sprintf()",
                            "  * CVE-2025-21780",
                            "    - drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()",
                            ""
                        ],
                        "package": "linux-kvm",
                        "version": "5.15.0-1093.98",
                        "urgency": "medium",
                        "distributions": "jammy",
                        "launchpad_bugs_fixed": [
                            2140890,
                            2140905
                        ],
                        "author": "Thibault Ferrante <thibault.ferrante@canonical.com>",
                        "date": "Fri, 13 Feb 2026 17:24:18 +0100"
                    }
                ],
                "notes": "linux-headers-5.15.0-1093-kvm version '5.15.0-1093.98' (source package linux-kvm version '5.15.0-1093.98') was added. linux-headers-5.15.0-1093-kvm version '5.15.0-1093.98' has the same source package name, linux-kvm, as removed package linux-headers-5.15.0-1092-kvm. As such we can use the source package version of the removed package, '5.15.0-1092.97', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-image-5.15.0-1093-kvm",
                "from_version": {
                    "source_package_name": "linux-signed-kvm",
                    "source_package_version": "5.15.0-1092.97",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux-signed-kvm",
                    "source_package_version": "5.15.0-1093.98",
                    "version": "5.15.0-1093.98"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1786013
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Main version: 5.15.0-1093.98",
                            "",
                            "  * Packaging resync (LP: #1786013)",
                            "    - [Packaging] debian/tracking-bug -- resync from main package",
                            ""
                        ],
                        "package": "linux-signed-kvm",
                        "version": "5.15.0-1093.98",
                        "urgency": "medium",
                        "distributions": "jammy",
                        "launchpad_bugs_fixed": [
                            1786013
                        ],
                        "author": "Thibault Ferrante <thibault.ferrante@canonical.com>",
                        "date": "Fri, 13 Feb 2026 17:24:31 +0100"
                    }
                ],
                "notes": "linux-image-5.15.0-1093-kvm version '5.15.0-1093.98' (source package linux-signed-kvm version '5.15.0-1093.98') was added. linux-image-5.15.0-1093-kvm version '5.15.0-1093.98' has the same source package name, linux-signed-kvm, as removed package linux-image-5.15.0-1092-kvm. As such we can use the source package version of the removed package, '5.15.0-1092.97', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-kvm-headers-5.15.0-1093",
                "from_version": {
                    "source_package_name": "linux-kvm",
                    "source_package_version": "5.15.0-1092.97",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux-kvm",
                    "source_package_version": "5.15.0-1093.98",
                    "version": "5.15.0-1093.98"
                },
                "cves": [
                    {
                        "cve": "CVE-2022-49267",
                        "url": "https://ubuntu.com/security/CVE-2022-49267",
                        "cve_description": "In the Linux kernel, the following vulnerability has been resolved:  mmc: core: use sysfs_emit() instead of sprintf()  sprintf() (still used in the MMC core for the sysfs output) is vulnerable to the buffer overflow.  Use the new-fangled sysfs_emit() instead.  Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.",
                        "cve_priority": "medium",
                        "cve_public_date": "2025-02-26 07:01:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-21780",
                        "url": "https://ubuntu.com/security/CVE-2025-21780",
                        "cve_description": "In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()  It malicious user provides a small pptable through sysfs and then a bigger pptable, it may cause buffer overflow attack in function smu_sys_set_pp_table().",
                        "cve_priority": "high",
                        "cve_public_date": "2025-02-27 03:15:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2140890,
                    2140905
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2022-49267",
                                "url": "https://ubuntu.com/security/CVE-2022-49267",
                                "cve_description": "In the Linux kernel, the following vulnerability has been resolved:  mmc: core: use sysfs_emit() instead of sprintf()  sprintf() (still used in the MMC core for the sysfs output) is vulnerable to the buffer overflow.  Use the new-fangled sysfs_emit() instead.  Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.",
                                "cve_priority": "medium",
                                "cve_public_date": "2025-02-26 07:01:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-21780",
                                "url": "https://ubuntu.com/security/CVE-2025-21780",
                                "cve_description": "In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()  It malicious user provides a small pptable through sysfs and then a bigger pptable, it may cause buffer overflow attack in function smu_sys_set_pp_table().",
                                "cve_priority": "high",
                                "cve_public_date": "2025-02-27 03:15:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * jammy/linux-kvm: 5.15.0-1093.98 -proposed tracker (LP: #2140890)",
                            "",
                            "  [ Ubuntu: 5.15.0-171.181 ]",
                            "",
                            "  * jammy/linux: 5.15.0-171.181 -proposed tracker (LP: #2140905)",
                            "  * CVE-2022-49267",
                            "    - mmc: core: use sysfs_emit() instead of sprintf()",
                            "  * CVE-2025-21780",
                            "    - drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()",
                            ""
                        ],
                        "package": "linux-kvm",
                        "version": "5.15.0-1093.98",
                        "urgency": "medium",
                        "distributions": "jammy",
                        "launchpad_bugs_fixed": [
                            2140890,
                            2140905
