{
    "summary": {
        "snap": {
            "added": [],
            "removed": [],
            "diff": []
        },
        "deb": {
            "added": [
                "busybox",
                "libperl5.42",
                "openssh-common",
                "perl-modules-5.42"
            ],
            "removed": [
                "bpfcc-tools",
                "bpftrace",
                "busybox-static",
                "cpio",
                "ieee-data",
                "libbpfcc",
                "libc-dev-bin",
                "libc6-dev",
                "libclang-cpp21",
                "libclang1-21",
                "libllvm21",
                "libperl5.40",
                "libproc2-0",
                "linux-libc-dev",
                "manpages-dev",
                "perl-modules-5.40",
                "python3-bpfcc",
                "python3-netaddr",
                "python3-pyasn1",
                "python3-pyasn1-modules",
                "rpcsvc-proto"
            ],
            "diff": [
                "adduser",
                "appstream",
                "binutils",
                "binutils-common",
                "binutils-x86-64-linux-gnu",
                "console-setup",
                "console-setup-linux",
                "coreutils",
                "coreutils-from-uutils",
                "cryptsetup",
                "cryptsetup-bin",
                "curl",
                "dirmngr",
                "dracut",
                "dracut-core",
                "dracut-install",
                "dracut-network",
                "fuse3",
                "gcc-16-base",
                "gir1.2-girepository-3.0",
                "gir1.2-glib-2.0",
                "gnupg",
                "gnupg-l10n",
                "gnupg-utils",
                "gpg",
                "gpg-agent",
                "gpg-wks-client",
                "gpgconf",
                "gpgsm",
                "gpgv",
                "hwdata",
                "ibverbs-providers",
                "info",
                "initramfs-tools-bin",
                "initramfs-tools-core",
                "install-info",
                "keyboard-configuration",
                "kpartx",
                "libappstream5",
                "libatomic1",
                "libbinutils",
                "libc-bin",
                "libc-gconv-modules-extra",
                "libc6",
                "libcryptsetup12",
                "libctf-nobfd0",
                "libctf0",
                "libcurl3t64-gnutls",
                "libcurl4t64",
                "libdebuginfod-common",
                "libdebuginfod1t64",
                "libdw1t64",
                "libelf1t64",
                "libfuse3-4",
                "libgcc-s1",
                "libgcrypt20",
                "libgirepository-2.0-0",
                "libglib2.0-0t64",
                "libglib2.0-bin",
                "libglib2.0-data",
                "libgprofng0",
                "libgstreamer1.0-0",
                "libibverbs1",
                "libintl-perl",
                "libintl-xs-perl",
                "libldap-common",
                "libldap2",
                "liblocale-gettext-perl",
                "libmpathcmd0",
                "libmpathpersist0",
                "libmultipath0",
                "libnghttp2-14",
                "libopeniscsiusr",
                "libpolkit-agent-1-0",
                "libpolkit-gobject-1-0",
                "libproc-processtable-perl",
                "libpython3-stdlib",
                "libpython3.14",
                "libpython3.14-minimal",
                "libpython3.14-stdlib",
                "libsframe3",
                "libstdc++6",
                "libterm-readkey-perl",
                "libtext-charwidth-perl",
                "libtext-iconv-perl",
                "libxml2-16",
                "linux-base",
                "linux-sysctl-defaults",
                "locales",
                "manpages",
                "mdadm",
                "multipath-tools",
                "open-iscsi",
                "open-vm-tools",
                "openssh-client",
                "openssh-server",
                "openssh-sftp-server",
                "perl",
                "perl-base",
                "pnp.ids",
                "polkitd",
                "python3",
                "python3-cffi-backend",
                "python3-cryptography",
                "python3-gdbm",
                "python3-markdown-it",
                "python3-minimal",
                "python3-openssl",
                "python3-service-identity",
                "python3-typing-extensions",
                "python3.14",
                "python3.14-gdbm",
                "python3.14-minimal",
                "rsyslog",
                "rust-coreutils",
                "snapd",
                "ubuntu-kernel-accessories",
                "ubuntu-minimal",
                "ubuntu-pro-client",
                "ubuntu-pro-client-l10n",
                "ubuntu-server",
                "ubuntu-standard",
                "vim",
                "vim-common",
                "vim-runtime",
                "vim-tiny",
                "wget",
                "xkb-data",
                "xxd"
            ]
        }
    },
    "diff": {
        "deb": [
            {
                "name": "adduser",
                "from_version": {
                    "source_package_name": "adduser",
                    "source_package_version": "3.157ubuntu1",
                    "version": "3.157ubuntu1"
                },
                "to_version": {
                    "source_package_name": "adduser",
                    "source_package_version": "3.157ubuntu2",
                    "version": "3.157ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2166367
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian/tests/f/firstlastuidgid.t:",
                            "    - Fix autopkgtest firstlastuidgid.t uid ranges conflicting with",
                            "      systemd-sysusers allocation (LP: #2166367)",
                            ""
                        ],
                        "package": "adduser",
                        "version": "3.157ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166367
                        ],
                        "author": "Sebastien Bacher <seb128@ubuntu.com>",
                        "date": "Fri, 11 Sep 2026 12:08:35 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "appstream",
                "from_version": {
                    "source_package_name": "appstream",
                    "source_package_version": "1.1.6-1",
                    "version": "1.1.6-1"
                },
                "to_version": {
                    "source_package_name": "appstream",
                    "source_package_version": "1.2.0-2",
                    "version": "1.2.0-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Adjust autopkgtests to follow the latest spec version",
                            "  * Add fix-riscv64-s390x-tests.patch:",
                            "    - Skips a failing test on s390x due to an endianness issue in",
                            "      libvips and gives the tests more time to complete on riscv64.",
                            "  * Add system-info-avoid-overflow-in-memtotal-on-32bit.patch:",
                            "    - Fix an integer overflow on 32-bit systems when measuring the",
                            "      system's physical memory size.",
                            ""
                        ],
                        "package": "appstream",
                        "version": "1.2.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klumpp <mak@debian.org>",
                        "date": "Thu, 10 Sep 2026 15:26:54 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version: 1.2.0",
                            "  * Move package Git repository to the Freedesktop.org team",
                            "  * Adjust for appstream-compose SOVERSION bump",
                            "  * Update dependencies",
                            "    - Drop gdk-pixbuf and librsvg, replaced with libvips-dev",
                            "  * Update d/copyright",
                            ""
                        ],
                        "package": "appstream",
                        "version": "1.2.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klumpp <mak@debian.org>",
                        "date": "Wed, 02 Sep 2026 22:54:06 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "binutils",
                "from_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-2ubuntu1",
                    "version": "2.47-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-6ubuntu1",
                    "version": "2.47-6ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Thu, 10 Sep 2026 15:44:45 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'gprofng.display/display.exp/jsynprog' test on arm64.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 15:31:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'ld-elf/elf.exp/Run PR ld/34184 test (PIE)' test on armhf.",
                            "    See #1147080.",
                            "  * Ignore 'ld-elf/dwarf.exp/Handle no DWARF information' test on loong64.",
                            "    See #1147079.",
                            "  * d/copyright: Replace FSF postal address with web reference.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 13:19:53 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Annotate the build autopkg test with the needs-root restriction.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 12:13:55 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream snapshot, taken from the 2.47 branch.",
                            "  * Update VCS attributes.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 11:49:12 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "binutils-common",
                "from_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-2ubuntu1",
                    "version": "2.47-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-6ubuntu1",
                    "version": "2.47-6ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Thu, 10 Sep 2026 15:44:45 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'gprofng.display/display.exp/jsynprog' test on arm64.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 15:31:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'ld-elf/elf.exp/Run PR ld/34184 test (PIE)' test on armhf.",
                            "    See #1147080.",
                            "  * Ignore 'ld-elf/dwarf.exp/Handle no DWARF information' test on loong64.",
                            "    See #1147079.",
                            "  * d/copyright: Replace FSF postal address with web reference.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 13:19:53 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Annotate the build autopkg test with the needs-root restriction.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 12:13:55 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream snapshot, taken from the 2.47 branch.",
                            "  * Update VCS attributes.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 11:49:12 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "binutils-x86-64-linux-gnu",
                "from_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-2ubuntu1",
                    "version": "2.47-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-6ubuntu1",
                    "version": "2.47-6ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Thu, 10 Sep 2026 15:44:45 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'gprofng.display/display.exp/jsynprog' test on arm64.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 15:31:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'ld-elf/elf.exp/Run PR ld/34184 test (PIE)' test on armhf.",
                            "    See #1147080.",
                            "  * Ignore 'ld-elf/dwarf.exp/Handle no DWARF information' test on loong64.",
                            "    See #1147079.",
                            "  * d/copyright: Replace FSF postal address with web reference.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 13:19:53 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Annotate the build autopkg test with the needs-root restriction.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 12:13:55 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream snapshot, taken from the 2.47 branch.",
                            "  * Update VCS attributes.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 11:49:12 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "console-setup",
                "from_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.248ubuntu2",
                    "version": "1.248ubuntu2"
                },
                "to_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.248ubuntu3",
                    "version": "1.248ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild to pick up xkeyboard-config 2.48-1",
                            ""
                        ],
                        "package": "console-setup",
                        "version": "1.248ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Rik Mills <rikmills@kde.org>",
                        "date": "Mon, 14 Sep 2026 12:24:26 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "console-setup-linux",
                "from_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.248ubuntu2",
                    "version": "1.248ubuntu2"
                },
                "to_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.248ubuntu3",
                    "version": "1.248ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild to pick up xkeyboard-config 2.48-1",
                            ""
                        ],
                        "package": "console-setup",
                        "version": "1.248ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Rik Mills <rikmills@kde.org>",
                        "date": "Mon, 14 Sep 2026 12:24:26 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "coreutils",
                "from_version": {
                    "source_package_name": "coreutils-from",
                    "source_package_version": "0.0.0~ubuntu29",
                    "version": "9.5-1ubuntu2+0.0.0~ubuntu29"
                },
                "to_version": {
                    "source_package_name": "coreutils-from",
                    "source_package_version": "2ubuntu1",
                    "version": "9.10+2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian experimental; remaining changes:",
                            "    - Build coreutils, coreutils-from-gnu",
                            "      + Only allow uutils and gnu coreutils",
                            "      + Remove Protected: yes from coreutils-from-gnu",
                            "      + Build-Depends on gnu-coreutils",
                            "  * Run update-links",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 13:23:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/rules: Bump gnu-coreutils version to 9.10",
                            "  * coreutils-from-uutils: Require 0.10",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Tue, 25 Aug 2026 13:20:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian experimental; remaining changes:",
                            "    - Specify minimum rust-coreutils version",
                            "    - Build coreutils, coreutils-from-gnu",
                            "    - Remove Protected: yes from coreutils-from-gnu",
                            "    - Only allow uutils and gnu coreutils",
                            "  * Dropped changes:",
                            "    - coreutils-from-uutils:",
                            "      + Break libdigest-sha3-perl",
                            "      + Pre-Depends gnu-coreutils",
                            "  * New changes:",
                            "    - Bump declared GNU coreutils version to 9.10",
                            "    - Bump rust-coreutils Pre-Depends to 0.10",
                            "    - Run update-links for Ubuntu",
                            "      + Install sha384sum in coreutils-from-busybox",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 13:06:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            "    - Drop coreutils, coreutils-from-gnu for unstable",
                            "  * Pick up all bug fixes from Ubuntu:",
                            "    - Remove extraneous diversions in postinst",
                            "    - diversions: Use the correct file paths for all files",
                            "    - uutils: Use /usr/lib/cargo/bin/coreutils/* as symlink targets",
                            "  * Misc:",
                            "    - Run update-links",
                            "    - d/control: Add Vcs-Git and Vcs-Browser fields",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Tue, 25 Aug 2026 12:43:42 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Initial version of swappable coreutils, for details see",
                            "    https://discourse.ubuntu.com/t/migration-to-rust-coreutils-in-25-10/59708",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "0.0.0",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Thu, 08 May 2025 12:17:09 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "coreutils-from-uutils",
                "from_version": {
                    "source_package_name": "coreutils-from",
                    "source_package_version": "0.0.0~ubuntu29",
                    "version": "0.0.0~ubuntu29"
                },
                "to_version": {
                    "source_package_name": "coreutils-from",
                    "source_package_version": "2ubuntu1",
                    "version": "2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian experimental; remaining changes:",
                            "    - Build coreutils, coreutils-from-gnu",
                            "      + Only allow uutils and gnu coreutils",
                            "      + Remove Protected: yes from coreutils-from-gnu",
                            "      + Build-Depends on gnu-coreutils",
                            "  * Run update-links",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 13:23:05 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/rules: Bump gnu-coreutils version to 9.10",
                            "  * coreutils-from-uutils: Require 0.10",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Tue, 25 Aug 2026 13:20:25 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian experimental; remaining changes:",
                            "    - Specify minimum rust-coreutils version",
                            "    - Build coreutils, coreutils-from-gnu",
                            "    - Remove Protected: yes from coreutils-from-gnu",
                            "    - Only allow uutils and gnu coreutils",
                            "  * Dropped changes:",
                            "    - coreutils-from-uutils:",
                            "      + Break libdigest-sha3-perl",
                            "      + Pre-Depends gnu-coreutils",
                            "  * New changes:",
                            "    - Bump declared GNU coreutils version to 9.10",
                            "    - Bump rust-coreutils Pre-Depends to 0.10",
                            "    - Run update-links for Ubuntu",
                            "      + Install sha384sum in coreutils-from-busybox",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <juliank@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 13:06:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            "    - Drop coreutils, coreutils-from-gnu for unstable",
                            "  * Pick up all bug fixes from Ubuntu:",
                            "    - Remove extraneous diversions in postinst",
                            "    - diversions: Use the correct file paths for all files",
                            "    - uutils: Use /usr/lib/cargo/bin/coreutils/* as symlink targets",
                            "  * Misc:",
                            "    - Run update-links",
                            "    - d/control: Add Vcs-Git and Vcs-Browser fields",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Tue, 25 Aug 2026 12:43:42 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Initial version of swappable coreutils, for details see",
                            "    https://discourse.ubuntu.com/t/migration-to-rust-coreutils-in-25-10/59708",
                            ""
                        ],
                        "package": "coreutils-from",
                        "version": "0.0.0",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Julian Andres Klode <jak@debian.org>",
                        "date": "Thu, 08 May 2025 12:17:09 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "cryptsetup",
                "from_version": {
                    "source_package_name": "cryptsetup",
                    "source_package_version": "2:2.8.7-1ubuntu1",
                    "version": "2:2.8.7-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "cryptsetup",
                    "source_package_version": "2:2.8.7-1ubuntu3",
                    "version": "2:2.8.7-1ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167087
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop alternative busybox-static dependency (LP: #2167087)",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167087
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Sat, 12 Sep 2026 23:44:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop test-use-gnudd-as-workaround-in-luks2-reencryption-mangle.patch",
                            "    This workaround is not needed with rust-coreutils 0.10 any more.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Thu, 10 Sep 2026 16:29:47 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "cryptsetup-bin",
                "from_version": {
                    "source_package_name": "cryptsetup",
                    "source_package_version": "2:2.8.7-1ubuntu1",
                    "version": "2:2.8.7-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "cryptsetup",
                    "source_package_version": "2:2.8.7-1ubuntu3",
                    "version": "2:2.8.7-1ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167087
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop alternative busybox-static dependency (LP: #2167087)",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167087
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Sat, 12 Sep 2026 23:44:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop test-use-gnudd-as-workaround-in-luks2-reencryption-mangle.patch",
                            "    This workaround is not needed with rust-coreutils 0.10 any more.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Thu, 10 Sep 2026 16:29:47 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "curl",
                "from_version": {
                    "source_package_name": "curl",
                    "source_package_version": "8.20.0-2ubuntu1",
                    "version": "8.20.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "curl",
                    "source_package_version": "8.20.0-2ubuntu3",
                    "version": "8.20.0-2ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-8932",
                        "url": "https://ubuntu.com/security/CVE-2026-8932",
                        "cve_description": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-07-03 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-8932",
                                "url": "https://ubuntu.com/security/CVE-2026-8932",
                                "cve_description": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-07-03 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Authentication Bypass in connection reuse.",
                            "    - debian/patches/CVE-2026-8932.patch: Fix incomplete mTLS config in",
                            "      lib/ldap.c, lib/urldata.h, lib/vssh/libssh.c, lib/vssh/libssh2.c,",
                            "      lib/vtls/gtls.c, lib/vtls/mbedtls.c, lib/vtls/openssl.c,",
                            "      lib/vtls/rustls.c, lib/vtls/schannel.c, lib/vtls/vtls.c,",
                            "      lib/vtls/vtls_scache.c, and lib/vtls/wolfssl.c.",
                            "    - CVE-2026-8932",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.20.0-2ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Tue, 08 Sep 2026 12:31:08 -0600"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.20.0-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:19 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dirmngr",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu3",
                    "version": "2.4.9-4ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-57062",
                        "url": "https://ubuntu.com/security/CVE-2026-57062",
                        "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-23 18:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-57062",
                                "url": "https://ubuntu.com/security/CVE-2026-57062",
                                "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-23 18:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Improper Input Validation",
                            "    - debian/patches/CVE-2026-57062.patch: gpgsm: Require a minimum tag length",
                            "      for GCM decryption. in sm/decrypt.c.",
                            "    - CVE-2026-57062",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Wed, 02 Sep 2026 15:37:13 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dracut",
                "from_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-5",
                    "version": "112-5"
                },
                "to_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-6",
                    "version": "112-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - fix(dracut): export prefer_dracutmodules to be used in dracut modules",
                            "    - fix(bluetooth): do not warn if this module is included via --prefer",
                            "    - docs(cli): formatting & grammar fix for DRACUT_INSTALL_LOG_{TARGET,LEVEL}",
                            "    - test(BUSYBOX): check built with CONFIG_FEATURE_TR_CLASSES",
                            "  * dracut-core: explicitly list man pages to include",
                            "  * Drop recommending busybox-static as alternative to busybox (bug #1147074)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Fri, 11 Sep 2026 13:18:57 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dracut-core",
                "from_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-5",
                    "version": "112-5"
                },
                "to_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-6",
                    "version": "112-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - fix(dracut): export prefer_dracutmodules to be used in dracut modules",
                            "    - fix(bluetooth): do not warn if this module is included via --prefer",
                            "    - docs(cli): formatting & grammar fix for DRACUT_INSTALL_LOG_{TARGET,LEVEL}",
                            "    - test(BUSYBOX): check built with CONFIG_FEATURE_TR_CLASSES",
                            "  * dracut-core: explicitly list man pages to include",
                            "  * Drop recommending busybox-static as alternative to busybox (bug #1147074)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Fri, 11 Sep 2026 13:18:57 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dracut-install",
                "from_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-5",
                    "version": "112-5"
                },
                "to_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-6",
                    "version": "112-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - fix(dracut): export prefer_dracutmodules to be used in dracut modules",
                            "    - fix(bluetooth): do not warn if this module is included via --prefer",
                            "    - docs(cli): formatting & grammar fix for DRACUT_INSTALL_LOG_{TARGET,LEVEL}",
                            "    - test(BUSYBOX): check built with CONFIG_FEATURE_TR_CLASSES",
                            "  * dracut-core: explicitly list man pages to include",
                            "  * Drop recommending busybox-static as alternative to busybox (bug #1147074)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Fri, 11 Sep 2026 13:18:57 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "dracut-network",
                "from_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-5",
                    "version": "112-5"
                },
                "to_version": {
                    "source_package_name": "dracut",
                    "source_package_version": "112-6",
                    "version": "112-6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Cherry-pick several upstream commits:",
                            "    - fix(dracut): export prefer_dracutmodules to be used in dracut modules",
                            "    - fix(bluetooth): do not warn if this module is included via --prefer",
                            "    - docs(cli): formatting & grammar fix for DRACUT_INSTALL_LOG_{TARGET,LEVEL}",
                            "    - test(BUSYBOX): check built with CONFIG_FEATURE_TR_CLASSES",
                            "  * dracut-core: explicitly list man pages to include",
                            "  * Drop recommending busybox-static as alternative to busybox (bug #1147074)",
                            ""
                        ],
                        "package": "dracut",
                        "version": "112-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@debian.org>",
                        "date": "Fri, 11 Sep 2026 13:18:57 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "fuse3",
                "from_version": {
                    "source_package_name": "fuse3",
                    "source_package_version": "3.18.2-2",
                    "version": "3.18.2-2"
                },
                "to_version": {
                    "source_package_name": "fuse3",
                    "source_package_version": "3.18.3-1",
                    "version": "3.18.3-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "fuse3",
                        "version": "3.18.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sun, 13 Sep 2026 08:42:13 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gcc-16-base",
                "from_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-1ubuntu1",
                    "version": "16.2.0-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-2ubuntu1",
                    "version": "16.2.0-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Wed, 02 Sep 2026 10:52:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260902 from the gcc-16 branch.",
                            "    - Fix PR middle-end/127098, PR tree-optimization/127105,",
                            "      PR tree-optimization/127100, PR target/120681 (PPC),",
                            "      PR target/120528 (PPC), PR target/99293 (PPC), PR target/117487 (PPC),",
                            "      PR ada/125984, PR ipa/127023, PR target/126873 (RISCV),",
                            "      PR rtl-optimization/126426, PR target/127004 (AVR), PR middle-end/126939,",
                            "      PR target/126787 (x86), PR target/126513 (PPC),",
                            "      PR target/124629 (AArch64), PR tree-optimization/126925,",
                            "      PR tree-optimization/126650, PR tree-optimization/126926,",
                            "      PR tree-optimization/126534, PR target/126454 (RISCV),",
                            "      PR target/126334 (RISCV), PR target/126550 (RISCV),",
                            "      PR target/126676 (x86), PR target/126320 (x86), PR target/126450 (x86),",
                            "      PR target/126529 (x86), PR ada/127026, PR ada/127026, PR ada/126928,",
                            "      PR ada/126907, PR c++/127046, PR c++/124888, PR c++/126335,",
                            "      PR c++/124794, PR c++/126546, PR c++/124811, PR c++/126918,",
                            "      PR c++/126867, PR c++/126752, PR c++/126093, PR c++/126483,",
                            "      PR c++/126754, PR c++/126783, PR c++/124794, PR c++/125069,",
                            "      PR c++/124806, PR fortran/98573, PR fortran/105594, PR fortran/88632,",
                            "      PR fortran/104630, PR fortran/126872, PR fortran/110626,",
                            "      PR fortran/104048, PR target/125803 (PPC), PR libstdc++/118665,",
                            "      PR libstdc++/123510, PR libstdc++/122981, PR libstdc++/127006,",
                            "      PR libstdc++/126731, PR libstdc++/125981, PR libstdc++/126452,",
                            "      PR libstdc++/126849.",
                            "  * Only enable LRA by default on m68k for snapshot builds. Closes: #1143971.",
                            "  * Don't apply the SH LRA patches for snapshot builds. Closes: #1146439.",
                            "  * Disable usage stats for the build.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 02 Sep 2026 11:07:42 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gir1.2-girepository-3.0",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.3-4",
                    "version": "2.89.3-4"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.90.0-1",
                    "version": "2.90.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.90.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Thu, 10 Sep 2026 12:07:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Re-upload with orig tarball, no source changes",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 19:33:06 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes a main-loop regression in 2.89.3 (mutter#4994 upstream)",
                            "  * d/patches: Drop patches that were part of the upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 18:52:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Fri, 21 Aug 2026 16:37:11 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gir1.2-glib-2.0",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.3-4",
                    "version": "2.89.3-4"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.90.0-1",
                    "version": "2.90.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.90.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Thu, 10 Sep 2026 12:07:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Re-upload with orig tarball, no source changes",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 19:33:06 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes a main-loop regression in 2.89.3 (mutter#4994 upstream)",
                            "  * d/patches: Drop patches that were part of the upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 18:52:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Fri, 21 Aug 2026 16:37:11 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gnupg",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu3",
                    "version": "2.4.9-4ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-57062",
                        "url": "https://ubuntu.com/security/CVE-2026-57062",
                        "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-23 18:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-57062",
                                "url": "https://ubuntu.com/security/CVE-2026-57062",
                                "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-23 18:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Improper Input Validation",
                            "    - debian/patches/CVE-2026-57062.patch: gpgsm: Require a minimum tag length",
                            "      for GCM decryption. in sm/decrypt.c.",
                            "    - CVE-2026-57062",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Wed, 02 Sep 2026 15:37:13 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gnupg-l10n",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu3",
                    "version": "2.4.9-4ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-57062",
                        "url": "https://ubuntu.com/security/CVE-2026-57062",
                        "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-23 18:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-57062",
                                "url": "https://ubuntu.com/security/CVE-2026-57062",
                                "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-23 18:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Improper Input Validation",
                            "    - debian/patches/CVE-2026-57062.patch: gpgsm: Require a minimum tag length",
                            "      for GCM decryption. in sm/decrypt.c.",
                            "    - CVE-2026-57062",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Wed, 02 Sep 2026 15:37:13 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gnupg-utils",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu3",
                    "version": "2.4.9-4ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-57062",
                        "url": "https://ubuntu.com/security/CVE-2026-57062",
                        "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-23 18:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-57062",
                                "url": "https://ubuntu.com/security/CVE-2026-57062",
                                "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-23 18:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Improper Input Validation",
                            "    - debian/patches/CVE-2026-57062.patch: gpgsm: Require a minimum tag length",
                            "      for GCM decryption. in sm/decrypt.c.",
                            "    - CVE-2026-57062",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Wed, 02 Sep 2026 15:37:13 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gpg",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu3",
                    "version": "2.4.9-4ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-57062",
                        "url": "https://ubuntu.com/security/CVE-2026-57062",
                        "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-23 18:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-57062",
                                "url": "https://ubuntu.com/security/CVE-2026-57062",
                                "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-23 18:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Improper Input Validation",
                            "    - debian/patches/CVE-2026-57062.patch: gpgsm: Require a minimum tag length",
                            "      for GCM decryption. in sm/decrypt.c.",
                            "    - CVE-2026-57062",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Wed, 02 Sep 2026 15:37:13 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gpg-agent",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu3",
                    "version": "2.4.9-4ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-57062",
                        "url": "https://ubuntu.com/security/CVE-2026-57062",
                        "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-23 18:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-57062",
                                "url": "https://ubuntu.com/security/CVE-2026-57062",
                                "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-23 18:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Improper Input Validation",
                            "    - debian/patches/CVE-2026-57062.patch: gpgsm: Require a minimum tag length",
                            "      for GCM decryption. in sm/decrypt.c.",
                            "    - CVE-2026-57062",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Wed, 02 Sep 2026 15:37:13 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gpg-wks-client",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu3",
                    "version": "2.4.9-4ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-57062",
                        "url": "https://ubuntu.com/security/CVE-2026-57062",
                        "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-23 18:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-57062",
                                "url": "https://ubuntu.com/security/CVE-2026-57062",
                                "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-23 18:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Improper Input Validation",
                            "    - debian/patches/CVE-2026-57062.patch: gpgsm: Require a minimum tag length",
                            "      for GCM decryption. in sm/decrypt.c.",
                            "    - CVE-2026-57062",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Wed, 02 Sep 2026 15:37:13 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gpgconf",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu3",
                    "version": "2.4.9-4ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-57062",
                        "url": "https://ubuntu.com/security/CVE-2026-57062",
                        "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-23 18:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-57062",
                                "url": "https://ubuntu.com/security/CVE-2026-57062",
                                "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-23 18:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Improper Input Validation",
                            "    - debian/patches/CVE-2026-57062.patch: gpgsm: Require a minimum tag length",
                            "      for GCM decryption. in sm/decrypt.c.",
                            "    - CVE-2026-57062",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Wed, 02 Sep 2026 15:37:13 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gpgsm",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu3",
                    "version": "2.4.9-4ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-57062",
                        "url": "https://ubuntu.com/security/CVE-2026-57062",
                        "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-23 18:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-57062",
                                "url": "https://ubuntu.com/security/CVE-2026-57062",
                                "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-23 18:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Improper Input Validation",
                            "    - debian/patches/CVE-2026-57062.patch: gpgsm: Require a minimum tag length",
                            "      for GCM decryption. in sm/decrypt.c.",
                            "    - CVE-2026-57062",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Wed, 02 Sep 2026 15:37:13 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "gpgv",
                "from_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu2",
                    "version": "2.4.9-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "gnupg2",
                    "source_package_version": "2.4.9-4ubuntu3",
                    "version": "2.4.9-4ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-57062",
                        "url": "https://ubuntu.com/security/CVE-2026-57062",
                        "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-06-23 18:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-57062",
                                "url": "https://ubuntu.com/security/CVE-2026-57062",
                                "cve_description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-06-23 18:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Improper Input Validation",
                            "    - debian/patches/CVE-2026-57062.patch: gpgsm: Require a minimum tag length",
                            "      for GCM decryption. in sm/decrypt.c.",
                            "    - CVE-2026-57062",
                            ""
                        ],
                        "package": "gnupg2",
                        "version": "2.4.9-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "John Breton <john.breton@canonical.com>",
                        "date": "Wed, 02 Sep 2026 15:37:13 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "hwdata",
                "from_version": {
                    "source_package_name": "hwdata",
                    "source_package_version": "0.394-1build1",
                    "version": "0.394-1build1"
                },
                "to_version": {
                    "source_package_name": "hwdata",
                    "source_package_version": "0.411-1",
                    "version": "0.411-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * CI: update/simplify configuration.",
                            "  * Bump Standards-Version to 4.7.4, no changes required.",
                            "  * Drop Rules-Requires-Root: no, no more needed since Debian trixie.",
                            "  * Drop Priority: optional, no more needed since dpkg 1.22.13.",
                            "  * Covert watch file to v5.",
                            ""
                        ],
                        "package": "hwdata",
                        "version": "0.411-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Pino Toscano <pino@debian.org>",
                        "date": "Mon, 07 Sep 2026 06:28:58 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ibverbs-providers",
                "from_version": {
                    "source_package_name": "rdma-core",
                    "source_package_version": "63.0-2ubuntu1",
                    "version": "63.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "rdma-core",
                    "source_package_version": "64.0-1ubuntu1",
                    "version": "64.0-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2165887
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2165887).",
                            "  * Remaining changes:",
                            "    - Do not build-depend on pandoc on i386 (not available there).",
                            "  * New changes:",
                            "    - d/rules: do not build man pages on i386 (-DNO_MAN_PAGES=1) and drop",
                            "      them from the .install files. The GitHub tag tarball fetched by",
                            "      d/watch since 63.0-2 ships no prebuilt man pages, so building without",
                            "      pandoc no longer works. i386 binary packages ship no man pages.",
                            ""
                        ],
                        "package": "rdma-core",
                        "version": "64.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165887
                        ],
                        "author": "Tomáš Virtus <tomas.virtus@canonical.com>",
                        "date": "Tue, 01 Sep 2026 12:59:55 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * Drop patches applied upstream",
                            "  * Update private libibverbs1 symbols",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "rdma-core",
                        "version": "64.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Mon, 31 Aug 2026 11:52:10 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "info",
                "from_version": {
                    "source_package_name": "texinfo",
                    "source_package_version": "7.2-5ubuntu2",
                    "version": "7.2-5ubuntu2"
                },
                "to_version": {
                    "source_package_name": "texinfo",
                    "source_package_version": "7.3-2build1",
                    "version": "7.3-2build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.3-2build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 11:10:52 -0700"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            "  * Lintian stuff.",
                            "  * Do not remove doc files, which are not regenerated during build",
                            "    (Closes: #1128912).",
                            "  * Improve d/copyright file a lot: still not complete according to",
                            "    licenserecon (Closes: #1129629).",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Hilmar Preuße <hille42@debian.org>",
                        "date": "Mon, 23 Mar 2026 10:53:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  Final release TeXInfo 7.3",
                            "  * Contains fix: crash when building the gcc-12-doc package.",
                            "  * Lot of (www.)gnu.org URLs use to https protocol",
                            "    (Closes: #1105214)",
                            "",
                            "  * Add patch for buggy resolution of cross-references (Closes: #484740).",
                            "  * Enable (still experimental) SWIG interface of TeXInfo.",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Hilmar Preuße <hille42@debian.org>",
                        "date": "Tue, 03 Mar 2026 22:46:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream (beta) version.",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.2.92-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Hilmar Preuße <hille42@debian.org>",
                        "date": "Sun, 22 Feb 2026 11:57:35 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream (beta) version.",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.2.91-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Hilmar Preuße <hille42@debian.org>",
                        "date": "Mon, 09 Feb 2026 14:36:42 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore comments in /etc/environment (Closes: #1127091).",
                            "  * Add libcrypt-dev to BD (Closes: #1127328).",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.2.90-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Hilmar Preuße <hille42@debian.org>",
                        "date": "Sun, 08 Feb 2026 15:12:35 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream (beta) version.",
                            "  * Bump Standards version, no changes needed.",
                            "  * Add patch from Daniel Abrecht <deb@danielabrecht.ch> to stop",
                            "    sourcing /etc/environment (Closes: #1114610).",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.2.90-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Hilmar Preuße <hille42@debian.org>",
                        "date": "Thu, 05 Feb 2026 23:00:19 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "initramfs-tools-bin",
                "from_version": {
                    "source_package_name": "initramfs-tools",
                    "source_package_version": "0.151ubuntu2",
                    "version": "0.151ubuntu2"
                },
                "to_version": {
                    "source_package_name": "initramfs-tools",
                    "source_package_version": "0.151ubuntu3",
                    "version": "0.151ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167087
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop alternative busybox-static recommends (LP: #2167087)",
                            ""
                        ],
                        "package": "initramfs-tools",
                        "version": "0.151ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167087
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Sun, 13 Sep 2026 22:20:32 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "initramfs-tools-core",
                "from_version": {
                    "source_package_name": "initramfs-tools",
                    "source_package_version": "0.151ubuntu2",
                    "version": "0.151ubuntu2"
                },
                "to_version": {
                    "source_package_name": "initramfs-tools",
                    "source_package_version": "0.151ubuntu3",
                    "version": "0.151ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167087
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop alternative busybox-static recommends (LP: #2167087)",
                            ""
                        ],
                        "package": "initramfs-tools",
                        "version": "0.151ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167087
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Sun, 13 Sep 2026 22:20:32 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "install-info",
                "from_version": {
                    "source_package_name": "texinfo",
                    "source_package_version": "7.2-5ubuntu2",
                    "version": "7.2-5ubuntu2"
                },
                "to_version": {
                    "source_package_name": "texinfo",
                    "source_package_version": "7.3-2build1",
                    "version": "7.3-2build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.3-2build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 11:10:52 -0700"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            "  * Lintian stuff.",
                            "  * Do not remove doc files, which are not regenerated during build",
                            "    (Closes: #1128912).",
                            "  * Improve d/copyright file a lot: still not complete according to",
                            "    licenserecon (Closes: #1129629).",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.3-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Hilmar Preuße <hille42@debian.org>",
                        "date": "Mon, 23 Mar 2026 10:53:09 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  Final release TeXInfo 7.3",
                            "  * Contains fix: crash when building the gcc-12-doc package.",
                            "  * Lot of (www.)gnu.org URLs use to https protocol",
                            "    (Closes: #1105214)",
                            "",
                            "  * Add patch for buggy resolution of cross-references (Closes: #484740).",
                            "  * Enable (still experimental) SWIG interface of TeXInfo.",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.3-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Hilmar Preuße <hille42@debian.org>",
                        "date": "Tue, 03 Mar 2026 22:46:58 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream (beta) version.",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.2.92-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Hilmar Preuße <hille42@debian.org>",
                        "date": "Sun, 22 Feb 2026 11:57:35 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream (beta) version.",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.2.91-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Hilmar Preuße <hille42@debian.org>",
                        "date": "Mon, 09 Feb 2026 14:36:42 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore comments in /etc/environment (Closes: #1127091).",
                            "  * Add libcrypt-dev to BD (Closes: #1127328).",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.2.90-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Hilmar Preuße <hille42@debian.org>",
                        "date": "Sun, 08 Feb 2026 15:12:35 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream (beta) version.",
                            "  * Bump Standards version, no changes needed.",
                            "  * Add patch from Daniel Abrecht <deb@danielabrecht.ch> to stop",
                            "    sourcing /etc/environment (Closes: #1114610).",
                            ""
                        ],
                        "package": "texinfo",
                        "version": "7.2.90-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Hilmar Preuße <hille42@debian.org>",
                        "date": "Thu, 05 Feb 2026 23:00:19 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "keyboard-configuration",
                "from_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.248ubuntu2",
                    "version": "1.248ubuntu2"
                },
                "to_version": {
                    "source_package_name": "console-setup",
                    "source_package_version": "1.248ubuntu3",
                    "version": "1.248ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild to pick up xkeyboard-config 2.48-1",
                            ""
                        ],
                        "package": "console-setup",
                        "version": "1.248ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Rik Mills <rikmills@kde.org>",
                        "date": "Mon, 14 Sep 2026 12:24:26 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "kpartx",
                "from_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu1",
                    "version": "0.14.3-3ubuntu1"
                },
                "to_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu2",
                    "version": "0.14.3-3ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2165993
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Pass the -s option instead of --syslog when invoking modprobe. The",
                            "    long option is not compatible with busybox's implementation of modprobe",
                            "    (LP: #2165993).",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165993
                        ],
                        "author": "Olivier Gayot <olivier.gayot@canonical.com>",
                        "date": "Mon, 07 Sep 2026 18:14:02 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libappstream5",
                "from_version": {
                    "source_package_name": "appstream",
                    "source_package_version": "1.1.6-1",
                    "version": "1.1.6-1"
                },
                "to_version": {
                    "source_package_name": "appstream",
                    "source_package_version": "1.2.0-2",
                    "version": "1.2.0-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Adjust autopkgtests to follow the latest spec version",
                            "  * Add fix-riscv64-s390x-tests.patch:",
                            "    - Skips a failing test on s390x due to an endianness issue in",
                            "      libvips and gives the tests more time to complete on riscv64.",
                            "  * Add system-info-avoid-overflow-in-memtotal-on-32bit.patch:",
                            "    - Fix an integer overflow on 32-bit systems when measuring the",
                            "      system's physical memory size.",
                            ""
                        ],
                        "package": "appstream",
                        "version": "1.2.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klumpp <mak@debian.org>",
                        "date": "Thu, 10 Sep 2026 15:26:54 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version: 1.2.0",
                            "  * Move package Git repository to the Freedesktop.org team",
                            "  * Adjust for appstream-compose SOVERSION bump",
                            "  * Update dependencies",
                            "    - Drop gdk-pixbuf and librsvg, replaced with libvips-dev",
                            "  * Update d/copyright",
                            ""
                        ],
                        "package": "appstream",
                        "version": "1.2.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klumpp <mak@debian.org>",
                        "date": "Wed, 02 Sep 2026 22:54:06 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libatomic1",
                "from_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-1ubuntu1",
                    "version": "16.2.0-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-2ubuntu1",
                    "version": "16.2.0-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Wed, 02 Sep 2026 10:52:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260902 from the gcc-16 branch.",
                            "    - Fix PR middle-end/127098, PR tree-optimization/127105,",
                            "      PR tree-optimization/127100, PR target/120681 (PPC),",
                            "      PR target/120528 (PPC), PR target/99293 (PPC), PR target/117487 (PPC),",
                            "      PR ada/125984, PR ipa/127023, PR target/126873 (RISCV),",
                            "      PR rtl-optimization/126426, PR target/127004 (AVR), PR middle-end/126939,",
                            "      PR target/126787 (x86), PR target/126513 (PPC),",
                            "      PR target/124629 (AArch64), PR tree-optimization/126925,",
                            "      PR tree-optimization/126650, PR tree-optimization/126926,",
                            "      PR tree-optimization/126534, PR target/126454 (RISCV),",
                            "      PR target/126334 (RISCV), PR target/126550 (RISCV),",
                            "      PR target/126676 (x86), PR target/126320 (x86), PR target/126450 (x86),",
                            "      PR target/126529 (x86), PR ada/127026, PR ada/127026, PR ada/126928,",
                            "      PR ada/126907, PR c++/127046, PR c++/124888, PR c++/126335,",
                            "      PR c++/124794, PR c++/126546, PR c++/124811, PR c++/126918,",
                            "      PR c++/126867, PR c++/126752, PR c++/126093, PR c++/126483,",
                            "      PR c++/126754, PR c++/126783, PR c++/124794, PR c++/125069,",
                            "      PR c++/124806, PR fortran/98573, PR fortran/105594, PR fortran/88632,",
                            "      PR fortran/104630, PR fortran/126872, PR fortran/110626,",
                            "      PR fortran/104048, PR target/125803 (PPC), PR libstdc++/118665,",
                            "      PR libstdc++/123510, PR libstdc++/122981, PR libstdc++/127006,",
                            "      PR libstdc++/126731, PR libstdc++/125981, PR libstdc++/126452,",
                            "      PR libstdc++/126849.",
                            "  * Only enable LRA by default on m68k for snapshot builds. Closes: #1143971.",
                            "  * Don't apply the SH LRA patches for snapshot builds. Closes: #1146439.",
                            "  * Disable usage stats for the build.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 02 Sep 2026 11:07:42 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libbinutils",
                "from_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-2ubuntu1",
                    "version": "2.47-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-6ubuntu1",
                    "version": "2.47-6ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Thu, 10 Sep 2026 15:44:45 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'gprofng.display/display.exp/jsynprog' test on arm64.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 15:31:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'ld-elf/elf.exp/Run PR ld/34184 test (PIE)' test on armhf.",
                            "    See #1147080.",
                            "  * Ignore 'ld-elf/dwarf.exp/Handle no DWARF information' test on loong64.",
                            "    See #1147079.",
                            "  * d/copyright: Replace FSF postal address with web reference.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 13:19:53 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Annotate the build autopkg test with the needs-root restriction.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 12:13:55 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream snapshot, taken from the 2.47 branch.",
                            "  * Update VCS attributes.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 11:49:12 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc-bin",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2.3",
                    "version": "2.43-2ubuntu2.3"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.44-1ubuntu1",
                    "version": "2.44-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6791",
                        "url": "https://ubuntu.com/security/CVE-2026-6791",
                        "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-10 19:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163528
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from Debian experimental (LP: #2163528)",
                            "    Delta dropped:",
                            "    - Revert \"debian/rules.d/build.mk: add a makefile function to filter out",
                            "      dpkg build flags incompatible with glibc and define CFLAGS from dpkg",
                            "       build flags. Closes: #1129746.\"",
                            "    - fix ftbfs: backport OPEN_TREE conditional define (LP #2145679)",
                            "      [fixed upstream in 2.44]",
                            "    - debian/patches/CVE-2026-4046.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5435.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5450.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-5928.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-6238-*.patch",
                            "      [fixed in 2.43-3]",
                            "  * Delta added:",
                            "    - filter -flto=auto from dpkg-buildflags to fix build",
                            "    - fix tst-spawn-chdir with coreutils-rs due to invalid link name",
                            "    - xfail tst-nscd-basic tstptrguard-static-dlopen (LP #2164576)",
                            "    - d/tests: fix gcc dependency cross conflict on i386 autopkgtest",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163528
                        ],
                        "author": "Simon Poirier <simon.poirier@canonical.com>",
                        "date": "Tue, 11 Aug 2026 18:48:32 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * New upstream release:",
                            "    - debian/patches/localedata/sort-UTF8-first.diff: rebased.",
                            "    - debian/patches/hurd-i386/local-enable-ldconfig.diff: rebased.",
                            "    - debian/patches/hurd-i386/tg-libc_rwlock_recursive.diff: dropped,",
                            "      obsolete.",
                            "    - debian/patches/hurd-i386/git-fork-gdb.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-sig-mmx-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-cancel-sig.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-mach_send_eintr.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-itimer-lock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-posix-timers.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-alarm.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-libio-mtsafe.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-timedrwlock-unlock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sigtimedwait-timeout.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-MSG_EXAMINE.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-interrupt-EINTR.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SEM_FAILED.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-tst-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-path_mounted.diff: upstreamed.",
                            "    - debian/patches/any/local-nss-overflow.diff: upstreamed.",
                            "    - debian/patches/any/local-ldconfig-multiarch.diff: refreshed.",
                            "    - debian/symbols.wildcards: add 2.44.",
                            "    - debian/sysdeps/arm64.mk: stop passing --enable-memory-tagging to",
                            "      configure, support for it was removed upstream.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/submitted-net.diff: rebased.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 15:02:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6791",
                                "url": "https://ubuntu.com/security/CVE-2026-6791",
                                "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-10 19:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/testsuite-xfail-debian.mk: Update hurd results.",
                            "  * debian/patches/hurd-i386/submitted-path_mounted.diff: Renamed to",
                            "    git-path_mounted.diff.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - debian/patches/hurd-i386/local-disable-ioctls.diff: rebased.",
                            "    - debian/patches/hurd-i386/submitted-AF_LINK.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/submitted-AF_ROUTE.diff: upstreamed.",
                            "    - Fix a buffer overread in ns_sprintrrf with corrupted RDATA field",
                            "      (CVE-2026-6238).  Closes: #1135231.",
                            "    - Fix an out-of-bounds write in ns_sprintrrf when printing TSIG records",
                            "      (CVE-2026-5435).  Closes: #1135230.",
                            "    - Fix stack overflow in wordexp tilde expansion (CVE-2026-6791).",
                            "    - Cache cpuid results in ld.so for Intel CPUs.",
                            "    - Restore optimized memchr for POWER10.",
                            "  * debian/control.in/libc, debian/rules.d/debhelper.mk: drop the libc6-dev",
                            "    dependency on rpcsvc-proto.",
                            "  * debian/watch: set Git-Mode to shallow.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 14:19:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix buffer overflow in scanf %mc (CVE-2026-5450).  Closes: #1134543.",
                            "    - Fix ungetwc operating on byte stream (CVE-2026-5928).  Closes: #1134544.",
                            "    - Save/restore VFP registers inPLT trampolines on arm.  Closes: #1133139.",
                            "    - Suppress iconv intermediate errors with //TRANSLIT.",
                            "    - debian/patches/hurd-i386/git-run-iconv-test.sh.diff: rebased.",
                            "  * debian/rules.d/build.mk: append extra_cflags to CFLAGS and ASFLAGS.",
                            "  * debian/control.in/libc: stop suggesting libnss-nisplus.",
                            "  * debian/debhelper.in/libc-bin.lintian-overrides: add a",
                            "    statically-linked-binary override for the ldconfig binary.",
                            "  * debian/control.in/main: build-depends on libselinux-dev instead of",
                            "    libselinux1-dev.",
                            "",
                            "  [ Miao Wang ]",
                            "  * debian/libc6.symbols.loong64: add.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: Add SO_TIMESTAMP macro.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 18 Jun 2026 21:48:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/sysdeps/mips*.mk: revert change to match the dpkg architecture",
                            "    name.",
                            "  * debian/rules.d/build.mk, debian/sysdeps/mips*.mk: add a way to define the",
                            "    debian architecture corresponding to a multilib build. Use it when it",
                            "    doesn't match the name of the pass and package like on mips*.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix build against linux 7.0 headers.  Closes: #1135405.",
                            "",
                            "  [ liu jianqiang ]",
                            "  * debian/debhelper.in/locales.config: handle leading spaces in",
                            "    /etc/locale.gen configuration.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 07 May 2026 00:25:31 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix random failure of tst-link-map-contiguous-ldso.",
                            "    - Fix tst-rseq with Linux 7.0.",
                            "    - Fix a possible crash due to an assertion failure when converting inputs",
                            "      from the IBM139x character sets (CVE-2026-4046).  Closes: #1132499.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-MSG_EXAMINE.diff: alterations to MSG_EXAMINE",
                            "    interface.",
                            "  * debian/patches/hurd-i386/git-interrupt-EINTR.diff: Interrupted RPC returning",
                            "    EINTR when server has actually changed state.",
                            "  * debian/patches/hurd-i386/git-SEM_FAILED.diff: Fix SEM_FAILED type.",