                        ],
                        "author": "Thibault Ferrante <thibault.ferrante@canonical.com>",
                        "date": "Fri, 13 Feb 2026 17:24:18 +0100"
                    }
                ],
                "notes": "linux-kvm-headers-5.15.0-1093 version '5.15.0-1093.98' (source package linux-kvm version '5.15.0-1093.98') was added. linux-kvm-headers-5.15.0-1093 version '5.15.0-1093.98' has the same source package name, linux-kvm, as removed package linux-headers-5.15.0-1092-kvm. As such we can use the source package version of the removed package, '5.15.0-1092.97', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "linux-modules-5.15.0-1093-kvm",
                "from_version": {
                    "source_package_name": "linux-kvm",
                    "source_package_version": "5.15.0-1092.97",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "linux-kvm",
                    "source_package_version": "5.15.0-1093.98",
                    "version": "5.15.0-1093.98"
                },
                "cves": [
                    {
                        "cve": "CVE-2022-49267",
                        "url": "https://ubuntu.com/security/CVE-2022-49267",
                        "cve_description": "In the Linux kernel, the following vulnerability has been resolved:  mmc: core: use sysfs_emit() instead of sprintf()  sprintf() (still used in the MMC core for the sysfs output) is vulnerable to the buffer overflow.  Use the new-fangled sysfs_emit() instead.  Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.",
                        "cve_priority": "medium",
                        "cve_public_date": "2025-02-26 07:01:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-21780",
                        "url": "https://ubuntu.com/security/CVE-2025-21780",
                        "cve_description": "In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()  It malicious user provides a small pptable through sysfs and then a bigger pptable, it may cause buffer overflow attack in function smu_sys_set_pp_table().",
                        "cve_priority": "high",
                        "cve_public_date": "2025-02-27 03:15:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2140890,
                    2140905
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2022-49267",
                                "url": "https://ubuntu.com/security/CVE-2022-49267",
                                "cve_description": "In the Linux kernel, the following vulnerability has been resolved:  mmc: core: use sysfs_emit() instead of sprintf()  sprintf() (still used in the MMC core for the sysfs output) is vulnerable to the buffer overflow.  Use the new-fangled sysfs_emit() instead.  Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.",
                                "cve_priority": "medium",
                                "cve_public_date": "2025-02-26 07:01:00 UTC"
                            },
                            {
                                "cve": "CVE-2025-21780",
                                "url": "https://ubuntu.com/security/CVE-2025-21780",
                                "cve_description": "In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()  It malicious user provides a small pptable through sysfs and then a bigger pptable, it may cause buffer overflow attack in function smu_sys_set_pp_table().",
                                "cve_priority": "high",
                                "cve_public_date": "2025-02-27 03:15:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * jammy/linux-kvm: 5.15.0-1093.98 -proposed tracker (LP: #2140890)",
                            "",
                            "  [ Ubuntu: 5.15.0-171.181 ]",
                            "",
                            "  * jammy/linux: 5.15.0-171.181 -proposed tracker (LP: #2140905)",
                            "  * CVE-2022-49267",
                            "    - mmc: core: use sysfs_emit() instead of sprintf()",
                            "  * CVE-2025-21780",
                            "    - drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()",
                            ""
                        ],
                        "package": "linux-kvm",
                        "version": "5.15.0-1093.98",
                        "urgency": "medium",
                        "distributions": "jammy",
                        "launchpad_bugs_fixed": [
                            2140890,
                            2140905
                        ],
                        "author": "Thibault Ferrante <thibault.ferrante@canonical.com>",
                        "date": "Fri, 13 Feb 2026 17:24:18 +0100"
                    }
                ],
                "notes": "linux-modules-5.15.0-1093-kvm version '5.15.0-1093.98' (source package linux-kvm version '5.15.0-1093.98') was added. linux-modules-5.15.0-1093-kvm version '5.15.0-1093.98' has the same source package name, linux-kvm, as removed package linux-headers-5.15.0-1092-kvm. As such we can use the source package version of the removed package, '5.15.0-1092.97', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "removed": {
        "deb": [
            {
                "name": "linux-headers-5.15.0-1092-kvm",
                "from_version": {
                    "source_package_name": "linux-kvm",
                    "source_package_version": "5.15.0-1092.97",
                    "version": "5.15.0-1092.97"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-image-5.15.0-1092-kvm",
                "from_version": {
                    "source_package_name": "linux-signed-kvm",
                    "source_package_version": "5.15.0-1092.97",
                    "version": "5.15.0-1092.97"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-kvm-headers-5.15.0-1092",
                "from_version": {
                    "source_package_name": "linux-kvm",
                    "source_package_version": "5.15.0-1092.97",
                    "version": "5.15.0-1092.97"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-modules-5.15.0-1092-kvm",
                "from_version": {
                    "source_package_name": "linux-kvm",
                    "source_package_version": "5.15.0-1092.97",
                    "version": "5.15.0-1092.97"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "notes": "Changelog diff for Ubuntu 22.04 jammy image from release image serial 20260217 to 20260223",
    "from_series": "jammy",
    "to_series": "jammy",
    "from_serial": "20260217",
    "to_serial": "20260223",
    "from_manifest_filename": "release_manifest.previous",
    "to_manifest_filename": "manifest.current"
}