                            "  * debian/patches/hurd-i386/git-tst-fix.diff: Fix test build.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-15",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Sun, 19 Apr 2026 15:41:41 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc-gconv-modules-extra",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2.3",
                    "version": "2.43-2ubuntu2.3"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.44-1ubuntu1",
                    "version": "2.44-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6791",
                        "url": "https://ubuntu.com/security/CVE-2026-6791",
                        "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-10 19:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163528
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from Debian experimental (LP: #2163528)",
                            "    Delta dropped:",
                            "    - Revert \"debian/rules.d/build.mk: add a makefile function to filter out",
                            "      dpkg build flags incompatible with glibc and define CFLAGS from dpkg",
                            "       build flags. Closes: #1129746.\"",
                            "    - fix ftbfs: backport OPEN_TREE conditional define (LP #2145679)",
                            "      [fixed upstream in 2.44]",
                            "    - debian/patches/CVE-2026-4046.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5435.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5450.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-5928.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-6238-*.patch",
                            "      [fixed in 2.43-3]",
                            "  * Delta added:",
                            "    - filter -flto=auto from dpkg-buildflags to fix build",
                            "    - fix tst-spawn-chdir with coreutils-rs due to invalid link name",
                            "    - xfail tst-nscd-basic tstptrguard-static-dlopen (LP #2164576)",
                            "    - d/tests: fix gcc dependency cross conflict on i386 autopkgtest",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163528
                        ],
                        "author": "Simon Poirier <simon.poirier@canonical.com>",
                        "date": "Tue, 11 Aug 2026 18:48:32 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * New upstream release:",
                            "    - debian/patches/localedata/sort-UTF8-first.diff: rebased.",
                            "    - debian/patches/hurd-i386/local-enable-ldconfig.diff: rebased.",
                            "    - debian/patches/hurd-i386/tg-libc_rwlock_recursive.diff: dropped,",
                            "      obsolete.",
                            "    - debian/patches/hurd-i386/git-fork-gdb.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-sig-mmx-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-cancel-sig.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-mach_send_eintr.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-itimer-lock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-posix-timers.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-alarm.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-libio-mtsafe.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-timedrwlock-unlock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sigtimedwait-timeout.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-MSG_EXAMINE.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-interrupt-EINTR.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SEM_FAILED.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-tst-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-path_mounted.diff: upstreamed.",
                            "    - debian/patches/any/local-nss-overflow.diff: upstreamed.",
                            "    - debian/patches/any/local-ldconfig-multiarch.diff: refreshed.",
                            "    - debian/symbols.wildcards: add 2.44.",
                            "    - debian/sysdeps/arm64.mk: stop passing --enable-memory-tagging to",
                            "      configure, support for it was removed upstream.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/submitted-net.diff: rebased.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 15:02:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6791",
                                "url": "https://ubuntu.com/security/CVE-2026-6791",
                                "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-10 19:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/testsuite-xfail-debian.mk: Update hurd results.",
                            "  * debian/patches/hurd-i386/submitted-path_mounted.diff: Renamed to",
                            "    git-path_mounted.diff.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - debian/patches/hurd-i386/local-disable-ioctls.diff: rebased.",
                            "    - debian/patches/hurd-i386/submitted-AF_LINK.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/submitted-AF_ROUTE.diff: upstreamed.",
                            "    - Fix a buffer overread in ns_sprintrrf with corrupted RDATA field",
                            "      (CVE-2026-6238).  Closes: #1135231.",
                            "    - Fix an out-of-bounds write in ns_sprintrrf when printing TSIG records",
                            "      (CVE-2026-5435).  Closes: #1135230.",
                            "    - Fix stack overflow in wordexp tilde expansion (CVE-2026-6791).",
                            "    - Cache cpuid results in ld.so for Intel CPUs.",
                            "    - Restore optimized memchr for POWER10.",
                            "  * debian/control.in/libc, debian/rules.d/debhelper.mk: drop the libc6-dev",
                            "    dependency on rpcsvc-proto.",
                            "  * debian/watch: set Git-Mode to shallow.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 14:19:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix buffer overflow in scanf %mc (CVE-2026-5450).  Closes: #1134543.",
                            "    - Fix ungetwc operating on byte stream (CVE-2026-5928).  Closes: #1134544.",
                            "    - Save/restore VFP registers inPLT trampolines on arm.  Closes: #1133139.",
                            "    - Suppress iconv intermediate errors with //TRANSLIT.",
                            "    - debian/patches/hurd-i386/git-run-iconv-test.sh.diff: rebased.",
                            "  * debian/rules.d/build.mk: append extra_cflags to CFLAGS and ASFLAGS.",
                            "  * debian/control.in/libc: stop suggesting libnss-nisplus.",
                            "  * debian/debhelper.in/libc-bin.lintian-overrides: add a",
                            "    statically-linked-binary override for the ldconfig binary.",
                            "  * debian/control.in/main: build-depends on libselinux-dev instead of",
                            "    libselinux1-dev.",
                            "",
                            "  [ Miao Wang ]",
                            "  * debian/libc6.symbols.loong64: add.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: Add SO_TIMESTAMP macro.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 18 Jun 2026 21:48:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/sysdeps/mips*.mk: revert change to match the dpkg architecture",
                            "    name.",
                            "  * debian/rules.d/build.mk, debian/sysdeps/mips*.mk: add a way to define the",
                            "    debian architecture corresponding to a multilib build. Use it when it",
                            "    doesn't match the name of the pass and package like on mips*.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix build against linux 7.0 headers.  Closes: #1135405.",
                            "",
                            "  [ liu jianqiang ]",
                            "  * debian/debhelper.in/locales.config: handle leading spaces in",
                            "    /etc/locale.gen configuration.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 07 May 2026 00:25:31 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix random failure of tst-link-map-contiguous-ldso.",
                            "    - Fix tst-rseq with Linux 7.0.",
                            "    - Fix a possible crash due to an assertion failure when converting inputs",
                            "      from the IBM139x character sets (CVE-2026-4046).  Closes: #1132499.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-MSG_EXAMINE.diff: alterations to MSG_EXAMINE",
                            "    interface.",
                            "  * debian/patches/hurd-i386/git-interrupt-EINTR.diff: Interrupted RPC returning",
                            "    EINTR when server has actually changed state.",
                            "  * debian/patches/hurd-i386/git-SEM_FAILED.diff: Fix SEM_FAILED type.",
                            "  * debian/patches/hurd-i386/git-tst-fix.diff: Fix test build.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-15",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Sun, 19 Apr 2026 15:41:41 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc6",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2.3",
                    "version": "2.43-2ubuntu2.3"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.44-1ubuntu1",
                    "version": "2.44-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6791",
                        "url": "https://ubuntu.com/security/CVE-2026-6791",
                        "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-10 19:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163528
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from Debian experimental (LP: #2163528)",
                            "    Delta dropped:",
                            "    - Revert \"debian/rules.d/build.mk: add a makefile function to filter out",
                            "      dpkg build flags incompatible with glibc and define CFLAGS from dpkg",
                            "       build flags. Closes: #1129746.\"",
                            "    - fix ftbfs: backport OPEN_TREE conditional define (LP #2145679)",
                            "      [fixed upstream in 2.44]",
                            "    - debian/patches/CVE-2026-4046.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5435.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5450.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-5928.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-6238-*.patch",
                            "      [fixed in 2.43-3]",
                            "  * Delta added:",
                            "    - filter -flto=auto from dpkg-buildflags to fix build",
                            "    - fix tst-spawn-chdir with coreutils-rs due to invalid link name",
                            "    - xfail tst-nscd-basic tstptrguard-static-dlopen (LP #2164576)",
                            "    - d/tests: fix gcc dependency cross conflict on i386 autopkgtest",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163528
                        ],
                        "author": "Simon Poirier <simon.poirier@canonical.com>",
                        "date": "Tue, 11 Aug 2026 18:48:32 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * New upstream release:",
                            "    - debian/patches/localedata/sort-UTF8-first.diff: rebased.",
                            "    - debian/patches/hurd-i386/local-enable-ldconfig.diff: rebased.",
                            "    - debian/patches/hurd-i386/tg-libc_rwlock_recursive.diff: dropped,",
                            "      obsolete.",
                            "    - debian/patches/hurd-i386/git-fork-gdb.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-sig-mmx-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-cancel-sig.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-mach_send_eintr.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-itimer-lock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-posix-timers.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-alarm.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-libio-mtsafe.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-timedrwlock-unlock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sigtimedwait-timeout.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-MSG_EXAMINE.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-interrupt-EINTR.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SEM_FAILED.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-tst-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-path_mounted.diff: upstreamed.",
                            "    - debian/patches/any/local-nss-overflow.diff: upstreamed.",
                            "    - debian/patches/any/local-ldconfig-multiarch.diff: refreshed.",
                            "    - debian/symbols.wildcards: add 2.44.",
                            "    - debian/sysdeps/arm64.mk: stop passing --enable-memory-tagging to",
                            "      configure, support for it was removed upstream.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/submitted-net.diff: rebased.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 15:02:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6791",
                                "url": "https://ubuntu.com/security/CVE-2026-6791",
                                "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-10 19:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/testsuite-xfail-debian.mk: Update hurd results.",
                            "  * debian/patches/hurd-i386/submitted-path_mounted.diff: Renamed to",
                            "    git-path_mounted.diff.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - debian/patches/hurd-i386/local-disable-ioctls.diff: rebased.",
                            "    - debian/patches/hurd-i386/submitted-AF_LINK.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/submitted-AF_ROUTE.diff: upstreamed.",
                            "    - Fix a buffer overread in ns_sprintrrf with corrupted RDATA field",
                            "      (CVE-2026-6238).  Closes: #1135231.",
                            "    - Fix an out-of-bounds write in ns_sprintrrf when printing TSIG records",
                            "      (CVE-2026-5435).  Closes: #1135230.",
                            "    - Fix stack overflow in wordexp tilde expansion (CVE-2026-6791).",
                            "    - Cache cpuid results in ld.so for Intel CPUs.",
                            "    - Restore optimized memchr for POWER10.",
                            "  * debian/control.in/libc, debian/rules.d/debhelper.mk: drop the libc6-dev",
                            "    dependency on rpcsvc-proto.",
                            "  * debian/watch: set Git-Mode to shallow.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 14:19:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix buffer overflow in scanf %mc (CVE-2026-5450).  Closes: #1134543.",
                            "    - Fix ungetwc operating on byte stream (CVE-2026-5928).  Closes: #1134544.",
                            "    - Save/restore VFP registers inPLT trampolines on arm.  Closes: #1133139.",
                            "    - Suppress iconv intermediate errors with //TRANSLIT.",
                            "    - debian/patches/hurd-i386/git-run-iconv-test.sh.diff: rebased.",
                            "  * debian/rules.d/build.mk: append extra_cflags to CFLAGS and ASFLAGS.",
                            "  * debian/control.in/libc: stop suggesting libnss-nisplus.",
                            "  * debian/debhelper.in/libc-bin.lintian-overrides: add a",
                            "    statically-linked-binary override for the ldconfig binary.",
                            "  * debian/control.in/main: build-depends on libselinux-dev instead of",
                            "    libselinux1-dev.",
                            "",
                            "  [ Miao Wang ]",
                            "  * debian/libc6.symbols.loong64: add.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: Add SO_TIMESTAMP macro.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 18 Jun 2026 21:48:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/sysdeps/mips*.mk: revert change to match the dpkg architecture",
                            "    name.",
                            "  * debian/rules.d/build.mk, debian/sysdeps/mips*.mk: add a way to define the",
                            "    debian architecture corresponding to a multilib build. Use it when it",
                            "    doesn't match the name of the pass and package like on mips*.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix build against linux 7.0 headers.  Closes: #1135405.",
                            "",
                            "  [ liu jianqiang ]",
                            "  * debian/debhelper.in/locales.config: handle leading spaces in",
                            "    /etc/locale.gen configuration.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 07 May 2026 00:25:31 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix random failure of tst-link-map-contiguous-ldso.",
                            "    - Fix tst-rseq with Linux 7.0.",
                            "    - Fix a possible crash due to an assertion failure when converting inputs",
                            "      from the IBM139x character sets (CVE-2026-4046).  Closes: #1132499.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-MSG_EXAMINE.diff: alterations to MSG_EXAMINE",
                            "    interface.",
                            "  * debian/patches/hurd-i386/git-interrupt-EINTR.diff: Interrupted RPC returning",
                            "    EINTR when server has actually changed state.",
                            "  * debian/patches/hurd-i386/git-SEM_FAILED.diff: Fix SEM_FAILED type.",
                            "  * debian/patches/hurd-i386/git-tst-fix.diff: Fix test build.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-15",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Sun, 19 Apr 2026 15:41:41 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libcryptsetup12",
                "from_version": {
                    "source_package_name": "cryptsetup",
                    "source_package_version": "2:2.8.7-1ubuntu1",
                    "version": "2:2.8.7-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "cryptsetup",
                    "source_package_version": "2:2.8.7-1ubuntu3",
                    "version": "2:2.8.7-1ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167087
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop alternative busybox-static dependency (LP: #2167087)",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167087
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Sat, 12 Sep 2026 23:44:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop test-use-gnudd-as-workaround-in-luks2-reencryption-mangle.patch",
                            "    This workaround is not needed with rust-coreutils 0.10 any more.",
                            ""
                        ],
                        "package": "cryptsetup",
                        "version": "2:2.8.7-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Thu, 10 Sep 2026 16:29:47 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libctf-nobfd0",
                "from_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-2ubuntu1",
                    "version": "2.47-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-6ubuntu1",
                    "version": "2.47-6ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Thu, 10 Sep 2026 15:44:45 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'gprofng.display/display.exp/jsynprog' test on arm64.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 15:31:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'ld-elf/elf.exp/Run PR ld/34184 test (PIE)' test on armhf.",
                            "    See #1147080.",
                            "  * Ignore 'ld-elf/dwarf.exp/Handle no DWARF information' test on loong64.",
                            "    See #1147079.",
                            "  * d/copyright: Replace FSF postal address with web reference.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 13:19:53 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Annotate the build autopkg test with the needs-root restriction.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 12:13:55 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream snapshot, taken from the 2.47 branch.",
                            "  * Update VCS attributes.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 11:49:12 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libctf0",
                "from_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-2ubuntu1",
                    "version": "2.47-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-6ubuntu1",
                    "version": "2.47-6ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Thu, 10 Sep 2026 15:44:45 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'gprofng.display/display.exp/jsynprog' test on arm64.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 15:31:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'ld-elf/elf.exp/Run PR ld/34184 test (PIE)' test on armhf.",
                            "    See #1147080.",
                            "  * Ignore 'ld-elf/dwarf.exp/Handle no DWARF information' test on loong64.",
                            "    See #1147079.",
                            "  * d/copyright: Replace FSF postal address with web reference.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 13:19:53 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Annotate the build autopkg test with the needs-root restriction.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 12:13:55 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream snapshot, taken from the 2.47 branch.",
                            "  * Update VCS attributes.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 11:49:12 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libcurl3t64-gnutls",
                "from_version": {
                    "source_package_name": "curl",
                    "source_package_version": "8.20.0-2ubuntu1",
                    "version": "8.20.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "curl",
                    "source_package_version": "8.20.0-2ubuntu3",
                    "version": "8.20.0-2ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-8932",
                        "url": "https://ubuntu.com/security/CVE-2026-8932",
                        "cve_description": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-07-03 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-8932",
                                "url": "https://ubuntu.com/security/CVE-2026-8932",
                                "cve_description": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-07-03 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Authentication Bypass in connection reuse.",
                            "    - debian/patches/CVE-2026-8932.patch: Fix incomplete mTLS config in",
                            "      lib/ldap.c, lib/urldata.h, lib/vssh/libssh.c, lib/vssh/libssh2.c,",
                            "      lib/vtls/gtls.c, lib/vtls/mbedtls.c, lib/vtls/openssl.c,",
                            "      lib/vtls/rustls.c, lib/vtls/schannel.c, lib/vtls/vtls.c,",
                            "      lib/vtls/vtls_scache.c, and lib/vtls/wolfssl.c.",
                            "    - CVE-2026-8932",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.20.0-2ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Tue, 08 Sep 2026 12:31:08 -0600"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.20.0-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:19 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libcurl4t64",
                "from_version": {
                    "source_package_name": "curl",
                    "source_package_version": "8.20.0-2ubuntu1",
                    "version": "8.20.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "curl",
                    "source_package_version": "8.20.0-2ubuntu3",
                    "version": "8.20.0-2ubuntu3"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-8932",
                        "url": "https://ubuntu.com/security/CVE-2026-8932",
                        "cve_description": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.",
                        "cve_priority": "low",
                        "cve_public_date": "2026-07-03 07:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-8932",
                                "url": "https://ubuntu.com/security/CVE-2026-8932",
                                "cve_description": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.",
                                "cve_priority": "low",
                                "cve_public_date": "2026-07-03 07:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Authentication Bypass in connection reuse.",
                            "    - debian/patches/CVE-2026-8932.patch: Fix incomplete mTLS config in",
                            "      lib/ldap.c, lib/urldata.h, lib/vssh/libssh.c, lib/vssh/libssh2.c,",
                            "      lib/vtls/gtls.c, lib/vtls/mbedtls.c, lib/vtls/openssl.c,",
                            "      lib/vtls/rustls.c, lib/vtls/schannel.c, lib/vtls/vtls.c,",
                            "      lib/vtls/vtls_scache.c, and lib/vtls/wolfssl.c.",
                            "    - CVE-2026-8932",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.20.0-2ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Tue, 08 Sep 2026 12:31:08 -0600"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "curl",
                        "version": "8.20.0-2ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:56:19 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libdebuginfod-common",
                "from_version": {
                    "source_package_name": "elfutils",
                    "source_package_version": "0.195-1",
                    "version": "0.195-1"
                },
                "to_version": {
                    "source_package_name": "elfutils",
                    "source_package_version": "0.196-1",
                    "version": "0.196-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Update symbols files.",
                            ""
                        ],
                        "package": "elfutils",
                        "version": "0.196-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 08:17:36 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libdebuginfod1t64",
                "from_version": {
                    "source_package_name": "elfutils",
                    "source_package_version": "0.195-1",
                    "version": "0.195-1"
                },
                "to_version": {
                    "source_package_name": "elfutils",
                    "source_package_version": "0.196-1",
                    "version": "0.196-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Update symbols files.",
                            ""
                        ],
                        "package": "elfutils",
                        "version": "0.196-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 08:17:36 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libdw1t64",
                "from_version": {
                    "source_package_name": "elfutils",
                    "source_package_version": "0.195-1",
                    "version": "0.195-1"
                },
                "to_version": {
                    "source_package_name": "elfutils",
                    "source_package_version": "0.196-1",
                    "version": "0.196-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Update symbols files.",
                            ""
                        ],
                        "package": "elfutils",
                        "version": "0.196-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 08:17:36 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libelf1t64",
                "from_version": {
                    "source_package_name": "elfutils",
                    "source_package_version": "0.195-1",
                    "version": "0.195-1"
                },
                "to_version": {
                    "source_package_name": "elfutils",
                    "source_package_version": "0.196-1",
                    "version": "0.196-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Update symbols files.",
                            ""
                        ],
                        "package": "elfutils",
                        "version": "0.196-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 08:17:36 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libfuse3-4",
                "from_version": {
                    "source_package_name": "fuse3",
                    "source_package_version": "3.18.2-2",
                    "version": "3.18.2-2"
                },
                "to_version": {
                    "source_package_name": "fuse3",
                    "source_package_version": "3.18.3-1",
                    "version": "3.18.3-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "fuse3",
                        "version": "3.18.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Laszlo Boszormenyi (GCS) <gcs@debian.org>",
                        "date": "Sun, 13 Sep 2026 08:42:13 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgcc-s1",
                "from_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-1ubuntu1",
                    "version": "16.2.0-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-2ubuntu1",
                    "version": "16.2.0-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Wed, 02 Sep 2026 10:52:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260902 from the gcc-16 branch.",
                            "    - Fix PR middle-end/127098, PR tree-optimization/127105,",
                            "      PR tree-optimization/127100, PR target/120681 (PPC),",
                            "      PR target/120528 (PPC), PR target/99293 (PPC), PR target/117487 (PPC),",
                            "      PR ada/125984, PR ipa/127023, PR target/126873 (RISCV),",
                            "      PR rtl-optimization/126426, PR target/127004 (AVR), PR middle-end/126939,",
                            "      PR target/126787 (x86), PR target/126513 (PPC),",
                            "      PR target/124629 (AArch64), PR tree-optimization/126925,",
                            "      PR tree-optimization/126650, PR tree-optimization/126926,",
                            "      PR tree-optimization/126534, PR target/126454 (RISCV),",
                            "      PR target/126334 (RISCV), PR target/126550 (RISCV),",
                            "      PR target/126676 (x86), PR target/126320 (x86), PR target/126450 (x86),",
                            "      PR target/126529 (x86), PR ada/127026, PR ada/127026, PR ada/126928,",
                            "      PR ada/126907, PR c++/127046, PR c++/124888, PR c++/126335,",
                            "      PR c++/124794, PR c++/126546, PR c++/124811, PR c++/126918,",
                            "      PR c++/126867, PR c++/126752, PR c++/126093, PR c++/126483,",
                            "      PR c++/126754, PR c++/126783, PR c++/124794, PR c++/125069,",
                            "      PR c++/124806, PR fortran/98573, PR fortran/105594, PR fortran/88632,",
                            "      PR fortran/104630, PR fortran/126872, PR fortran/110626,",
                            "      PR fortran/104048, PR target/125803 (PPC), PR libstdc++/118665,",
                            "      PR libstdc++/123510, PR libstdc++/122981, PR libstdc++/127006,",
                            "      PR libstdc++/126731, PR libstdc++/125981, PR libstdc++/126452,",
                            "      PR libstdc++/126849.",
                            "  * Only enable LRA by default on m68k for snapshot builds. Closes: #1143971.",
                            "  * Don't apply the SH LRA patches for snapshot builds. Closes: #1146439.",
                            "  * Disable usage stats for the build.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 02 Sep 2026 11:07:42 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgcrypt20",
                "from_version": {
                    "source_package_name": "libgcrypt20",
                    "source_package_version": "1.12.2-1ubuntu1",
                    "version": "1.12.2-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "libgcrypt20",
                    "source_package_version": "1.12.2-1ubuntu2",
                    "version": "1.12.2-1ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2024-2236",
                        "url": "https://ubuntu.com/security/CVE-2024-2236",
                        "cve_description": "A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.",
                        "cve_priority": "low",
                        "cve_public_date": "2024-03-06 22:15:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2024-2236",
                                "url": "https://ubuntu.com/security/CVE-2024-2236",
                                "cve_description": "A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.",
                                "cve_priority": "low",
                                "cve_public_date": "2024-03-06 22:15:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: timing-based side-channel flaw in RSA implementation",
                            "    - debian/patches/CVE-2024-2236-1.patch: rsa: Do not accept invalid PKCS#1.5",
                            "      padding when deciphering in cipher/rsa-common.c, src/const-time.h.",
                            "    - debian/patches/CVE-2024-2236-2.patch: rsa: Constant time blinding removal",
                            "      in cipher/rsa.c, configure.ac, mpi/Makefile.am, mpi/mpi-internal.h,",
                            "      mpi/mpi-mul-cs.c, mpi/mpi-mul.c, src/gcrypt-int.h.",
                            "    - debian/patches/CVE-2024-2236-3.patch: Constant time conversion of the",
                            "      message to the SEXP in cipher/rsa.c, src/const-time.c, src/const-time.h,",
                            "      src/sexp.c.",
                            "    - debian/patches/CVE-2024-2236-4.patch: rsa: Implement constant-time",
                            "      conversion of MPI to string in cipher/rsa-common.c.",
                            "    - debian/patches/CVE-2024-2236-5.patch: cipher: Use the constant time",
                            "      conversion also for OAEP in cipher/rsa-common.c, cipher/rsa.c.",
                            "    - debian/patches/CVE-2024-2236-6.patch: Implement implicit rejection for",
                            "      PKCS#1.5 decipher in cipher/pubkey-internal.h, cipher/pubkey-util.c,",
                            "      cipher/rsa-common.c, cipher/rsa.c, src/cipher.h, src/const-time.h,",
                            "      tests/pkcs1v2-v15c.h, tests/pkcs1v2.c.",
                            "    - debian/rules: build with --enable-marvin-workaround.",
                            "    - Thanks for Red Hat for the patches!",
                            "    - CVE-2024-2236",
                            ""
                        ],
                        "package": "libgcrypt20",
                        "version": "1.12.2-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 08:39:46 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgirepository-2.0-0",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.3-4",
                    "version": "2.89.3-4"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.90.0-1",
                    "version": "2.90.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.90.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Thu, 10 Sep 2026 12:07:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Re-upload with orig tarball, no source changes",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 19:33:06 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes a main-loop regression in 2.89.3 (mutter#4994 upstream)",
                            "  * d/patches: Drop patches that were part of the upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 18:52:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Fri, 21 Aug 2026 16:37:11 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libglib2.0-0t64",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.3-4",
                    "version": "2.89.3-4"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.90.0-1",
                    "version": "2.90.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.90.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Thu, 10 Sep 2026 12:07:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Re-upload with orig tarball, no source changes",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 19:33:06 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes a main-loop regression in 2.89.3 (mutter#4994 upstream)",
                            "  * d/patches: Drop patches that were part of the upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 18:52:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Fri, 21 Aug 2026 16:37:11 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libglib2.0-bin",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.3-4",
                    "version": "2.89.3-4"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.90.0-1",
                    "version": "2.90.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.90.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Thu, 10 Sep 2026 12:07:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Re-upload with orig tarball, no source changes",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 19:33:06 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes a main-loop regression in 2.89.3 (mutter#4994 upstream)",
                            "  * d/patches: Drop patches that were part of the upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 18:52:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Fri, 21 Aug 2026 16:37:11 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libglib2.0-data",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.89.3-4",
                    "version": "2.89.3-4"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.90.0-1",
                    "version": "2.90.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.90.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alessandro Astone <alessandro.astone@canonical.com>",
                        "date": "Thu, 10 Sep 2026 12:07:43 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Re-upload with orig tarball, no source changes",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 19:33:06 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "    - Fixes a main-loop regression in 2.89.3 (mutter#4994 upstream)",
                            "  * d/patches: Drop patches that were part of the upstream release",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.4-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Simon McVittie <smcv@debian.org>",
                        "date": "Mon, 24 Aug 2026 18:52:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Release to unstable",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.89.3-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jeremy Bícha <jbicha@ubuntu.com>",
                        "date": "Fri, 21 Aug 2026 16:37:11 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgprofng0",
                "from_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-2ubuntu1",
                    "version": "2.47-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-6ubuntu1",
                    "version": "2.47-6ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Thu, 10 Sep 2026 15:44:45 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'gprofng.display/display.exp/jsynprog' test on arm64.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 15:31:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'ld-elf/elf.exp/Run PR ld/34184 test (PIE)' test on armhf.",
                            "    See #1147080.",
                            "  * Ignore 'ld-elf/dwarf.exp/Handle no DWARF information' test on loong64.",
                            "    See #1147079.",
                            "  * d/copyright: Replace FSF postal address with web reference.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 13:19:53 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Annotate the build autopkg test with the needs-root restriction.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 12:13:55 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream snapshot, taken from the 2.47 branch.",
                            "  * Update VCS attributes.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 11:49:12 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libgstreamer1.0-0",
                "from_version": {
                    "source_package_name": "gstreamer1.0",
                    "source_package_version": "1.28.6-1",
                    "version": "1.28.6-1"
                },
                "to_version": {
                    "source_package_name": "gstreamer1.0",
                    "source_package_version": "1.28.7-1",
                    "version": "1.28.7-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 1.28.7 (Closes: #1144521)",
                            ""
                        ],
                        "package": "gstreamer1.0",
                        "version": "1.28.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Leeman <marc.leeman@gmail.com>",
                        "date": "Tue, 08 Sep 2026 08:02:57 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libibverbs1",
                "from_version": {
                    "source_package_name": "rdma-core",
                    "source_package_version": "63.0-2ubuntu1",
                    "version": "63.0-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "rdma-core",
                    "source_package_version": "64.0-1ubuntu1",
                    "version": "64.0-1ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2165887
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2165887).",
                            "  * Remaining changes:",
                            "    - Do not build-depend on pandoc on i386 (not available there).",
                            "  * New changes:",
                            "    - d/rules: do not build man pages on i386 (-DNO_MAN_PAGES=1) and drop",
                            "      them from the .install files. The GitHub tag tarball fetched by",
                            "      d/watch since 63.0-2 ships no prebuilt man pages, so building without",
                            "      pandoc no longer works. i386 binary packages ship no man pages.",
                            ""
                        ],
                        "package": "rdma-core",
                        "version": "64.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165887
                        ],
                        "author": "Tomáš Virtus <tomas.virtus@canonical.com>",
                        "date": "Tue, 01 Sep 2026 12:59:55 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release",
                            "  * Drop patches applied upstream",
                            "  * Update private libibverbs1 symbols",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "rdma-core",
                        "version": "64.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Mon, 31 Aug 2026 11:52:10 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libintl-perl",
                "from_version": {
                    "source_package_name": "libintl-perl",
                    "source_package_version": "1.37-1",
                    "version": "1.37-1"
                },
                "to_version": {
                    "source_package_name": "libintl-perl",
                    "source_package_version": "1.37-1build1",
                    "version": "1.37-1build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "libintl-perl",
                        "version": "1.37-1build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Wed, 19 Aug 2026 13:41:06 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libintl-xs-perl",
                "from_version": {
                    "source_package_name": "libintl-perl",
                    "source_package_version": "1.37-1",
                    "version": "1.37-1"
                },
                "to_version": {
                    "source_package_name": "libintl-perl",
                    "source_package_version": "1.37-1build1",
                    "version": "1.37-1build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "libintl-perl",
                        "version": "1.37-1build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Wed, 19 Aug 2026 13:41:06 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libldap-common",
                "from_version": {
                    "source_package_name": "openldap",
                    "source_package_version": "2.6.13+dfsg-1ubuntu2",
                    "version": "2.6.13+dfsg-1ubuntu2"
                },
                "to_version": {
                    "source_package_name": "openldap",
                    "source_package_version": "2.6.13+dfsg-1ubuntu3",
                    "version": "2.6.13+dfsg-1ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "openldap",
                        "version": "2.6.13+dfsg-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 11:06:14 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libldap2",
                "from_version": {
                    "source_package_name": "openldap",
                    "source_package_version": "2.6.13+dfsg-1ubuntu2",
                    "version": "2.6.13+dfsg-1ubuntu2"
                },
                "to_version": {
                    "source_package_name": "openldap",
                    "source_package_version": "2.6.13+dfsg-1ubuntu3",
                    "version": "2.6.13+dfsg-1ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "openldap",
                        "version": "2.6.13+dfsg-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Thu, 20 Aug 2026 11:06:14 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "liblocale-gettext-perl",
                "from_version": {
                    "source_package_name": "liblocale-gettext-perl",
                    "source_package_version": "1.07-10",
                    "version": "1.07-10"
                },
                "to_version": {
                    "source_package_name": "liblocale-gettext-perl",
                    "source_package_version": "1.07-10build1",
                    "version": "1.07-10build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "liblocale-gettext-perl",
                        "version": "1.07-10build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Wed, 19 Aug 2026 13:48:00 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libmpathcmd0",
                "from_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu1",
                    "version": "0.14.3-3ubuntu1"
                },
                "to_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu2",
                    "version": "0.14.3-3ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2165993
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Pass the -s option instead of --syslog when invoking modprobe. The",
                            "    long option is not compatible with busybox's implementation of modprobe",
                            "    (LP: #2165993).",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165993
                        ],
                        "author": "Olivier Gayot <olivier.gayot@canonical.com>",
                        "date": "Mon, 07 Sep 2026 18:14:02 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libmpathpersist0",
                "from_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu1",
                    "version": "0.14.3-3ubuntu1"
                },
                "to_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu2",
                    "version": "0.14.3-3ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2165993
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Pass the -s option instead of --syslog when invoking modprobe. The",
                            "    long option is not compatible with busybox's implementation of modprobe",
                            "    (LP: #2165993).",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165993
                        ],
                        "author": "Olivier Gayot <olivier.gayot@canonical.com>",
                        "date": "Mon, 07 Sep 2026 18:14:02 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libmultipath0",
                "from_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu1",
                    "version": "0.14.3-3ubuntu1"
                },
                "to_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu2",
                    "version": "0.14.3-3ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2165993
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Pass the -s option instead of --syslog when invoking modprobe. The",
                            "    long option is not compatible with busybox's implementation of modprobe",
                            "    (LP: #2165993).",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165993
                        ],
                        "author": "Olivier Gayot <olivier.gayot@canonical.com>",
                        "date": "Mon, 07 Sep 2026 18:14:02 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libnghttp2-14",
                "from_version": {
                    "source_package_name": "nghttp2",
                    "source_package_version": "1.69.0-1ubuntu2",
                    "version": "1.69.0-1ubuntu2"
                },
                "to_version": {
                    "source_package_name": "nghttp2",
                    "source_package_version": "1.70.0-1",
                    "version": "1.70.0-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-58055",
                        "url": "https://ubuntu.com/security/CVE-2026-58055",
                        "cve_description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-28 02:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "nghttp2",
                        "version": "1.69.0-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Fri, 24 Jul 2026 07:59:54 +0000"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58055",
                                "url": "https://ubuntu.com/security/CVE-2026-58055",
                                "cve_description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-28 02:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: HTTP request/response smuggling issue",
                            "    - debian/patches/CVE-2026-58055.patch: nghttpx: Tighten up CONNECT and HTTP",
                            "      Upgrade handling in src/shrpx_downstream.cc, src/shrpx_downstream.h,",
                            "      src/shrpx_http2_upstream.cc, src/shrpx_http3_upstream.cc,",
                            "      src/shrpx_http_downstream_connection.cc,",
                            "      src/shrpx_http_downstream_connection.h, src/shrpx_https_upstream.cc.",
                            "    - CVE-2026-58055",
                            ""
                        ],
                        "package": "nghttp2",
                        "version": "1.69.0-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Tue, 30 Jun 2026 12:28:17 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "libopeniscsiusr",
                "from_version": {
                    "source_package_name": "open-iscsi",
                    "source_package_version": "2.1.11-5ubuntu4",
                    "version": "2.1.11-5ubuntu4"
                },
                "to_version": {
                    "source_package_name": "open-iscsi",
                    "source_package_version": "2.1.11-5ubuntu5",
                    "version": "2.1.11-5ubuntu5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167087
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop alternative busybox-static recommends (LP: #2167087)",
                            ""
                        ],
                        "package": "open-iscsi",
                        "version": "2.1.11-5ubuntu5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167087
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Sun, 13 Sep 2026 22:26:54 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpolkit-agent-1-0",
                "from_version": {
                    "source_package_name": "policykit-1",
                    "source_package_version": "127-3",
                    "version": "127-3"
                },
                "to_version": {
                    "source_package_name": "policykit-1",
                    "source_package_version": "127-3ubuntu1",
                    "version": "127-3ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-85498",
                        "url": "https://ubuntu.com/security/CVE-2026-85498",
                        "cve_description": "[Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow]",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-07"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-85498",
                                "url": "https://ubuntu.com/security/CVE-2026-85498",
                                "cve_description": "[Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow]",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-07"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: stack underflow in cookie input",
                            "    - debian/patches/CVE-2026-85498.patch: Unsanitized underflow in cookie",
                            "      input in src/polkitagent/polkitagenthelperprivate.c.",
                            "    - CVE-2026-85498",
                            ""
                        ],
                        "package": "policykit-1",
                        "version": "127-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Fri, 11 Sep 2026 13:29:14 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpolkit-gobject-1-0",
                "from_version": {
                    "source_package_name": "policykit-1",
                    "source_package_version": "127-3",
                    "version": "127-3"
                },
                "to_version": {
                    "source_package_name": "policykit-1",
                    "source_package_version": "127-3ubuntu1",
                    "version": "127-3ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-85498",
                        "url": "https://ubuntu.com/security/CVE-2026-85498",
                        "cve_description": "[Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow]",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-07"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-85498",
                                "url": "https://ubuntu.com/security/CVE-2026-85498",
                                "cve_description": "[Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow]",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-07"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: stack underflow in cookie input",
                            "    - debian/patches/CVE-2026-85498.patch: Unsanitized underflow in cookie",
                            "      input in src/polkitagent/polkitagenthelperprivate.c.",
                            "    - CVE-2026-85498",
                            ""
                        ],
                        "package": "policykit-1",
                        "version": "127-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Fri, 11 Sep 2026 13:29:14 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libproc-processtable-perl",
                "from_version": {
                    "source_package_name": "libproc-processtable-perl",
                    "source_package_version": "0.637-1",
                    "version": "0.637-1"
                },
                "to_version": {
                    "source_package_name": "libproc-processtable-perl",
                    "source_package_version": "0.637-1build1",
                    "version": "0.637-1build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "libproc-processtable-perl",
                        "version": "0.637-1build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Wed, 19 Aug 2026 14:06:00 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpython3-stdlib",
                "from_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.3-0ubuntu2",
                    "version": "3.14.3-0ubuntu2"
                },
                "to_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.7-3",
                    "version": "3.14.7-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Remove a missed Python 3.13 dependency.",
                            "  * Update README.Debian.",
                            "",
                            "  [ Simon McVittie ]",
                            "  * policy: Expand the section about package names. (Closes: #791635)",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Thu, 27 Aug 2026 11:09:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Bump to version 3.14.7.",
                            "  * Remove Python 3.13 as a supported version.",
                            "  * Remove references to IronPython and Jython in the package descriptions.",
                            "  * Bump standards version.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 26 Aug 2026 16:45:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            "  * Bump to version 3.14.6.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Sat, 27 Jun 2026 09:14:35 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpython3.14",
                "from_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.6-1",
                    "version": "3.14.6-1"
                },
                "to_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.7-4ubuntu1",
                    "version": "3.14.7-4ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert the module-install-* autopkg tests to run with setuptools v78.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:51:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-13.",
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Re-enable the module-install-* autopkgtests, updated for setuptools 80.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:30:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-05.",
                            "  * Disable the module-install-* autopkg tests for now.",
                            "  * Update symbols file.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sat, 05 Sep 2026 07:55:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-01.",
                            "    - Reworks the test_typing stack test. Closes: #1146095.",
                            "  * Apply the OpenSSL 4.0 patches from the 3.15 branch. Closes: #1137595.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 11:47:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Python 3.14.7 release.",
                            "  * Drop the the min-pyrepl patch, handled by an upstream backport.",
                            "  * Refresh patches.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 11 Aug 2026 10:48:35 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpython3.14-minimal",
                "from_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.6-1",
                    "version": "3.14.6-1"
                },
                "to_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.7-4ubuntu1",
                    "version": "3.14.7-4ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert the module-install-* autopkg tests to run with setuptools v78.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:51:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-13.",
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Re-enable the module-install-* autopkgtests, updated for setuptools 80.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:30:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-05.",
                            "  * Disable the module-install-* autopkg tests for now.",
                            "  * Update symbols file.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sat, 05 Sep 2026 07:55:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-01.",
                            "    - Reworks the test_typing stack test. Closes: #1146095.",
                            "  * Apply the OpenSSL 4.0 patches from the 3.15 branch. Closes: #1137595.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 11:47:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Python 3.14.7 release.",
                            "  * Drop the the min-pyrepl patch, handled by an upstream backport.",
                            "  * Refresh patches.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 11 Aug 2026 10:48:35 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpython3.14-stdlib",
                "from_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.6-1",
                    "version": "3.14.6-1"
                },
                "to_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.7-4ubuntu1",
                    "version": "3.14.7-4ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert the module-install-* autopkg tests to run with setuptools v78.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:51:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-13.",
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Re-enable the module-install-* autopkgtests, updated for setuptools 80.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:30:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-05.",
                            "  * Disable the module-install-* autopkg tests for now.",
                            "  * Update symbols file.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sat, 05 Sep 2026 07:55:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-01.",
                            "    - Reworks the test_typing stack test. Closes: #1146095.",
                            "  * Apply the OpenSSL 4.0 patches from the 3.15 branch. Closes: #1137595.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 11:47:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Python 3.14.7 release.",
                            "  * Drop the the min-pyrepl patch, handled by an upstream backport.",
                            "  * Refresh patches.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 11 Aug 2026 10:48:35 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libsframe3",
                "from_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-2ubuntu1",
                    "version": "2.47-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "binutils",
                    "source_package_version": "2.47-6ubuntu1",
                    "version": "2.47-6ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Thu, 10 Sep 2026 15:44:45 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'gprofng.display/display.exp/jsynprog' test on arm64.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 15:31:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Ignore 'ld-elf/elf.exp/Run PR ld/34184 test (PIE)' test on armhf.",
                            "    See #1147080.",
                            "  * Ignore 'ld-elf/dwarf.exp/Handle no DWARF information' test on loong64.",
                            "    See #1147079.",
                            "  * d/copyright: Replace FSF postal address with web reference.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Thu, 10 Sep 2026 13:19:53 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Annotate the build autopkg test with the needs-root restriction.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 12:13:55 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream snapshot, taken from the 2.47 branch.",
                            "  * Update VCS attributes.",
                            ""
                        ],
                        "package": "binutils",
                        "version": "2.47-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 06 Sep 2026 11:49:12 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libstdc++6",
                "from_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-1ubuntu1",
                    "version": "16.2.0-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "gcc-16",
                    "source_package_version": "16.2.0-2ubuntu1",
                    "version": "16.2.0-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian; remaining changes:",
                            "    - Build from upstream sources.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@ubuntu.com>",
                        "date": "Wed, 02 Sep 2026 10:52:46 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to git 20260902 from the gcc-16 branch.",
                            "    - Fix PR middle-end/127098, PR tree-optimization/127105,",
                            "      PR tree-optimization/127100, PR target/120681 (PPC),",
                            "      PR target/120528 (PPC), PR target/99293 (PPC), PR target/117487 (PPC),",
                            "      PR ada/125984, PR ipa/127023, PR target/126873 (RISCV),",
                            "      PR rtl-optimization/126426, PR target/127004 (AVR), PR middle-end/126939,",
                            "      PR target/126787 (x86), PR target/126513 (PPC),",
                            "      PR target/124629 (AArch64), PR tree-optimization/126925,",
                            "      PR tree-optimization/126650, PR tree-optimization/126926,",
                            "      PR tree-optimization/126534, PR target/126454 (RISCV),",
                            "      PR target/126334 (RISCV), PR target/126550 (RISCV),",
                            "      PR target/126676 (x86), PR target/126320 (x86), PR target/126450 (x86),",
                            "      PR target/126529 (x86), PR ada/127026, PR ada/127026, PR ada/126928,",
                            "      PR ada/126907, PR c++/127046, PR c++/124888, PR c++/126335,",
                            "      PR c++/124794, PR c++/126546, PR c++/124811, PR c++/126918,",
                            "      PR c++/126867, PR c++/126752, PR c++/126093, PR c++/126483,",
                            "      PR c++/126754, PR c++/126783, PR c++/124794, PR c++/125069,",
                            "      PR c++/124806, PR fortran/98573, PR fortran/105594, PR fortran/88632,",
                            "      PR fortran/104630, PR fortran/126872, PR fortran/110626,",
                            "      PR fortran/104048, PR target/125803 (PPC), PR libstdc++/118665,",
                            "      PR libstdc++/123510, PR libstdc++/122981, PR libstdc++/127006,",
                            "      PR libstdc++/126731, PR libstdc++/125981, PR libstdc++/126452,",
                            "      PR libstdc++/126849.",
                            "  * Only enable LRA by default on m68k for snapshot builds. Closes: #1143971.",
                            "  * Don't apply the SH LRA patches for snapshot builds. Closes: #1146439.",
                            "  * Disable usage stats for the build.",
                            ""
                        ],
                        "package": "gcc-16",
                        "version": "16.2.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 02 Sep 2026 11:07:42 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libterm-readkey-perl",
                "from_version": {
                    "source_package_name": "libterm-readkey-perl",
                    "source_package_version": "2.38-2build5",
                    "version": "2.38-2build5"
                },
                "to_version": {
                    "source_package_name": "libterm-readkey-perl",
                    "source_package_version": "2.38-2build6",
                    "version": "2.38-2build6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "libterm-readkey-perl",
                        "version": "2.38-2build6",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Wed, 19 Aug 2026 14:16:07 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libtext-charwidth-perl",
                "from_version": {
                    "source_package_name": "libtext-charwidth-perl",
                    "source_package_version": "0.04-12",
                    "version": "0.04-12"
                },
                "to_version": {
                    "source_package_name": "libtext-charwidth-perl",
                    "source_package_version": "0.04-12build1",
                    "version": "0.04-12build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Rebuild against current perl",
                            ""
                        ],
                        "package": "libtext-charwidth-perl",
                        "version": "0.04-12build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <tjaalton@debian.org>",
                        "date": "Wed, 19 Aug 2026 10:14:13 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libtext-iconv-perl",
                "from_version": {
                    "source_package_name": "libtext-iconv-perl",
                    "source_package_version": "1.7-9",
                    "version": "1.7-9"
                },
                "to_version": {
                    "source_package_name": "libtext-iconv-perl",
                    "source_package_version": "1.7-9build1",
                    "version": "1.7-9build1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against perl 5.42.3",
                            ""
                        ],
                        "package": "libtext-iconv-perl",
                        "version": "1.7-9build1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Wed, 19 Aug 2026 14:18:59 -0700"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libxml2-16",
                "from_version": {
                    "source_package_name": "libxml2",
                    "source_package_version": "2.15.3+dfsg-1",
                    "version": "2.15.3+dfsg-1"
                },
                "to_version": {
                    "source_package_name": "libxml2",
                    "source_package_version": "2.15.4+dfsg-1",
                    "version": "2.15.4+dfsg-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-86137",
                        "url": "https://ubuntu.com/security/CVE-2026-86137",
                        "cve_description": "In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-05 05:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-86138",
                        "url": "https://ubuntu.com/security/CVE-2026-86138",
                        "cve_description": "In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-05 05:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-86139",
                        "url": "https://ubuntu.com/security/CVE-2026-86139",
                        "cve_description": "In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-05 05:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-86140",
                        "url": "https://ubuntu.com/security/CVE-2026-86140",
                        "cve_description": "In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-05 05:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-86141",
                        "url": "https://ubuntu.com/security/CVE-2026-86141",
                        "cve_description": "xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-05 05:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-86142",
                        "url": "https://ubuntu.com/security/CVE-2026-86142",
                        "cve_description": "In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-05 05:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-86143",
                        "url": "https://ubuntu.com/security/CVE-2026-86143",
                        "cve_description": "In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-05 05:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-86144",
                        "url": "https://ubuntu.com/security/CVE-2026-86144",
                        "cve_description": "In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-05 05:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11979",
                        "url": "https://ubuntu.com/security/CVE-2026-11979",
                        "cve_description": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.  This issue has been fixed in the commit c2e233fc.  NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.",
                        "cve_priority": "negligible",
                        "cve_public_date": "2026-06-29 14:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-86137",
                                "url": "https://ubuntu.com/security/CVE-2026-86137",
                                "cve_description": "In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-05 05:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-86138",
                                "url": "https://ubuntu.com/security/CVE-2026-86138",
                                "cve_description": "In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-05 05:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-86139",
                                "url": "https://ubuntu.com/security/CVE-2026-86139",
                                "cve_description": "In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-05 05:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-86140",
                                "url": "https://ubuntu.com/security/CVE-2026-86140",
                                "cve_description": "In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-05 05:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-86141",
                                "url": "https://ubuntu.com/security/CVE-2026-86141",
                                "cve_description": "xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-05 05:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-86142",
                                "url": "https://ubuntu.com/security/CVE-2026-86142",
                                "cve_description": "In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-05 05:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-86143",
                                "url": "https://ubuntu.com/security/CVE-2026-86143",
                                "cve_description": "In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-05 05:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-86144",
                                "url": "https://ubuntu.com/security/CVE-2026-86144",
                                "cve_description": "In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-05 05:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11979",
                                "url": "https://ubuntu.com/security/CVE-2026-11979",
                                "cve_description": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.  This issue has been fixed in the commit c2e233fc.  NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.",
                                "cve_priority": "negligible",
                                "cve_public_date": "2026-06-29 14:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream bug fix release. Closes: #1146744.",
                            "    Security fixes:",
                            "    - CVE-2026-86137: xmlregexp: out-of-bounds read in the NXT macro",
                            "      (xmlFAParsePosCharGroup).",
                            "    - CVE-2026-86138: dict: integer overflow in xmlDictAddQString leading",
                            "      to a heap-based buffer overflow.",
                            "    - CVE-2026-86139: uri: integer overflow in xmlURIEscapeStr.",
                            "    - CVE-2026-86140: valid: stack-based buffer overflow through unchecked",
                            "      strcat in xmlSnprintfElements.",
                            "    - CVE-2026-86141: xmlregexp: NULL pointer dereference in",
                            "      xmlRegNewParserCtxt.",
                            "    - CVE-2026-86142: xpointer: heap-based buffer overflow in",
                            "      xmlXPtrEvalXPtrPart.",
                            "    - CVE-2026-86143: xmlIO: missing integer overflow check before calling",
                            "      the write callback.",
                            "    - CVE-2026-86144: xinclude: parse flags such as XML_PARSE_NONET were",
                            "      not propagated by xmlXIncludeProcess and xmlXIncludeProcessTree.",
                            "    - CVE-2026-11979: xmlcatalog: stack-based buffer overflows in --shell",
                            "      command handling.",
                            "  * d/control: bump Standards-Version to 4.7.4, no changes needed.",
                            ""
                        ],
                        "package": "libxml2",
                        "version": "2.15.4+dfsg-1",
                        "urgency": "high",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aron Xu <aron@debian.org>",
                        "date": "Sun, 06 Sep 2026 01:58:14 +0800"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-base",
                "from_version": {
                    "source_package_name": "linux-base",
                    "source_package_version": "4.16ubuntu1",
                    "version": "4.16ubuntu1"
                },
                "to_version": {
                    "source_package_name": "linux-base",
                    "source_package_version": "4.17ubuntu1",
                    "version": "4.17ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1877088,
                    1929255,
                    1928700,
                    1867820,
                    1881338,
                    1932582,
                    2018128,
                    2098735,
                    21465330
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from debian unstable. Remaining changes:",
                            "    - Default to link_in_boot by default, on all architectures.",
                            "    - Add kernel postinst hook to update initrd softlinks to match the kernel",
                            "      version targets (LP: #1877088, #1929255).",
                            "    - Check for update-initramfs being installed before running the postinst",
                            "      hook which updates the softlinks (LP: #1928700).",
                            "    - Add linux-base-sgx package with SGX udev rules (LP: #1867820, #1881338,",
                            "      #1932582).",
                            "    - Add Apport package hook and links for kernel packages (LP: #2018128,",
                            "      #2098735, #21465330).",
                            "    - Change package maintainer to Ubuntu Kernel Team.",
                            "  * Update kernel links for Apport for Stonking.",
                            ""
                        ],
                        "package": "linux-base",
                        "version": "4.17ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1877088,
                            1929255,
                            1928700,
                            1867820,
                            1881338,
                            1932582,
                            2018128,
                            2098735,
                            21465330
                        ],
                        "author": "Juerg Haefliger <juerg.haefliger@canonical.com>",
                        "date": "Mon, 14 Sep 2026 08:58:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Also copy config file to /boot.",
                            "  * New hooks ignore all calls by unpackaged kernels. (closes: #1144902)",
                            ""
                        ],
                        "package": "linux-base",
                        "version": "4.17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Blank <waldi@debian.org>",
                        "date": "Wed, 02 Sep 2026 12:32:39 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-sysctl-defaults",
                "from_version": {
                    "source_package_name": "linux-base",
                    "source_package_version": "4.16ubuntu1",
                    "version": "4.16ubuntu1"
                },
                "to_version": {
                    "source_package_name": "linux-base",
                    "source_package_version": "4.17ubuntu1",
                    "version": "4.17ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    1877088,
                    1929255,
                    1928700,
                    1867820,
                    1881338,
                    1932582,
                    2018128,
                    2098735,
                    21465330
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge from debian unstable. Remaining changes:",
                            "    - Default to link_in_boot by default, on all architectures.",
                            "    - Add kernel postinst hook to update initrd softlinks to match the kernel",
                            "      version targets (LP: #1877088, #1929255).",
                            "    - Check for update-initramfs being installed before running the postinst",
                            "      hook which updates the softlinks (LP: #1928700).",
                            "    - Add linux-base-sgx package with SGX udev rules (LP: #1867820, #1881338,",
                            "      #1932582).",
                            "    - Add Apport package hook and links for kernel packages (LP: #2018128,",
                            "      #2098735, #21465330).",
                            "    - Change package maintainer to Ubuntu Kernel Team.",
                            "  * Update kernel links for Apport for Stonking.",
                            ""
                        ],
                        "package": "linux-base",
                        "version": "4.17ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            1877088,
                            1929255,
                            1928700,
                            1867820,
                            1881338,
                            1932582,
                            2018128,
                            2098735,
                            21465330
                        ],
                        "author": "Juerg Haefliger <juerg.haefliger@canonical.com>",
                        "date": "Mon, 14 Sep 2026 08:58:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Also copy config file to /boot.",
                            "  * New hooks ignore all calls by unpackaged kernels. (closes: #1144902)",
                            ""
                        ],
                        "package": "linux-base",
                        "version": "4.17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Bastian Blank <waldi@debian.org>",
                        "date": "Wed, 02 Sep 2026 12:32:39 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "locales",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2.3",
                    "version": "2.43-2ubuntu2.3"
                },
                "to_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.44-1ubuntu1",
                    "version": "2.44-1ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6238",
                        "url": "https://ubuntu.com/security/CVE-2026-6238",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 19:37:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5435",
                        "url": "https://ubuntu.com/security/CVE-2026-5435",
                        "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-28 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-6791",
                        "url": "https://ubuntu.com/security/CVE-2026-6791",
                        "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-10 19:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5450",
                        "url": "https://ubuntu.com/security/CVE-2026-5450",
                        "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-5928",
                        "url": "https://ubuntu.com/security/CVE-2026-5928",
                        "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-20 21:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-4046",
                        "url": "https://ubuntu.com/security/CVE-2026-4046",
                        "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-30 18:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163528
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge from Debian experimental (LP: #2163528)",
                            "    Delta dropped:",
                            "    - Revert \"debian/rules.d/build.mk: add a makefile function to filter out",
                            "      dpkg build flags incompatible with glibc and define CFLAGS from dpkg",
                            "       build flags. Closes: #1129746.\"",
                            "    - fix ftbfs: backport OPEN_TREE conditional define (LP #2145679)",
                            "      [fixed upstream in 2.44]",
                            "    - debian/patches/CVE-2026-4046.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5435.patch",
                            "      [fixed in 2.43-3]",
                            "    - debian/patches/CVE-2026-5450.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-5928.patch",
                            "      [fixed in 2.42-17]",
                            "    - debian/patches/CVE-2026-6238-*.patch",
                            "      [fixed in 2.43-3]",
                            "  * Delta added:",
                            "    - filter -flto=auto from dpkg-buildflags to fix build",
                            "    - fix tst-spawn-chdir with coreutils-rs due to invalid link name",
                            "    - xfail tst-nscd-basic tstptrguard-static-dlopen (LP #2164576)",
                            "    - d/tests: fix gcc dependency cross conflict on i386 autopkgtest",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163528
                        ],
                        "author": "Simon Poirier <simon.poirier@canonical.com>",
                        "date": "Tue, 11 Aug 2026 18:48:32 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * New upstream release:",
                            "    - debian/patches/localedata/sort-UTF8-first.diff: rebased.",
                            "    - debian/patches/hurd-i386/local-enable-ldconfig.diff: rebased.",
                            "    - debian/patches/hurd-i386/tg-libc_rwlock_recursive.diff: dropped,",
                            "      obsolete.",
                            "    - debian/patches/hurd-i386/git-fork-gdb.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-sig-mmx-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-cancel-sig.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-mach_send_eintr.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-itimer-lock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-posix-timers.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sig-alarm.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-libio-mtsafe.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-timedrwlock-unlock.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-sigtimedwait-timeout.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-MSG_EXAMINE.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-interrupt-EINTR.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SEM_FAILED.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-tst-fix.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/git-path_mounted.diff: upstreamed.",
                            "    - debian/patches/any/local-nss-overflow.diff: upstreamed.",
                            "    - debian/patches/any/local-ldconfig-multiarch.diff: refreshed.",
                            "    - debian/symbols.wildcards: add 2.44.",
                            "    - debian/sysdeps/arm64.mk: stop passing --enable-memory-tagging to",
                            "      configure, support for it was removed upstream.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/submitted-net.diff: rebased.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.44-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 15:02:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-6238",
                                "url": "https://ubuntu.com/security/CVE-2026-6238",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 19:37:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5435",
                                "url": "https://ubuntu.com/security/CVE-2026-5435",
                                "cve_description": "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-28 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-6791",
                                "url": "https://ubuntu.com/security/CVE-2026-6791",
                                "cve_description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-10 19:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/testsuite-xfail-debian.mk: Update hurd results.",
                            "  * debian/patches/hurd-i386/submitted-path_mounted.diff: Renamed to",
                            "    git-path_mounted.diff.",
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - debian/patches/hurd-i386/local-disable-ioctls.diff: rebased.",
                            "    - debian/patches/hurd-i386/submitted-AF_LINK.diff: upstreamed.",
                            "    - debian/patches/hurd-i386/submitted-AF_ROUTE.diff: upstreamed.",
                            "    - Fix a buffer overread in ns_sprintrrf with corrupted RDATA field",
                            "      (CVE-2026-6238).  Closes: #1135231.",
                            "    - Fix an out-of-bounds write in ns_sprintrrf when printing TSIG records",
                            "      (CVE-2026-5435).  Closes: #1135230.",
                            "    - Fix stack overflow in wordexp tilde expansion (CVE-2026-6791).",
                            "    - Cache cpuid results in ld.so for Intel CPUs.",
                            "    - Restore optimized memchr for POWER10.",
                            "  * debian/control.in/libc, debian/rules.d/debhelper.mk: drop the libc6-dev",
                            "    dependency on rpcsvc-proto.",
                            "  * debian/watch: set Git-Mode to shallow.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.43-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Mon, 10 Aug 2026 14:19:03 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-5450",
                                "url": "https://ubuntu.com/security/CVE-2026-5450",
                                "cve_description": "Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-5928",
                                "url": "https://ubuntu.com/security/CVE-2026-5928",
                                "cve_description": "Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-20 21:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix buffer overflow in scanf %mc (CVE-2026-5450).  Closes: #1134543.",
                            "    - Fix ungetwc operating on byte stream (CVE-2026-5928).  Closes: #1134544.",
                            "    - Save/restore VFP registers inPLT trampolines on arm.  Closes: #1133139.",
                            "    - Suppress iconv intermediate errors with //TRANSLIT.",
                            "    - debian/patches/hurd-i386/git-run-iconv-test.sh.diff: rebased.",
                            "  * debian/rules.d/build.mk: append extra_cflags to CFLAGS and ASFLAGS.",
                            "  * debian/control.in/libc: stop suggesting libnss-nisplus.",
                            "  * debian/debhelper.in/libc-bin.lintian-overrides: add a",
                            "    statically-linked-binary override for the ldconfig binary.",
                            "  * debian/control.in/main: build-depends on libselinux-dev instead of",
                            "    libselinux1-dev.",
                            "",
                            "  [ Miao Wang ]",
                            "  * debian/libc6.symbols.loong64: add.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: Add SO_TIMESTAMP macro.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-17",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 18 Jun 2026 21:48:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/sysdeps/mips*.mk: revert change to match the dpkg architecture",
                            "    name.",
                            "  * debian/rules.d/build.mk, debian/sysdeps/mips*.mk: add a way to define the",
                            "    debian architecture corresponding to a multilib build. Use it when it",
                            "    doesn't match the name of the pass and package like on mips*.",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix build against linux 7.0 headers.  Closes: #1135405.",
                            "",
                            "  [ liu jianqiang ]",
                            "  * debian/debhelper.in/locales.config: handle leading spaces in",
                            "    /etc/locale.gen configuration.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-16",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Thu, 07 May 2026 00:25:31 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-4046",
                                "url": "https://ubuntu.com/security/CVE-2026-4046",
                                "cve_description": "The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-30 18:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Aurelien Jarno ]",
                            "  * debian/patches/git-updates.diff: update from upstream stable branch:",
                            "    - Fix random failure of tst-link-map-contiguous-ldso.",
                            "    - Fix tst-rseq with Linux 7.0.",
                            "    - Fix a possible crash due to an assertion failure when converting inputs",
                            "      from the IBM139x character sets (CVE-2026-4046).  Closes: #1132499.",
                            "",
                            "  [ Samuel Thibault ]",
                            "  * debian/patches/hurd-i386/git-MSG_EXAMINE.diff: alterations to MSG_EXAMINE",
                            "    interface.",
                            "  * debian/patches/hurd-i386/git-interrupt-EINTR.diff: Interrupted RPC returning",
                            "    EINTR when server has actually changed state.",
                            "  * debian/patches/hurd-i386/git-SEM_FAILED.diff: Fix SEM_FAILED type.",
                            "  * debian/patches/hurd-i386/git-tst-fix.diff: Fix test build.",
                            ""
                        ],
                        "package": "glibc",
                        "version": "2.42-15",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Aurelien Jarno <aurel32@debian.org>",
                        "date": "Sun, 19 Apr 2026 15:41:41 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "manpages",
                "from_version": {
                    "source_package_name": "manpages",
                    "source_package_version": "6.18-1",
                    "version": "6.18-1"
                },
                "to_version": {
                    "source_package_name": "manpages",
                    "source_package_version": "6.19-3",
                    "version": "6.19-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Fix typo in pathname to actually close #1146566",
                            ""
                        ],
                        "package": "manpages",
                        "version": "6.19-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Dr. Tobias Quathamer <toddy@debian.org>",
                        "date": "Fri, 04 Sep 2026 14:58:16 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add output to autopkgtests for easier debugging",
                            "  * Use man3/tolower_l.3 to check for installed symlinks.",
                            "    The previously used symlink man3/tcflow.3 has been turned",
                            "    into a proper manpage, so the autopkgtest check that",
                            "    it is a symlink failed. (Closes: #1146566)",
                            ""
                        ],
                        "package": "manpages",
                        "version": "6.19-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Dr. Tobias Quathamer <toddy@debian.org>",
                        "date": "Thu, 03 Sep 2026 11:47:07 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version 6.19",
                            "    - Refresh patches",
                            "  * Update d/copyright",
                            "  * Do not install manpages for man0 and man9",
                            ""
                        ],
                        "package": "manpages",
                        "version": "6.19-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Dr. Tobias Quathamer <toddy@debian.org>",
                        "date": "Wed, 26 Aug 2026 17:57:51 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "mdadm",
                "from_version": {
                    "source_package_name": "mdadm",
                    "source_package_version": "4.6-2ubuntu1",
                    "version": "4.6-2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "mdadm",
                    "source_package_version": "4.6-3ubuntu1",
                    "version": "4.6-3ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2161533
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2161533). Remaining changes:",
                            "    - d/{control,mdadm.install,/finalrd/mdadm.finalrd}: ship a finalrd hook",
                            "      This is in order to have mdadm and mdmon remain available after pivoting",
                            "      away from the root filesystem.  It takes over external-metadata",
                            "      monitoring, waits for arrays to become clean, then stops arrays that can",
                            "      be deactivated.  This enables orderly shutdown of root-backed,",
                            "      external-metadata, and stacked MD arrays.",
                            "    - d/t/control: add allow-stderr restriction",
                            "    - d/t/test-installed: disable failing on error and skip tests",
                            "      Use same test settings as the upstream github tests to prevent",
                            "      failing after error and disable problematic or extra long tests",
                            "    - d/p/u/disable-tests-failing-on-ubuntu.patch: disable some tests",
                            "      that fail either intermittently or consistently on Ubuntu",
                            ""
                        ],
                        "package": "mdadm",
                        "version": "4.6-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161533
                        ],
                        "author": "Pierre-Elliott Bécue <pierre-elliott.becue@canonical.com>",
                        "date": "Thu, 20 Aug 2026 13:00:50 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Updating to debhelper 14.",
                            "  * Including rm from coreutils explicitly for systems without busybox",
                            "    (Closes: #1082657).",
                            ""
                        ],
                        "package": "mdadm",
                        "version": "4.6-3",
                        "urgency": "medium",
                        "distributions": "sid",
                        "launchpad_bugs_fixed": [],
                        "author": "Daniel Baumann <daniel@debian.org>",
                        "date": "Sun, 12 Jul 2026 19:29:50 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "multipath-tools",
                "from_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu1",
                    "version": "0.14.3-3ubuntu1"
                },
                "to_version": {
                    "source_package_name": "multipath-tools",
                    "source_package_version": "0.14.3-3ubuntu2",
                    "version": "0.14.3-3ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2165993
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Pass the -s option instead of --syslog when invoking modprobe. The",
                            "    long option is not compatible with busybox's implementation of modprobe",
                            "    (LP: #2165993).",
                            ""
                        ],
                        "package": "multipath-tools",
                        "version": "0.14.3-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165993
                        ],
                        "author": "Olivier Gayot <olivier.gayot@canonical.com>",
                        "date": "Mon, 07 Sep 2026 18:14:02 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "open-iscsi",
                "from_version": {
                    "source_package_name": "open-iscsi",
                    "source_package_version": "2.1.11-5ubuntu4",
                    "version": "2.1.11-5ubuntu4"
                },
                "to_version": {
                    "source_package_name": "open-iscsi",
                    "source_package_version": "2.1.11-5ubuntu5",
                    "version": "2.1.11-5ubuntu5"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167087
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop alternative busybox-static recommends (LP: #2167087)",
                            ""
                        ],
                        "package": "open-iscsi",
                        "version": "2.1.11-5ubuntu5",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167087
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Sun, 13 Sep 2026 22:26:54 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "open-vm-tools",
                "from_version": {
                    "source_package_name": "open-vm-tools",
                    "source_package_version": "2:13.0.10-1ubuntu5",
                    "version": "2:13.0.10-1ubuntu5"
                },
                "to_version": {
                    "source_package_name": "open-vm-tools",
                    "source_package_version": "2:13.0.10-1ubuntu6",
                    "version": "2:13.0.10-1ubuntu6"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2166910
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Avoid ordering implications to other services on non-vmware systems",
                            "    (LP: #2166910)",
                            ""
                        ],
                        "package": "open-vm-tools",
                        "version": "2:13.0.10-1ubuntu6",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166910
                        ],
                        "author": "Christian Ehrhardt <christian.ehrhardt@canonical.com>",
                        "date": "Thu, 10 Sep 2026 07:59:57 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "openssh-client",
                "from_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.3p1-4ubuntu2",
                    "version": "1:10.3p1-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.5p1-1ubuntu2",
                    "version": "1:10.5p1-1ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-73281",
                        "url": "https://ubuntu.com/security/CVE-2026-73281",
                        "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73282",
                        "url": "https://ubuntu.com/security/CVE-2026-73282",
                        "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73283",
                        "url": "https://ubuntu.com/security/CVE-2026-73283",
                        "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59995",
                        "url": "https://ubuntu.com/security/CVE-2026-59995",
                        "cve_description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59996",
                        "url": "https://ubuntu.com/security/CVE-2026-59996",
                        "cve_description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59997",
                        "url": "https://ubuntu.com/security/CVE-2026-59997",
                        "cve_description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59998",
                        "url": "https://ubuntu.com/security/CVE-2026-59998",
                        "cve_description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59999",
                        "url": "https://ubuntu.com/security/CVE-2026-59999",
                        "cve_description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60000",
                        "url": "https://ubuntu.com/security/CVE-2026-60000",
                        "cve_description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60001",
                        "url": "https://ubuntu.com/security/CVE-2026-60001",
                        "cve_description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60002",
                        "url": "https://ubuntu.com/security/CVE-2026-60002",
                        "cve_description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2150273,
                    2166924,
                    2166081,
                    2164936,
                    2165026,
                    2164221
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2150273-openssh-pam-upn: Fix PAM user mismatch with",
                            "    alternative UPN suffixes by comparing account UIDs instead of",
                            "    username strings (LP: #2150273)",
                            "  * d/t/password-auth-no-pam: create /run/sshd for the custom test",
                            "    service (LP: #2166924)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150273,
                            2166924
                        ],
                        "author": "Finn Rayk Gartner <finn.gartner@canonical.com>",
                        "date": "Wed, 09 Sep 2026 21:08:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2166081). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "      [Not needed since 1:10.5p1-1]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166081
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 01 Sep 2026 14:45:43 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-73281",
                                "url": "https://ubuntu.com/security/CVE-2026-73281",
                                "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73282",
                                "url": "https://ubuntu.com/security/CVE-2026-73282",
                                "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73283",
                                "url": "https://ubuntu.com/security/CVE-2026-73283",
                                "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1144192):",
                            "    - CVE-2026-73281: ssh-agent(1): fix an interaction between agent locking",
                            "      and the session-bind@openssh.com extension that is used to identify",
                            "      forwarded agents. These binding requests were refused when the agent",
                            "      was locked, with the result that operations that were intended to be",
                            "      limited to local use only could be performed remotely, including the",
                            "      ability to add PKCS#11 tokens and make use of keys that had",
                            "      destination restrictions applied.",
                            "    - CVE-2026-73282: ssh(1): avoid potential realloc use-after-free in the",
                            "      client if a remote forwarding is added via the local session",
                            "      multiplexing socket while a remote forwarding open request is pending",
                            "      with the server.",
                            "    - CVE-2026-73283: sshd(8): make the authorized_keys \"restrict\" keyword",
                            "      apply correctly to tunnel forwarding too (which is administratively",
                            "      disabled by default).",
                            "    - ssh-keygen(1): add ability to set or clear the touch-required and",
                            "      verify-required flags on FIDO private keys when resetting a private",
                            "      key's passphrase.",
                            "    - ssh(1): tweak ordering of certificates tried during pubkey",
                            "      authentication to prefer FIDO keys that do not require user presence",
                            "      (touch) first, and FIDO keys that require user verification via PIN or",
                            "      biometrics last. This effectively tries low-friction authenticators",
                            "      before higher friction ones.",
                            "    - ssh(1): add a \"ssh -Z user@host\" mode that prints the keys that will",
                            "      be tried for public key authentication in the order that they will be",
                            "      used.",
                            "    - sshd(8) use setproctitle(3) to identify sshd-session when it's acting",
                            "      as a post-authentication monitor.",
                            "    - ssh-keyscan(1): make reading the server banner a non-blocking",
                            "      operation to prevent a stuck server from blocking a many-host keyscan",
                            "      from proceeding.",
                            "    - sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the",
                            "      packet code as this provides context of the failing peer (address,",
                            "      port, user, etc).",
                            "    - sshd(8): when signing hostkey proofs for a client UpdateHostKeys",
                            "      request, allow each hostkey to perform at most one signature",
                            "      operation.",
                            "    - ssh-keygen(1): pass back errors from ed25519 key generation, which",
                            "      theoretically can fail.",
                            "    - sshd(8): move check of public key type against allowed algorithms to",
                            "      before parsing of the key sent by the peer. This removes at least some",
                            "      key parsing and verification paths from the pre-auth attack surface.",
                            "    - ssh-keygen(1): fix double frees (impossible to reach outside of a test",
                            "      harness), and also use freezero where possible.",
                            "    - sshd(8): fix ChannelTimeout and RekeyLimit not being applied in",
                            "      sshd_config Match blocks.",
                            "    - sshd(8): in sshd config dump mode, write all directives in mixed case",
                            "      for consistency.",
                            "    - sshd(8): re-allow PAMServiceName inside a Match block, which was",
                            "      incorrectly disabled during a refactoring in openssh-10.4.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 31 Aug 2026 20:53:27 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164936). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "  * Added:",
                            "    - d/openssh-server.ucf-md5sum: update for 1:10.4p1-5ubuntu1",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/ssh-gssapi: disable -e in cleanup()",
                            "      [Test no longer shipped in this source package]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-5ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164936
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Thu, 27 Aug 2026 09:37:48 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop GSS-API authentication and key exchange support, to reduce",
                            "    pre-authentication attack surface.  Users who need these features should",
                            "    install openssh-client-gssapi or openssh-server-gssapi instead.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 23 Aug 2026 17:39:55 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/rules: only act on files from bin:openssh-tests if it's being",
                            "    built (LP: #2165026)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165026
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 25 Aug 2026 09:19:48 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164221). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/t/ssh-gssapi: disable -e in cleanup()",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "  * Added:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164221
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:34:01 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add missing test dependencies.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 31 Jul 2026 17:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove most openssh-* dependencies from openssh-tests.",
                            "  * Add Slovak debconf translation (thanks, Damian Daniel; closes:",
                            "    #1142938).",
                            "  * Remove references to rsh/rcp/rlogin/rshd from package descriptions.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Tue, 28 Jul 2026 16:29:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Alexander Fisher ]",
                            "  * Build-Depends: add libcrypt-dev so crypt() is detected at build time,",
                            "    fixing password authentication with UsePAM=no (closes: #1142354).",
                            "  * debian/tests: add password-auth-no-pam regression test.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 19 Jul 2026 12:46:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-59995",
                                "url": "https://ubuntu.com/security/CVE-2026-59995",
                                "cve_description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59996",
                                "url": "https://ubuntu.com/security/CVE-2026-59996",
                                "cve_description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59997",
                                "url": "https://ubuntu.com/security/CVE-2026-59997",
                                "cve_description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59998",
                                "url": "https://ubuntu.com/security/CVE-2026-59998",
                                "cve_description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59999",
                                "url": "https://ubuntu.com/security/CVE-2026-59999",
                                "cve_description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60000",
                                "url": "https://ubuntu.com/security/CVE-2026-60000",
                                "cve_description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60001",
                                "url": "https://ubuntu.com/security/CVE-2026-60001",
                                "cve_description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60002",
                                "url": "https://ubuntu.com/security/CVE-2026-60002",
                                "cve_description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Sven Joachim ]",
                            "  * Make doc symlinks relative on upgrade from 1:10.3p1-5 (closes:",
                            "    #1141420).",
                            "",
                            "  [ Colin Watson ]",
                            "  * New upstream release:",
                            "    - CVE-2026-59995: sftp(1): when downloading files on the command-line",
                            "      using \"sftp host:/path .\", a malicious server could cause the file to",
                            "      be downloaded to an unexpected location. This issue was identified by",
                            "      the Swival Security Scanner.",
                            "    - CVE-2026-59996: scp(1): when copying files between two remote",
                            "      destinations, do not allow a malicious server to write files to the",
                            "      parent directory of the intended target directory. This issue was",
                            "      identified by the Swival Security Scanner.",
                            "    - CVE-2026-59997: sshd(8): when using the \"internal-sftp\" SFTP server",
                            "      implementation (this is not the default), long command lines were",
                            "      previously truncated silently after the 9th argument. If a",
                            "      security-relevant option was in the 10th or later position, it would",
                            "      be discarded. Reported by Steve Caffrey.",
                            "    - CVE-2026-59998: sshd(8): add a documentation note to mention that the",
                            "      GSSAPIStrictAcceptorCheck option is ineffective when the server is",
                            "      joined to a Windows Active Directory. Reported by Yarin Aharoni of",
                            "      Safebreach.",
                            "    - CVE-2026-59999: sshd(8): DisableForwarding=yes didn't override",
                            "      PermitTunnel=yes as it was documented to do. Note that PermitTunnel is",
                            "      not enabled by default. Reported independently by Huzaifa Sidhpurwala",
                            "      of Redhat and Marko Jevtic.",
                            "    - CVE-2026-60000: sshd(8): avoid a potential pre-authentication denial",
                            "      of service when GSSAPIAuthentication was enabled (this feature is off",
                            "      by default). This was not mitigated by MaxAuthTries, but would be",
                            "      penalised by PerSourcePenalties. This was reported by Manfred Kaiser",
                            "      of the milCERT AT (Austrian Ministry of Defence).",
                            "    - CVE-2026-60001: sshd(8): fix a number of cases where the minimum",
                            "      authentication delay was not being enforced. Reported by the Orange",
                            "      Cyberdefense Vulnerability Team.",
                            "    - CVE-2026-60002: ssh(1): fix a possible client-side use-after-free if",
                            "      the server changes its host key during a key reexchange. This was",
                            "      reported by Zhenpeng (Leo) Lin of Depthfirst.",
                            "    - All: add experimental support for a composite post-quantum signature",
                            "      scheme that combines ML-DSA 44 and Ed25519 as specified in",
                            "      draft-miller-sshm-mldsa44-ed25519-composite-sigs. This scheme is not",
                            "      enabled by default. To use it, you'll need to add it to",
                            "      HostKeyAlgorithms, PubkeyAcceptedAlgorithms, etc. Keys may be",
                            "      generated using \"ssh-keygen -t mldsa44-ed25519\".",
                            "    - ssh(1), sshd(8): replace the wildcard pattern matcher with an",
                            "      implementation based on an NFA. This avoids exponential worst-case",
                            "      behaviour for the old implementation.",
                            "    - ssh-agent(1): fix incorrect reply to \"query\" SSH_AGENTC_EXTENSION",
                            "      requests.",
                            "    - sshd(8): avoid sending observably different messages for valid vs",
                            "      invalid users in GSSAPIAuthentication (disabled by default).",
                            "    - ssh(1), sshd(8): fix several bugs that incorrectly classified bulk",
                            "      traffic as interactive.",
                            "    - ssh-keygen(1), ssh-add(1): skip unsupported key types when downloading",
                            "      resident keys from a FIDO token. Previously, downloads would abort",
                            "      when one was encountered.",
                            "    - ssh(1): fix a potential use-after-free on an error path if",
                            "      cipher_init() fails.",
                            "    - sshd(8): perform stricter encoding and validation of transport state",
                            "      passed between sshd privilege separation subprocesses. This somewhat",
                            "      further hardens the server against attacks on sshd-auth or",
                            "      sshd-session subprocesses.",
                            "    - ssh-agent(1): avoid possible runtime denial of service by enforcing",
                            "      some limits on the length of usernames in key use constraints.",
                            "    - sftp(1): fix two separate one-byte out-of-bounds reads, in",
                            "      SSH2_FXP_REALPATH and batch command processing.",
                            "    - sftp-server(8): disallow use of the copy-data extension to read and",
                            "      write to the same inode simultaneously.",
                            "    - ssh(1), sshd(8): avoid strlen(NULL) crash if an X11 channel was",
                            "      created before the x11-req SSH_MSG_CHANNEL_REQUEST was sent.",
                            "    - sftp(1), scp(1): avoid a situation where sftp_download() could get",
                            "      stuck in a loop if a broken server repeatedly returned zero length",
                            "      while reading a file.",
                            "    - ssh(1): avoid leaking DNS0x20 case-randomised names into names",
                            "      canonicalised using CanonicalizePermittedCNAMEs.",
                            "    - sftp-server(8): avoid truncation of pathnames passed to lstat() during",
                            "      SSH_FXP_REALPATH handling on systems where PATH_MAX is not the actual",
                            "      max.",
                            "    - ssh(1), sshd(8): correct arming of poll(2) event masks for some",
                            "      socket-type channels.",
                            "    - sshd(8): major refactor of sshd_config parsing and management code, to",
                            "      allow for more exact serialisation/deserialisation across privilege",
                            "      separation boundaries.",
                            "    - ssh-add(1): open connection to the agent only after getopt()",
                            "      processing has completed, to give options like \"-v\" a chance to",
                            "      display debug information about this operation.",
                            "    - sshd(8): differentiate between execution failures and a subsystem that",
                            "      was not found when logging why a subsystem failed to start.",
                            "    - All: use safer idioms for timegm(3) and mktime(3) error detection.",
                            "    - ssh(1), sshd(8): avoid accepting invalid cipher or MAC lists in config",
                            "      files or command-line arguments. This could cause runtime failures",
                            "      later.",
                            "    - ssh(1): fix NULL deref crash during pubkey auth when using a PEM style",
                            "      private key with no corresponding .pub key adjacent to it (closes:",
                            "      #1134814).",
                            "    - sshd(8): don't print an error message when trying to load a host",
                            "      private key when PKCS#11 keys are in use, as these don't need the",
                            "      private half on the filesystem.",
                            "    - All: don't use deprecated ERR_load_crypto_strings().",
                            "    - ssh(1): properly report errors during configuration default setting.",
                            "    - ssh(1): use correct directive name (Match instead of Host) in error",
                            "      message.",
                            "    - sftp(1): fix \"ls -ln\" which was not correctly showing numeric UID/GIDs",
                            "      but rather user and group names.",
                            "    - sshd(8): avoid possible NULL dereference if an allocation fails during",
                            "      config parsing.",
                            "    - All: fix ineffective guards against loading overly large public keys",
                            "      in several places.",
                            "    - sftp(1): ensure file descriptors used by sftp to communicate to its",
                            "      ssh(1) subprocess don't leak into executed subprocesses (e.g. via",
                            "      \"!\").",
                            "    - Sync fmt_scaled.c with OpenBSD upstream, picking up an exactness fix",
                            "      for large exponents.",
                            "    - sshd(8): remove duplicate sandbox entry for clock_gettime64.",
                            "    - Sync getrrsetbyname.c with OpenBSD upstream, picking up robustness",
                            "      fixes.",
                            "    - Fix a number of memory leaks on error paths in the portability code.",
                            "    - Revise the README.privsep documentation to reflect sshd's recent",
                            "      switch to a multi-binary model.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 19:11:28 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * openssh-client Conflicts: openssh-server (<< 1:10.3p1-6~) (closes:",
                            "    #1141550).",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-9",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 09:51:32 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/copyright: Add some missing authors.",
                            "  * Standards-Version: 4.7.4.",
                            "  * openssh-tests: Make a couple more scripts executable.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-8",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 03 Jul 2026 16:54:01 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Reupload with binaries, since openssh-common is new.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 03 Jul 2026 00:32:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Move documentation to a new openssh-common package (closes: #1070098).",
                            "  * Remove dependency on openssh-client{,-gssapi} from",
                            "    openssh-server{,-gssapi} (closes: #699473).",
                            "  * Use --link-doc on all packages.",
                            "  * Move ssh-keygen and openssh-{pkcs11,sk}-helper to openssh-common.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Thu, 02 Jul 2026 20:24:29 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * Support DPKG_ROOT.",
                            "",
                            "  [ Colin Watson ]",
                            "  * d/copyright: Significantly rework to be lrc-clean.",
                            "",
                            "  [ Roland C. Dowdeswell ]",
                            "  * Fix GSS C25519 server blob bounds check.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 26 Jun 2026 16:16:18 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "openssh-server",
                "from_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.3p1-4ubuntu2",
                    "version": "1:10.3p1-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.5p1-1ubuntu2",
                    "version": "1:10.5p1-1ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-73281",
                        "url": "https://ubuntu.com/security/CVE-2026-73281",
                        "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73282",
                        "url": "https://ubuntu.com/security/CVE-2026-73282",
                        "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73283",
                        "url": "https://ubuntu.com/security/CVE-2026-73283",
                        "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59995",
                        "url": "https://ubuntu.com/security/CVE-2026-59995",
                        "cve_description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59996",
                        "url": "https://ubuntu.com/security/CVE-2026-59996",
                        "cve_description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59997",
                        "url": "https://ubuntu.com/security/CVE-2026-59997",
                        "cve_description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59998",
                        "url": "https://ubuntu.com/security/CVE-2026-59998",
                        "cve_description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59999",
                        "url": "https://ubuntu.com/security/CVE-2026-59999",
                        "cve_description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60000",
                        "url": "https://ubuntu.com/security/CVE-2026-60000",
                        "cve_description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60001",
                        "url": "https://ubuntu.com/security/CVE-2026-60001",
                        "cve_description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60002",
                        "url": "https://ubuntu.com/security/CVE-2026-60002",
                        "cve_description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2150273,
                    2166924,
                    2166081,
                    2164936,
                    2165026,
                    2164221
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2150273-openssh-pam-upn: Fix PAM user mismatch with",
                            "    alternative UPN suffixes by comparing account UIDs instead of",
                            "    username strings (LP: #2150273)",
                            "  * d/t/password-auth-no-pam: create /run/sshd for the custom test",
                            "    service (LP: #2166924)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150273,
                            2166924
                        ],
                        "author": "Finn Rayk Gartner <finn.gartner@canonical.com>",
                        "date": "Wed, 09 Sep 2026 21:08:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2166081). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "      [Not needed since 1:10.5p1-1]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166081
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 01 Sep 2026 14:45:43 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-73281",
                                "url": "https://ubuntu.com/security/CVE-2026-73281",
                                "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73282",
                                "url": "https://ubuntu.com/security/CVE-2026-73282",
                                "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73283",
                                "url": "https://ubuntu.com/security/CVE-2026-73283",
                                "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1144192):",
                            "    - CVE-2026-73281: ssh-agent(1): fix an interaction between agent locking",
                            "      and the session-bind@openssh.com extension that is used to identify",
                            "      forwarded agents. These binding requests were refused when the agent",
                            "      was locked, with the result that operations that were intended to be",
                            "      limited to local use only could be performed remotely, including the",
                            "      ability to add PKCS#11 tokens and make use of keys that had",
                            "      destination restrictions applied.",
                            "    - CVE-2026-73282: ssh(1): avoid potential realloc use-after-free in the",
                            "      client if a remote forwarding is added via the local session",
                            "      multiplexing socket while a remote forwarding open request is pending",
                            "      with the server.",
                            "    - CVE-2026-73283: sshd(8): make the authorized_keys \"restrict\" keyword",
                            "      apply correctly to tunnel forwarding too (which is administratively",
                            "      disabled by default).",
                            "    - ssh-keygen(1): add ability to set or clear the touch-required and",
                            "      verify-required flags on FIDO private keys when resetting a private",
                            "      key's passphrase.",
                            "    - ssh(1): tweak ordering of certificates tried during pubkey",
                            "      authentication to prefer FIDO keys that do not require user presence",
                            "      (touch) first, and FIDO keys that require user verification via PIN or",
                            "      biometrics last. This effectively tries low-friction authenticators",
                            "      before higher friction ones.",
                            "    - ssh(1): add a \"ssh -Z user@host\" mode that prints the keys that will",
                            "      be tried for public key authentication in the order that they will be",
                            "      used.",
                            "    - sshd(8) use setproctitle(3) to identify sshd-session when it's acting",
                            "      as a post-authentication monitor.",
                            "    - ssh-keyscan(1): make reading the server banner a non-blocking",
                            "      operation to prevent a stuck server from blocking a many-host keyscan",
                            "      from proceeding.",
                            "    - sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the",
                            "      packet code as this provides context of the failing peer (address,",
                            "      port, user, etc).",
                            "    - sshd(8): when signing hostkey proofs for a client UpdateHostKeys",
                            "      request, allow each hostkey to perform at most one signature",
                            "      operation.",
                            "    - ssh-keygen(1): pass back errors from ed25519 key generation, which",
                            "      theoretically can fail.",
                            "    - sshd(8): move check of public key type against allowed algorithms to",
                            "      before parsing of the key sent by the peer. This removes at least some",
                            "      key parsing and verification paths from the pre-auth attack surface.",
                            "    - ssh-keygen(1): fix double frees (impossible to reach outside of a test",
                            "      harness), and also use freezero where possible.",
                            "    - sshd(8): fix ChannelTimeout and RekeyLimit not being applied in",
                            "      sshd_config Match blocks.",
                            "    - sshd(8): in sshd config dump mode, write all directives in mixed case",
                            "      for consistency.",
                            "    - sshd(8): re-allow PAMServiceName inside a Match block, which was",
                            "      incorrectly disabled during a refactoring in openssh-10.4.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 31 Aug 2026 20:53:27 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164936). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "  * Added:",
                            "    - d/openssh-server.ucf-md5sum: update for 1:10.4p1-5ubuntu1",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/ssh-gssapi: disable -e in cleanup()",
                            "      [Test no longer shipped in this source package]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-5ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164936
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Thu, 27 Aug 2026 09:37:48 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop GSS-API authentication and key exchange support, to reduce",
                            "    pre-authentication attack surface.  Users who need these features should",
                            "    install openssh-client-gssapi or openssh-server-gssapi instead.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 23 Aug 2026 17:39:55 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/rules: only act on files from bin:openssh-tests if it's being",
                            "    built (LP: #2165026)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165026
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 25 Aug 2026 09:19:48 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164221). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/t/ssh-gssapi: disable -e in cleanup()",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "  * Added:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164221
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:34:01 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add missing test dependencies.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 31 Jul 2026 17:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove most openssh-* dependencies from openssh-tests.",
                            "  * Add Slovak debconf translation (thanks, Damian Daniel; closes:",
                            "    #1142938).",
                            "  * Remove references to rsh/rcp/rlogin/rshd from package descriptions.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Tue, 28 Jul 2026 16:29:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Alexander Fisher ]",
                            "  * Build-Depends: add libcrypt-dev so crypt() is detected at build time,",
                            "    fixing password authentication with UsePAM=no (closes: #1142354).",
                            "  * debian/tests: add password-auth-no-pam regression test.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 19 Jul 2026 12:46:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-59995",
                                "url": "https://ubuntu.com/security/CVE-2026-59995",
                                "cve_description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59996",
                                "url": "https://ubuntu.com/security/CVE-2026-59996",
                                "cve_description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59997",
                                "url": "https://ubuntu.com/security/CVE-2026-59997",
                                "cve_description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59998",
                                "url": "https://ubuntu.com/security/CVE-2026-59998",
                                "cve_description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59999",
                                "url": "https://ubuntu.com/security/CVE-2026-59999",
                                "cve_description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60000",
                                "url": "https://ubuntu.com/security/CVE-2026-60000",
                                "cve_description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60001",
                                "url": "https://ubuntu.com/security/CVE-2026-60001",
                                "cve_description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60002",
                                "url": "https://ubuntu.com/security/CVE-2026-60002",
                                "cve_description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Sven Joachim ]",
                            "  * Make doc symlinks relative on upgrade from 1:10.3p1-5 (closes:",
                            "    #1141420).",
                            "",
                            "  [ Colin Watson ]",
                            "  * New upstream release:",
                            "    - CVE-2026-59995: sftp(1): when downloading files on the command-line",
                            "      using \"sftp host:/path .\", a malicious server could cause the file to",
                            "      be downloaded to an unexpected location. This issue was identified by",
                            "      the Swival Security Scanner.",
                            "    - CVE-2026-59996: scp(1): when copying files between two remote",
                            "      destinations, do not allow a malicious server to write files to the",
                            "      parent directory of the intended target directory. This issue was",
                            "      identified by the Swival Security Scanner.",
                            "    - CVE-2026-59997: sshd(8): when using the \"internal-sftp\" SFTP server",
                            "      implementation (this is not the default), long command lines were",
                            "      previously truncated silently after the 9th argument. If a",
                            "      security-relevant option was in the 10th or later position, it would",
                            "      be discarded. Reported by Steve Caffrey.",
                            "    - CVE-2026-59998: sshd(8): add a documentation note to mention that the",
                            "      GSSAPIStrictAcceptorCheck option is ineffective when the server is",
                            "      joined to a Windows Active Directory. Reported by Yarin Aharoni of",
                            "      Safebreach.",
                            "    - CVE-2026-59999: sshd(8): DisableForwarding=yes didn't override",
                            "      PermitTunnel=yes as it was documented to do. Note that PermitTunnel is",
                            "      not enabled by default. Reported independently by Huzaifa Sidhpurwala",
                            "      of Redhat and Marko Jevtic.",
                            "    - CVE-2026-60000: sshd(8): avoid a potential pre-authentication denial",
                            "      of service when GSSAPIAuthentication was enabled (this feature is off",
                            "      by default). This was not mitigated by MaxAuthTries, but would be",
                            "      penalised by PerSourcePenalties. This was reported by Manfred Kaiser",
                            "      of the milCERT AT (Austrian Ministry of Defence).",
                            "    - CVE-2026-60001: sshd(8): fix a number of cases where the minimum",
                            "      authentication delay was not being enforced. Reported by the Orange",
                            "      Cyberdefense Vulnerability Team.",
                            "    - CVE-2026-60002: ssh(1): fix a possible client-side use-after-free if",
                            "      the server changes its host key during a key reexchange. This was",
                            "      reported by Zhenpeng (Leo) Lin of Depthfirst.",
                            "    - All: add experimental support for a composite post-quantum signature",
                            "      scheme that combines ML-DSA 44 and Ed25519 as specified in",
                            "      draft-miller-sshm-mldsa44-ed25519-composite-sigs. This scheme is not",
                            "      enabled by default. To use it, you'll need to add it to",
                            "      HostKeyAlgorithms, PubkeyAcceptedAlgorithms, etc. Keys may be",
                            "      generated using \"ssh-keygen -t mldsa44-ed25519\".",
                            "    - ssh(1), sshd(8): replace the wildcard pattern matcher with an",
                            "      implementation based on an NFA. This avoids exponential worst-case",
                            "      behaviour for the old implementation.",
                            "    - ssh-agent(1): fix incorrect reply to \"query\" SSH_AGENTC_EXTENSION",
                            "      requests.",
                            "    - sshd(8): avoid sending observably different messages for valid vs",
                            "      invalid users in GSSAPIAuthentication (disabled by default).",
                            "    - ssh(1), sshd(8): fix several bugs that incorrectly classified bulk",
                            "      traffic as interactive.",
                            "    - ssh-keygen(1), ssh-add(1): skip unsupported key types when downloading",
                            "      resident keys from a FIDO token. Previously, downloads would abort",
                            "      when one was encountered.",
                            "    - ssh(1): fix a potential use-after-free on an error path if",
                            "      cipher_init() fails.",
                            "    - sshd(8): perform stricter encoding and validation of transport state",
                            "      passed between sshd privilege separation subprocesses. This somewhat",
                            "      further hardens the server against attacks on sshd-auth or",
                            "      sshd-session subprocesses.",
                            "    - ssh-agent(1): avoid possible runtime denial of service by enforcing",
                            "      some limits on the length of usernames in key use constraints.",
                            "    - sftp(1): fix two separate one-byte out-of-bounds reads, in",
                            "      SSH2_FXP_REALPATH and batch command processing.",
                            "    - sftp-server(8): disallow use of the copy-data extension to read and",
                            "      write to the same inode simultaneously.",
                            "    - ssh(1), sshd(8): avoid strlen(NULL) crash if an X11 channel was",
                            "      created before the x11-req SSH_MSG_CHANNEL_REQUEST was sent.",
                            "    - sftp(1), scp(1): avoid a situation where sftp_download() could get",
                            "      stuck in a loop if a broken server repeatedly returned zero length",
                            "      while reading a file.",
                            "    - ssh(1): avoid leaking DNS0x20 case-randomised names into names",
                            "      canonicalised using CanonicalizePermittedCNAMEs.",
                            "    - sftp-server(8): avoid truncation of pathnames passed to lstat() during",
                            "      SSH_FXP_REALPATH handling on systems where PATH_MAX is not the actual",
                            "      max.",
                            "    - ssh(1), sshd(8): correct arming of poll(2) event masks for some",
                            "      socket-type channels.",
                            "    - sshd(8): major refactor of sshd_config parsing and management code, to",
                            "      allow for more exact serialisation/deserialisation across privilege",
                            "      separation boundaries.",
                            "    - ssh-add(1): open connection to the agent only after getopt()",
                            "      processing has completed, to give options like \"-v\" a chance to",
                            "      display debug information about this operation.",
                            "    - sshd(8): differentiate between execution failures and a subsystem that",
                            "      was not found when logging why a subsystem failed to start.",
                            "    - All: use safer idioms for timegm(3) and mktime(3) error detection.",
                            "    - ssh(1), sshd(8): avoid accepting invalid cipher or MAC lists in config",
                            "      files or command-line arguments. This could cause runtime failures",
                            "      later.",
                            "    - ssh(1): fix NULL deref crash during pubkey auth when using a PEM style",
                            "      private key with no corresponding .pub key adjacent to it (closes:",
                            "      #1134814).",
                            "    - sshd(8): don't print an error message when trying to load a host",
                            "      private key when PKCS#11 keys are in use, as these don't need the",
                            "      private half on the filesystem.",
                            "    - All: don't use deprecated ERR_load_crypto_strings().",
                            "    - ssh(1): properly report errors during configuration default setting.",
                            "    - ssh(1): use correct directive name (Match instead of Host) in error",
                            "      message.",
                            "    - sftp(1): fix \"ls -ln\" which was not correctly showing numeric UID/GIDs",
                            "      but rather user and group names.",
                            "    - sshd(8): avoid possible NULL dereference if an allocation fails during",
                            "      config parsing.",
                            "    - All: fix ineffective guards against loading overly large public keys",
                            "      in several places.",
                            "    - sftp(1): ensure file descriptors used by sftp to communicate to its",
                            "      ssh(1) subprocess don't leak into executed subprocesses (e.g. via",
                            "      \"!\").",
                            "    - Sync fmt_scaled.c with OpenBSD upstream, picking up an exactness fix",
                            "      for large exponents.",
                            "    - sshd(8): remove duplicate sandbox entry for clock_gettime64.",
                            "    - Sync getrrsetbyname.c with OpenBSD upstream, picking up robustness",
                            "      fixes.",
                            "    - Fix a number of memory leaks on error paths in the portability code.",
                            "    - Revise the README.privsep documentation to reflect sshd's recent",
                            "      switch to a multi-binary model.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 19:11:28 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * openssh-client Conflicts: openssh-server (<< 1:10.3p1-6~) (closes:",
                            "    #1141550).",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-9",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 09:51:32 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/copyright: Add some missing authors.",
                            "  * Standards-Version: 4.7.4.",
                            "  * openssh-tests: Make a couple more scripts executable.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-8",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 03 Jul 2026 16:54:01 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Reupload with binaries, since openssh-common is new.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 03 Jul 2026 00:32:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Move documentation to a new openssh-common package (closes: #1070098).",
                            "  * Remove dependency on openssh-client{,-gssapi} from",
                            "    openssh-server{,-gssapi} (closes: #699473).",
                            "  * Use --link-doc on all packages.",
                            "  * Move ssh-keygen and openssh-{pkcs11,sk}-helper to openssh-common.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Thu, 02 Jul 2026 20:24:29 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * Support DPKG_ROOT.",
                            "",
                            "  [ Colin Watson ]",
                            "  * d/copyright: Significantly rework to be lrc-clean.",
                            "",
                            "  [ Roland C. Dowdeswell ]",
                            "  * Fix GSS C25519 server blob bounds check.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 26 Jun 2026 16:16:18 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "openssh-sftp-server",
                "from_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.3p1-4ubuntu2",
                    "version": "1:10.3p1-4ubuntu2"
                },
                "to_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.5p1-1ubuntu2",
                    "version": "1:10.5p1-1ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-73281",
                        "url": "https://ubuntu.com/security/CVE-2026-73281",
                        "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73282",
                        "url": "https://ubuntu.com/security/CVE-2026-73282",
                        "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73283",
                        "url": "https://ubuntu.com/security/CVE-2026-73283",
                        "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59995",
                        "url": "https://ubuntu.com/security/CVE-2026-59995",
                        "cve_description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59996",
                        "url": "https://ubuntu.com/security/CVE-2026-59996",
                        "cve_description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59997",
                        "url": "https://ubuntu.com/security/CVE-2026-59997",
                        "cve_description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59998",
                        "url": "https://ubuntu.com/security/CVE-2026-59998",
                        "cve_description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-59999",
                        "url": "https://ubuntu.com/security/CVE-2026-59999",
                        "cve_description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60000",
                        "url": "https://ubuntu.com/security/CVE-2026-60000",
                        "cve_description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60001",
                        "url": "https://ubuntu.com/security/CVE-2026-60001",
                        "cve_description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-60002",
                        "url": "https://ubuntu.com/security/CVE-2026-60002",
                        "cve_description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-08 01:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2150273,
                    2166924,
                    2166081,
                    2164936,
                    2165026,
                    2164221
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2150273-openssh-pam-upn: Fix PAM user mismatch with",
                            "    alternative UPN suffixes by comparing account UIDs instead of",
                            "    username strings (LP: #2150273)",
                            "  * d/t/password-auth-no-pam: create /run/sshd for the custom test",
                            "    service (LP: #2166924)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150273,
                            2166924
                        ],
                        "author": "Finn Rayk Gartner <finn.gartner@canonical.com>",
                        "date": "Wed, 09 Sep 2026 21:08:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2166081). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "      [Not needed since 1:10.5p1-1]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166081
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 01 Sep 2026 14:45:43 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-73281",
                                "url": "https://ubuntu.com/security/CVE-2026-73281",
                                "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73282",
                                "url": "https://ubuntu.com/security/CVE-2026-73282",
                                "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73283",
                                "url": "https://ubuntu.com/security/CVE-2026-73283",
                                "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1144192):",
                            "    - CVE-2026-73281: ssh-agent(1): fix an interaction between agent locking",
                            "      and the session-bind@openssh.com extension that is used to identify",
                            "      forwarded agents. These binding requests were refused when the agent",
                            "      was locked, with the result that operations that were intended to be",
                            "      limited to local use only could be performed remotely, including the",
                            "      ability to add PKCS#11 tokens and make use of keys that had",
                            "      destination restrictions applied.",
                            "    - CVE-2026-73282: ssh(1): avoid potential realloc use-after-free in the",
                            "      client if a remote forwarding is added via the local session",
                            "      multiplexing socket while a remote forwarding open request is pending",
                            "      with the server.",
                            "    - CVE-2026-73283: sshd(8): make the authorized_keys \"restrict\" keyword",
                            "      apply correctly to tunnel forwarding too (which is administratively",
                            "      disabled by default).",
                            "    - ssh-keygen(1): add ability to set or clear the touch-required and",
                            "      verify-required flags on FIDO private keys when resetting a private",
                            "      key's passphrase.",
                            "    - ssh(1): tweak ordering of certificates tried during pubkey",
                            "      authentication to prefer FIDO keys that do not require user presence",
                            "      (touch) first, and FIDO keys that require user verification via PIN or",
                            "      biometrics last. This effectively tries low-friction authenticators",
                            "      before higher friction ones.",
                            "    - ssh(1): add a \"ssh -Z user@host\" mode that prints the keys that will",
                            "      be tried for public key authentication in the order that they will be",
                            "      used.",
                            "    - sshd(8) use setproctitle(3) to identify sshd-session when it's acting",
                            "      as a post-authentication monitor.",
                            "    - ssh-keyscan(1): make reading the server banner a non-blocking",
                            "      operation to prevent a stuck server from blocking a many-host keyscan",
                            "      from proceeding.",
                            "    - sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the",
                            "      packet code as this provides context of the failing peer (address,",
                            "      port, user, etc).",
                            "    - sshd(8): when signing hostkey proofs for a client UpdateHostKeys",
                            "      request, allow each hostkey to perform at most one signature",
                            "      operation.",
                            "    - ssh-keygen(1): pass back errors from ed25519 key generation, which",
                            "      theoretically can fail.",
                            "    - sshd(8): move check of public key type against allowed algorithms to",
                            "      before parsing of the key sent by the peer. This removes at least some",
                            "      key parsing and verification paths from the pre-auth attack surface.",
                            "    - ssh-keygen(1): fix double frees (impossible to reach outside of a test",
                            "      harness), and also use freezero where possible.",
                            "    - sshd(8): fix ChannelTimeout and RekeyLimit not being applied in",
                            "      sshd_config Match blocks.",
                            "    - sshd(8): in sshd config dump mode, write all directives in mixed case",
                            "      for consistency.",
                            "    - sshd(8): re-allow PAMServiceName inside a Match block, which was",
                            "      incorrectly disabled during a refactoring in openssh-10.4.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 31 Aug 2026 20:53:27 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164936). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "  * Added:",
                            "    - d/openssh-server.ucf-md5sum: update for 1:10.4p1-5ubuntu1",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/ssh-gssapi: disable -e in cleanup()",
                            "      [Test no longer shipped in this source package]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-5ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164936
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Thu, 27 Aug 2026 09:37:48 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Drop GSS-API authentication and key exchange support, to reduce",
                            "    pre-authentication attack surface.  Users who need these features should",
                            "    install openssh-client-gssapi or openssh-server-gssapi instead.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 23 Aug 2026 17:39:55 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/rules: only act on files from bin:openssh-tests if it's being",
                            "    built (LP: #2165026)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2165026
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 25 Aug 2026 09:19:48 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164221). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/t/ssh-gssapi: disable -e in cleanup()",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "  * Added:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164221
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:34:01 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add missing test dependencies.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 31 Jul 2026 17:11:39 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Remove most openssh-* dependencies from openssh-tests.",
                            "  * Add Slovak debconf translation (thanks, Damian Daniel; closes:",
                            "    #1142938).",
                            "  * Remove references to rsh/rcp/rlogin/rshd from package descriptions.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Tue, 28 Jul 2026 16:29:14 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Alexander Fisher ]",
                            "  * Build-Depends: add libcrypt-dev so crypt() is detected at build time,",
                            "    fixing password authentication with UsePAM=no (closes: #1142354).",
                            "  * debian/tests: add password-auth-no-pam regression test.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Sun, 19 Jul 2026 12:46:25 +0100"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-59995",
                                "url": "https://ubuntu.com/security/CVE-2026-59995",
                                "cve_description": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59996",
                                "url": "https://ubuntu.com/security/CVE-2026-59996",
                                "cve_description": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59997",
                                "url": "https://ubuntu.com/security/CVE-2026-59997",
                                "cve_description": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59998",
                                "url": "https://ubuntu.com/security/CVE-2026-59998",
                                "cve_description": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-59999",
                                "url": "https://ubuntu.com/security/CVE-2026-59999",
                                "cve_description": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60000",
                                "url": "https://ubuntu.com/security/CVE-2026-60000",
                                "cve_description": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60001",
                                "url": "https://ubuntu.com/security/CVE-2026-60001",
                                "cve_description": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-60002",
                                "url": "https://ubuntu.com/security/CVE-2026-60002",
                                "cve_description": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-08 01:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  [ Sven Joachim ]",
                            "  * Make doc symlinks relative on upgrade from 1:10.3p1-5 (closes:",
                            "    #1141420).",
                            "",
                            "  [ Colin Watson ]",
                            "  * New upstream release:",
                            "    - CVE-2026-59995: sftp(1): when downloading files on the command-line",
                            "      using \"sftp host:/path .\", a malicious server could cause the file to",
                            "      be downloaded to an unexpected location. This issue was identified by",
                            "      the Swival Security Scanner.",
                            "    - CVE-2026-59996: scp(1): when copying files between two remote",
                            "      destinations, do not allow a malicious server to write files to the",
                            "      parent directory of the intended target directory. This issue was",
                            "      identified by the Swival Security Scanner.",
                            "    - CVE-2026-59997: sshd(8): when using the \"internal-sftp\" SFTP server",
                            "      implementation (this is not the default), long command lines were",
                            "      previously truncated silently after the 9th argument. If a",
                            "      security-relevant option was in the 10th or later position, it would",
                            "      be discarded. Reported by Steve Caffrey.",
                            "    - CVE-2026-59998: sshd(8): add a documentation note to mention that the",
                            "      GSSAPIStrictAcceptorCheck option is ineffective when the server is",
                            "      joined to a Windows Active Directory. Reported by Yarin Aharoni of",
                            "      Safebreach.",
                            "    - CVE-2026-59999: sshd(8): DisableForwarding=yes didn't override",
                            "      PermitTunnel=yes as it was documented to do. Note that PermitTunnel is",
                            "      not enabled by default. Reported independently by Huzaifa Sidhpurwala",
                            "      of Redhat and Marko Jevtic.",
                            "    - CVE-2026-60000: sshd(8): avoid a potential pre-authentication denial",
                            "      of service when GSSAPIAuthentication was enabled (this feature is off",
                            "      by default). This was not mitigated by MaxAuthTries, but would be",
                            "      penalised by PerSourcePenalties. This was reported by Manfred Kaiser",
                            "      of the milCERT AT (Austrian Ministry of Defence).",
                            "    - CVE-2026-60001: sshd(8): fix a number of cases where the minimum",
                            "      authentication delay was not being enforced. Reported by the Orange",
                            "      Cyberdefense Vulnerability Team.",
                            "    - CVE-2026-60002: ssh(1): fix a possible client-side use-after-free if",
                            "      the server changes its host key during a key reexchange. This was",
                            "      reported by Zhenpeng (Leo) Lin of Depthfirst.",
                            "    - All: add experimental support for a composite post-quantum signature",
                            "      scheme that combines ML-DSA 44 and Ed25519 as specified in",
                            "      draft-miller-sshm-mldsa44-ed25519-composite-sigs. This scheme is not",
                            "      enabled by default. To use it, you'll need to add it to",
                            "      HostKeyAlgorithms, PubkeyAcceptedAlgorithms, etc. Keys may be",
                            "      generated using \"ssh-keygen -t mldsa44-ed25519\".",
                            "    - ssh(1), sshd(8): replace the wildcard pattern matcher with an",
                            "      implementation based on an NFA. This avoids exponential worst-case",
                            "      behaviour for the old implementation.",
                            "    - ssh-agent(1): fix incorrect reply to \"query\" SSH_AGENTC_EXTENSION",
                            "      requests.",
                            "    - sshd(8): avoid sending observably different messages for valid vs",
                            "      invalid users in GSSAPIAuthentication (disabled by default).",
                            "    - ssh(1), sshd(8): fix several bugs that incorrectly classified bulk",
                            "      traffic as interactive.",
                            "    - ssh-keygen(1), ssh-add(1): skip unsupported key types when downloading",
                            "      resident keys from a FIDO token. Previously, downloads would abort",
                            "      when one was encountered.",
                            "    - ssh(1): fix a potential use-after-free on an error path if",
                            "      cipher_init() fails.",
                            "    - sshd(8): perform stricter encoding and validation of transport state",
                            "      passed between sshd privilege separation subprocesses. This somewhat",
                            "      further hardens the server against attacks on sshd-auth or",
                            "      sshd-session subprocesses.",
                            "    - ssh-agent(1): avoid possible runtime denial of service by enforcing",
                            "      some limits on the length of usernames in key use constraints.",
                            "    - sftp(1): fix two separate one-byte out-of-bounds reads, in",
                            "      SSH2_FXP_REALPATH and batch command processing.",
                            "    - sftp-server(8): disallow use of the copy-data extension to read and",
                            "      write to the same inode simultaneously.",
                            "    - ssh(1), sshd(8): avoid strlen(NULL) crash if an X11 channel was",
                            "      created before the x11-req SSH_MSG_CHANNEL_REQUEST was sent.",
                            "    - sftp(1), scp(1): avoid a situation where sftp_download() could get",
                            "      stuck in a loop if a broken server repeatedly returned zero length",
                            "      while reading a file.",
                            "    - ssh(1): avoid leaking DNS0x20 case-randomised names into names",
                            "      canonicalised using CanonicalizePermittedCNAMEs.",
                            "    - sftp-server(8): avoid truncation of pathnames passed to lstat() during",
                            "      SSH_FXP_REALPATH handling on systems where PATH_MAX is not the actual",
                            "      max.",
                            "    - ssh(1), sshd(8): correct arming of poll(2) event masks for some",
                            "      socket-type channels.",
                            "    - sshd(8): major refactor of sshd_config parsing and management code, to",
                            "      allow for more exact serialisation/deserialisation across privilege",
                            "      separation boundaries.",
                            "    - ssh-add(1): open connection to the agent only after getopt()",
                            "      processing has completed, to give options like \"-v\" a chance to",
                            "      display debug information about this operation.",
                            "    - sshd(8): differentiate between execution failures and a subsystem that",
                            "      was not found when logging why a subsystem failed to start.",
                            "    - All: use safer idioms for timegm(3) and mktime(3) error detection.",
                            "    - ssh(1), sshd(8): avoid accepting invalid cipher or MAC lists in config",
                            "      files or command-line arguments. This could cause runtime failures",
                            "      later.",
                            "    - ssh(1): fix NULL deref crash during pubkey auth when using a PEM style",
                            "      private key with no corresponding .pub key adjacent to it (closes:",
                            "      #1134814).",
                            "    - sshd(8): don't print an error message when trying to load a host",
                            "      private key when PKCS#11 keys are in use, as these don't need the",
                            "      private half on the filesystem.",
                            "    - All: don't use deprecated ERR_load_crypto_strings().",
                            "    - ssh(1): properly report errors during configuration default setting.",
                            "    - ssh(1): use correct directive name (Match instead of Host) in error",
                            "      message.",
                            "    - sftp(1): fix \"ls -ln\" which was not correctly showing numeric UID/GIDs",
                            "      but rather user and group names.",
                            "    - sshd(8): avoid possible NULL dereference if an allocation fails during",
                            "      config parsing.",
                            "    - All: fix ineffective guards against loading overly large public keys",
                            "      in several places.",
                            "    - sftp(1): ensure file descriptors used by sftp to communicate to its",
                            "      ssh(1) subprocess don't leak into executed subprocesses (e.g. via",
                            "      \"!\").",
                            "    - Sync fmt_scaled.c with OpenBSD upstream, picking up an exactness fix",
                            "      for large exponents.",
                            "    - sshd(8): remove duplicate sandbox entry for clock_gettime64.",
                            "    - Sync getrrsetbyname.c with OpenBSD upstream, picking up robustness",
                            "      fixes.",
                            "    - Fix a number of memory leaks on error paths in the portability code.",
                            "    - Revise the README.privsep documentation to reflect sshd's recent",
                            "      switch to a multi-binary model.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.4p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 19:11:28 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * openssh-client Conflicts: openssh-server (<< 1:10.3p1-6~) (closes:",
                            "    #1141550).",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-9",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 09:51:32 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/copyright: Add some missing authors.",
                            "  * Standards-Version: 4.7.4.",
                            "  * openssh-tests: Make a couple more scripts executable.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-8",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 03 Jul 2026 16:54:01 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Reupload with binaries, since openssh-common is new.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-7",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 03 Jul 2026 00:32:52 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Move documentation to a new openssh-common package (closes: #1070098).",
                            "  * Remove dependency on openssh-client{,-gssapi} from",
                            "    openssh-server{,-gssapi} (closes: #699473).",
                            "  * Use --link-doc on all packages.",
                            "  * Move ssh-keygen and openssh-{pkcs11,sk}-helper to openssh-common.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-6",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Thu, 02 Jul 2026 20:24:29 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Johannes Schauer Marin Rodrigues ]",
                            "  * Support DPKG_ROOT.",
                            "",
                            "  [ Colin Watson ]",
                            "  * d/copyright: Significantly rework to be lrc-clean.",
                            "",
                            "  [ Roland C. Dowdeswell ]",
                            "  * Fix GSS C25519 server blob bounds check.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.3p1-5",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Fri, 26 Jun 2026 16:16:18 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "perl",
                "from_version": {
                    "source_package_name": "perl",
                    "source_package_version": "5.40.1-8ubuntu1",
                    "version": "5.40.1-8ubuntu1"
                },
                "to_version": {
                    "source_package_name": "perl",
                    "source_package_version": "5.42.3-1",
                    "version": "5.42.3-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-7017",
                        "url": "https://ubuntu.com/security/CVE-2026-7017",
                        "cve_description": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-9538",
                        "url": "https://ubuntu.com/security/CVE-2026-9538",
                        "cve_description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42496",
                        "url": "https://ubuntu.com/security/CVE-2026-42496",
                        "cve_description": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42497",
                        "url": "https://ubuntu.com/security/CVE-2026-42497",
                        "cve_description": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-12087",
                        "url": "https://ubuntu.com/security/CVE-2026-12087",
                        "cve_description": "Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-15 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-13221",
                        "url": "https://ubuntu.com/security/CVE-2026-13221",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15649",
                        "url": "https://ubuntu.com/security/CVE-2025-15649",
                        "cve_description": "IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-7010",
                        "url": "https://ubuntu.com/security/CVE-2026-7010",
                        "cve_description": "HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 22:22:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-8376",
                        "url": "https://ubuntu.com/security/CVE-2026-8376",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 00:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48959",
                        "url": "https://ubuntu.com/security/CVE-2026-48959",
                        "cve_description": "IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48961",
                        "url": "https://ubuntu.com/security/CVE-2026-48961",
                        "cve_description": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48962",
                        "url": "https://ubuntu.com/security/CVE-2026-48962",
                        "cve_description": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-57432",
                        "url": "https://ubuntu.com/security/CVE-2026-57432",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-57433",
                        "url": "https://ubuntu.com/security/CVE-2026-57433",
                        "cve_description": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-7017",
                                "url": "https://ubuntu.com/security/CVE-2026-7017",
                                "cve_description": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-9538",
                                "url": "https://ubuntu.com/security/CVE-2026-9538",
                                "cve_description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42496",
                                "url": "https://ubuntu.com/security/CVE-2026-42496",
                                "cve_description": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42497",
                                "url": "https://ubuntu.com/security/CVE-2026-42497",
                                "cve_description": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-12087",
                                "url": "https://ubuntu.com/security/CVE-2026-12087",
                                "cve_description": "Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-15 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-13221",
                                "url": "https://ubuntu.com/security/CVE-2026-13221",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.3.",
                            "  * [SECURITY] includes various upstream fixes:",
                            "    + CVE-2026-7017: HTTP::Tiny credential forwarding on redirects.",
                            "        (Closes: #1141639)",
                            "    + CVE-2026-9538: Archive::Tar memory exhaustion.",
                            "        (Closes: #1138861)",
                            "    + CVE-2026-42496: Archive::Tar symlink extraction.",
                            "        (Closes: #1138860)",
                            "    + CVE-2026-42497: Archive::Tar hardlink extraction.",
                            "        (Closes: #1138859)",
                            "    + CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read.",
                            "        (Closes: #1140152)",
                            "    + CVE-2026-13221: silently incorrect regular expression matches.",
                            "        (Closes: #1142037)",
                            "  * Refresh cross support files for all architectures.",
                            "    + also update the architecture lists in d/cross/README",
                            "  * Disable salsa-ci.yml as nobody currently cares about the results.",
                            "  * Update debian/copyright based on DFSG team review.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Mon, 17 Aug 2026 22:59:18 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add 5.42.2 to debian/released-versions.",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Wed, 22 Jul 2026 22:26:36 +0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2025-15649",
                                "url": "https://ubuntu.com/security/CVE-2025-15649",
                                "cve_description": "IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-7010",
                                "url": "https://ubuntu.com/security/CVE-2026-7010",
                                "cve_description": "HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 22:22:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-8376",
                                "url": "https://ubuntu.com/security/CVE-2026-8376",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 00:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48959",
                                "url": "https://ubuntu.com/security/CVE-2026-48959",
                                "cve_description": "IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48961",
                                "url": "https://ubuntu.com/security/CVE-2026-48961",
                                "cve_description": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48962",
                                "url": "https://ubuntu.com/security/CVE-2026-48962",
                                "cve_description": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-57432",
                                "url": "https://ubuntu.com/security/CVE-2026-57432",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-57433",
                                "url": "https://ubuntu.com/security/CVE-2026-57433",
                                "cve_description": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * [SECURITY] backport various fixes from upstream:",
                            "    + CVE-2025-15649: header parsing in IO::Uncompress::Unzip.",
                            "        (Closes: #1138863)",
                            "    + CVE-2026-7010:  CRLF-validation in HTTP::Tiny.",
                            "        (Closes: #1138858)",
                            "    + CVE-2026-8376:  Buffer overflow in Perl_study_chunk.",
                            "        (Closes: #1137345)",
                            "    + CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip.",
                            "        (Closes: #1138856)",
                            "    + CVE-2026-48961: crash in zipdetails.",
                            "        (Closes: #1138855)",
                            "    + CVE-2026-48962: code execution in IO-Compress via output globs.",
                            "        (Closes: #1138854)",
                            "    + CVE-2026-57432: out of bound heap reads in pack() and unpack().",
                            "        (Closes: #1138905)",
                            "    + CVE-2026-57433: signed integer overflow in Storable.",
                            "        (Closes: #1138906)",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sat, 06 Jun 2026 18:02:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.2.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Fri, 24 Apr 2026 22:39:00 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Helmut Grohne ]",
                            "  * Add libcrypt-dev to libperl-dev's Depends. (Closes: #1102978)",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Mon, 17 Nov 2025 21:03:18 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Reinstate Provides: libtest2-suite-perl. (See #1080359)",
                            "  * Refresh cross build support files for most architectures.",
                            "  * Update lintian overrides for 5.42.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sun, 24 Aug 2025 11:55:37 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.0.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sat, 16 Aug 2025 18:44:35 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "perl-base",
                "from_version": {
                    "source_package_name": "perl",
                    "source_package_version": "5.40.1-8ubuntu1",
                    "version": "5.40.1-8ubuntu1"
                },
                "to_version": {
                    "source_package_name": "perl",
                    "source_package_version": "5.42.3-1",
                    "version": "5.42.3-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-7017",
                        "url": "https://ubuntu.com/security/CVE-2026-7017",
                        "cve_description": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-9538",
                        "url": "https://ubuntu.com/security/CVE-2026-9538",
                        "cve_description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42496",
                        "url": "https://ubuntu.com/security/CVE-2026-42496",
                        "cve_description": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42497",
                        "url": "https://ubuntu.com/security/CVE-2026-42497",
                        "cve_description": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-12087",
                        "url": "https://ubuntu.com/security/CVE-2026-12087",
                        "cve_description": "Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-15 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-13221",
                        "url": "https://ubuntu.com/security/CVE-2026-13221",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15649",
                        "url": "https://ubuntu.com/security/CVE-2025-15649",
                        "cve_description": "IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-7010",
                        "url": "https://ubuntu.com/security/CVE-2026-7010",
                        "cve_description": "HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 22:22:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-8376",
                        "url": "https://ubuntu.com/security/CVE-2026-8376",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 00:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48959",
                        "url": "https://ubuntu.com/security/CVE-2026-48959",
                        "cve_description": "IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48961",
                        "url": "https://ubuntu.com/security/CVE-2026-48961",
                        "cve_description": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48962",
                        "url": "https://ubuntu.com/security/CVE-2026-48962",
                        "cve_description": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-57432",
                        "url": "https://ubuntu.com/security/CVE-2026-57432",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-57433",
                        "url": "https://ubuntu.com/security/CVE-2026-57433",
                        "cve_description": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-7017",
                                "url": "https://ubuntu.com/security/CVE-2026-7017",
                                "cve_description": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-9538",
                                "url": "https://ubuntu.com/security/CVE-2026-9538",
                                "cve_description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42496",
                                "url": "https://ubuntu.com/security/CVE-2026-42496",
                                "cve_description": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42497",
                                "url": "https://ubuntu.com/security/CVE-2026-42497",
                                "cve_description": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-12087",
                                "url": "https://ubuntu.com/security/CVE-2026-12087",
                                "cve_description": "Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-15 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-13221",
                                "url": "https://ubuntu.com/security/CVE-2026-13221",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.3.",
                            "  * [SECURITY] includes various upstream fixes:",
                            "    + CVE-2026-7017: HTTP::Tiny credential forwarding on redirects.",
                            "        (Closes: #1141639)",
                            "    + CVE-2026-9538: Archive::Tar memory exhaustion.",
                            "        (Closes: #1138861)",
                            "    + CVE-2026-42496: Archive::Tar symlink extraction.",
                            "        (Closes: #1138860)",
                            "    + CVE-2026-42497: Archive::Tar hardlink extraction.",
                            "        (Closes: #1138859)",
                            "    + CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read.",
                            "        (Closes: #1140152)",
                            "    + CVE-2026-13221: silently incorrect regular expression matches.",
                            "        (Closes: #1142037)",
                            "  * Refresh cross support files for all architectures.",
                            "    + also update the architecture lists in d/cross/README",
                            "  * Disable salsa-ci.yml as nobody currently cares about the results.",
                            "  * Update debian/copyright based on DFSG team review.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Mon, 17 Aug 2026 22:59:18 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add 5.42.2 to debian/released-versions.",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Wed, 22 Jul 2026 22:26:36 +0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2025-15649",
                                "url": "https://ubuntu.com/security/CVE-2025-15649",
                                "cve_description": "IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-7010",
                                "url": "https://ubuntu.com/security/CVE-2026-7010",
                                "cve_description": "HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 22:22:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-8376",
                                "url": "https://ubuntu.com/security/CVE-2026-8376",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 00:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48959",
                                "url": "https://ubuntu.com/security/CVE-2026-48959",
                                "cve_description": "IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48961",
                                "url": "https://ubuntu.com/security/CVE-2026-48961",
                                "cve_description": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48962",
                                "url": "https://ubuntu.com/security/CVE-2026-48962",
                                "cve_description": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-57432",
                                "url": "https://ubuntu.com/security/CVE-2026-57432",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-57433",
                                "url": "https://ubuntu.com/security/CVE-2026-57433",
                                "cve_description": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * [SECURITY] backport various fixes from upstream:",
                            "    + CVE-2025-15649: header parsing in IO::Uncompress::Unzip.",
                            "        (Closes: #1138863)",
                            "    + CVE-2026-7010:  CRLF-validation in HTTP::Tiny.",
                            "        (Closes: #1138858)",
                            "    + CVE-2026-8376:  Buffer overflow in Perl_study_chunk.",
                            "        (Closes: #1137345)",
                            "    + CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip.",
                            "        (Closes: #1138856)",
                            "    + CVE-2026-48961: crash in zipdetails.",
                            "        (Closes: #1138855)",
                            "    + CVE-2026-48962: code execution in IO-Compress via output globs.",
                            "        (Closes: #1138854)",
                            "    + CVE-2026-57432: out of bound heap reads in pack() and unpack().",
                            "        (Closes: #1138905)",
                            "    + CVE-2026-57433: signed integer overflow in Storable.",
                            "        (Closes: #1138906)",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sat, 06 Jun 2026 18:02:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.2.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Fri, 24 Apr 2026 22:39:00 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Helmut Grohne ]",
                            "  * Add libcrypt-dev to libperl-dev's Depends. (Closes: #1102978)",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Mon, 17 Nov 2025 21:03:18 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Reinstate Provides: libtest2-suite-perl. (See #1080359)",
                            "  * Refresh cross build support files for most architectures.",
                            "  * Update lintian overrides for 5.42.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sun, 24 Aug 2025 11:55:37 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.0.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sat, 16 Aug 2025 18:44:35 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "pnp.ids",
                "from_version": {
                    "source_package_name": "hwdata",
                    "source_package_version": "0.394-1build1",
                    "version": "0.394-1build1"
                },
                "to_version": {
                    "source_package_name": "hwdata",
                    "source_package_version": "0.411-1",
                    "version": "0.411-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * CI: update/simplify configuration.",
                            "  * Bump Standards-Version to 4.7.4, no changes required.",
                            "  * Drop Rules-Requires-Root: no, no more needed since Debian trixie.",
                            "  * Drop Priority: optional, no more needed since dpkg 1.22.13.",
                            "  * Covert watch file to v5.",
                            ""
                        ],
                        "package": "hwdata",
                        "version": "0.411-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Pino Toscano <pino@debian.org>",
                        "date": "Mon, 07 Sep 2026 06:28:58 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "polkitd",
                "from_version": {
                    "source_package_name": "policykit-1",
                    "source_package_version": "127-3",
                    "version": "127-3"
                },
                "to_version": {
                    "source_package_name": "policykit-1",
                    "source_package_version": "127-3ubuntu1",
                    "version": "127-3ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-85498",
                        "url": "https://ubuntu.com/security/CVE-2026-85498",
                        "cve_description": "[Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow]",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-07"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-85498",
                                "url": "https://ubuntu.com/security/CVE-2026-85498",
                                "cve_description": "[Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow]",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-07"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: stack underflow in cookie input",
                            "    - debian/patches/CVE-2026-85498.patch: Unsanitized underflow in cookie",
                            "      input in src/polkitagent/polkitagenthelperprivate.c.",
                            "    - CVE-2026-85498",
                            ""
                        ],
                        "package": "policykit-1",
                        "version": "127-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Fri, 11 Sep 2026 13:29:14 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3",
                "from_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.3-0ubuntu2",
                    "version": "3.14.3-0ubuntu2"
                },
                "to_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.7-3",
                    "version": "3.14.7-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Remove a missed Python 3.13 dependency.",
                            "  * Update README.Debian.",
                            "",
                            "  [ Simon McVittie ]",
                            "  * policy: Expand the section about package names. (Closes: #791635)",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Thu, 27 Aug 2026 11:09:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Bump to version 3.14.7.",
                            "  * Remove Python 3.13 as a supported version.",
                            "  * Remove references to IronPython and Jython in the package descriptions.",
                            "  * Bump standards version.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 26 Aug 2026 16:45:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            "  * Bump to version 3.14.6.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Sat, 27 Jun 2026 09:14:35 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-cffi-backend",
                "from_version": {
                    "source_package_name": "python-cffi",
                    "source_package_version": "2.0.0-3build1",
                    "version": "2.0.0-3build1"
                },
                "to_version": {
                    "source_package_name": "python-cffi",
                    "source_package_version": "2.1.1-1",
                    "version": "2.1.1-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team Upload",
                            "  * New upstream version 2.1.1",
                            "  * Drop build-dep on python3-py (Closes: #1121670)",
                            "  * Refresh bundled-wheel-and-setuptools.patch",
                            "  * Drop pycparser-3.patch: applied upstream",
                            "  * Add debian/salsa-ci.yml",
                            "  * Bump Standards-Version to 4.7.4, drop Priority: tag",
                            "  * Drop duplicate dependency on dh-python",
                            ""
                        ],
                        "package": "python-cffi",
                        "version": "2.1.1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Mon, 17 Aug 2026 14:07:44 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-cryptography",
                "from_version": {
                    "source_package_name": "python-cryptography",
                    "source_package_version": "46.0.5-1ubuntu2",
                    "version": "46.0.5-1ubuntu2"
                },
                "to_version": {
                    "source_package_name": "python-cryptography",
                    "source_package_version": "49.0.0-2ubuntu1",
                    "version": "49.0.0-2ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-34073",
                        "url": "https://ubuntu.com/security/CVE-2026-34073",
                        "cve_description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the \"peer name\" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-31 03:15:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-69247",
                        "url": "https://ubuntu.com/security/CVE-2026-69247",
                        "cve_description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-03 22:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2164143,
                    2155078
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-34073",
                                "url": "https://ubuntu.com/security/CVE-2026-34073",
                                "cve_description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the \"peer name\" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-31 03:15:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2164143). Remaining changes:",
                            "    - Vendor rust for Ubuntu main",
                            "      - Adjust dependencies version for vendored build",
                            "      - Add a recipe in d/rules to generate the vendor tarball",
                            "      - Add vendored crates",
                            "      - Add debian/README.source",
                            "    * Drop patches, merged upstream",
                            "      - d/p/CVE-2026-34073.patch",
                            "      - d/p/CVE-2026-34073.patch",
                            "  * Fixes FTBFS with OpenSSL 4 (LP: #2155078)",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "49.0.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164143,
                            2155078
                        ],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Tue, 18 Aug 2026 19:30:20 +0000"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-69247",
                                "url": "https://ubuntu.com/security/CVE-2026-69247",
                                "cve_description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-03 22:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Backport the upstream fix for CVE-2026-69247 (Closes: #1143596).",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "49.0.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Wed, 05 Aug 2026 01:32:33 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "49.0.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Wed, 15 Jul 2026 14:39:03 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to experimental.",
                            "  * New upstream version.",
                            "  * Support building against pyo3 0.29.",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "49.0.0-1~exp1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Wed, 24 Jun 2026 00:27:00 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "    + Fix building with OpenSSL 4 (Closes: #1139232).",
                            "  * Add overlooked B-D: librust-base64-0.22-dev.",
                            "  * Update B-D from librust-asn1-0.23-dev to librust-asn1-0.24-dev.",
                            "  * Switch to debhelper compat level 14.",
                            "  * Add X-Style: black and reformat.",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "47.0.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Wed, 24 Jun 2026 00:01:10 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Bump Standards-Version to 4.7.4.",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "46.0.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Thu, 09 Apr 2026 12:18:03 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "46.0.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Fri, 27 Mar 2026 10:49:47 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Support building against pyo3 0.28.",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "46.0.5-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Jelmer Vernooĳ <jelmer@debian.org>",
                        "date": "Tue, 17 Mar 2026 11:38:26 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * No-change rebuild against libssl4",
                            ""
                        ],
                        "package": "python-cryptography",
                        "version": "46.0.5-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Ravi Kant Sharma <ravi.kant.sharma@canonical.com>",
                        "date": "Thu, 23 Jul 2026 16:01:32 +0000"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-gdbm",
                "from_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.3-0ubuntu2",
                    "version": "3.14.3-0ubuntu2"
                },
                "to_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.7-3",
                    "version": "3.14.7-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Remove a missed Python 3.13 dependency.",
                            "  * Update README.Debian.",
                            "",
                            "  [ Simon McVittie ]",
                            "  * policy: Expand the section about package names. (Closes: #791635)",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Thu, 27 Aug 2026 11:09:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Bump to version 3.14.7.",
                            "  * Remove Python 3.13 as a supported version.",
                            "  * Remove references to IronPython and Jython in the package descriptions.",
                            "  * Bump standards version.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 26 Aug 2026 16:45:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            "  * Bump to version 3.14.6.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Sat, 27 Jun 2026 09:14:35 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-markdown-it",
                "from_version": {
                    "source_package_name": "markdown-it-py",
                    "source_package_version": "3.0.0-3build1",
                    "version": "3.0.0-3build1"
                },
                "to_version": {
                    "source_package_name": "markdown-it-py",
                    "source_package_version": "4.2.0-3",
                    "version": "4.2.0-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team Upload",
                            "  * Remove redundant \"flit\" relation in debian/control.",
                            "  * Salsa: test the <!nocheck> profile",
                            "  * Mark python3-attr & python3-mdurl as <!nocheck>",
                            "  * Drop unused python3-sphinx build-dep",
                            "  * Use dh-sequence-python3",
                            ""
                        ],
                        "package": "markdown-it-py",
                        "version": "4.2.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Sun, 28 Jun 2026 00:07:59 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add manpage for binary package (Closes: #1104584).",
                            ""
                        ],
                        "package": "markdown-it-py",
                        "version": "4.2.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Emmanuel Arias <eamanu@debian.org>",
                        "date": "Wed, 13 May 2026 16:51:57 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            "  * Update watch file format version to 5.",
                            "  * Use GitHub template in watch file instead of explicit",
                            "    Source/Matching-Pattern.",
                            "  * debputy lint --auto-fix (routine-update)",
                            "  * d/control: Add Breaks for python3-myst-parser (<< 5.0.0-2).",
                            ""
                        ],
                        "package": "markdown-it-py",
                        "version": "4.2.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Emmanuel Arias <eamanu@debian.org>",
                        "date": "Wed, 13 May 2026 13:06:27 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version",
                            "  * Standards-Version: 4.7.4",
                            "  * Reorder sequence of d/control fields by cme (routine-update)",
                            "  * Set upstream metadata fields: Documentation, Security-Contact.",
                            "  * d/control: Drop \"Rules-Requires-Root: no\" it is default now.",
                            "  * d/control: Add Multi-Arch: foreign to binary package.",
                            "  * d/rules: Skip test_markdown_it_pyrs test. See #1118258.",
                            "    - Also skip in autopkgtests.",
                            "  * d/control: Update my contact information.",
                            "  * d/control: Remove Priority: optional. It's no longer needed.",
                            ""
                        ],
                        "package": "markdown-it-py",
                        "version": "4.0.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Emmanuel Arias <eamanu@debian.org>",
                        "date": "Sun, 26 Apr 2026 17:41:41 -0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-minimal",
                "from_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.3-0ubuntu2",
                    "version": "3.14.3-0ubuntu2"
                },
                "to_version": {
                    "source_package_name": "python3-defaults",
                    "source_package_version": "3.14.7-3",
                    "version": "3.14.7-3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Remove a missed Python 3.13 dependency.",
                            "  * Update README.Debian.",
                            "",
                            "  [ Simon McVittie ]",
                            "  * policy: Expand the section about package names. (Closes: #791635)",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Thu, 27 Aug 2026 11:09:35 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Bump to version 3.14.7.",
                            "  * Remove Python 3.13 as a supported version.",
                            "  * Remove references to IronPython and Jython in the package descriptions.",
                            "  * Bump standards version.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Wed, 26 Aug 2026 16:45:39 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            "  * Bump to version 3.14.6.",
                            ""
                        ],
                        "package": "python3-defaults",
                        "version": "3.14.6-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Stefano Rivera <stefanor@debian.org>",
                        "date": "Sat, 27 Jun 2026 09:14:35 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-openssl",
                "from_version": {
                    "source_package_name": "pyopenssl",
                    "source_package_version": "25.3.0-1ubuntu1",
                    "version": "25.3.0-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "pyopenssl",
                    "source_package_version": "26.4.0-1",
                    "version": "26.4.0-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Update the supported python3-cryptography versions.",
                            ""
                        ],
                        "package": "pyopenssl",
                        "version": "26.4.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Mon, 03 Aug 2026 12:01:10 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "pyopenssl",
                        "version": "26.3.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Wed, 15 Jul 2026 14:46:52 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to experimental.",
                            "  * New upstream version.",
                            "  * Update the supported python3-cryptography versions.",
                            "  * Switch to the debhelper compat level 14.",
                            "  * Add X-Style: black and reformat.",
                            ""
                        ],
                        "package": "pyopenssl",
                        "version": "26.3.0-1~exp1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Thu, 25 Jun 2026 22:49:56 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "pyopenssl",
                        "version": "26.2.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Fri, 05 Jun 2026 23:50:49 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Upload to experimental.",
                            "  * Update the maximum supported python3-cryptography version.",
                            ""
                        ],
                        "package": "pyopenssl",
                        "version": "26.2.0-1~exp1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Wed, 06 May 2026 00:15:09 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            "  * Bump Standards-Version to 4.7.4.",
                            "  * Add Build-Profiles: <!nodoc> to the doc subpackage.",
                            "  * Update the maximum supported python3-cryptography version.",
                            "  * Remove the obsolete Python 3 mention from the description.",
                            "  * Remove an obsolete conditional dependency.",
                            ""
                        ],
                        "package": "pyopenssl",
                        "version": "26.1.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Sat, 25 Apr 2026 22:03:15 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream version.",
                            ""
                        ],
                        "package": "pyopenssl",
                        "version": "26.0.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Tue, 17 Mar 2026 22:58:07 +0500"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Skip test_client_receives_servers_data that fails with openssl 3.6, patch",
                            "    from Sebastian Andrzej Siewior (Closes: #1130440).",
                            "  * Bump Standards-Version to 4.7.3.",
                            "  * Add Multi-Arch: foreign to python-openssl-doc.",
                            ""
                        ],
                        "package": "pyopenssl",
                        "version": "25.3.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Andrey Rakhmatullin <wrar@debian.org>",
                        "date": "Fri, 13 Mar 2026 12:29:22 +0500"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-service-identity",
                "from_version": {
                    "source_package_name": "python-service-identity",
                    "source_package_version": "24.2.0-2",
                    "version": "24.2.0-2"
                },
                "to_version": {
                    "source_package_name": "python-service-identity",
                    "source_package_version": "26.1.0-2",
                    "version": "26.1.0-2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Drop unused python3-sphinx build-dependency",
                            ""
                        ],
                        "package": "python-service-identity",
                        "version": "26.1.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Wed, 22 Jul 2026 23:27:02 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "python-service-identity",
                        "version": "26.1.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 29 Jun 2026 11:43:32 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-typing-extensions",
                "from_version": {
                    "source_package_name": "python-typing-extensions",
                    "source_package_version": "4.15.0-2",
                    "version": "4.15.0-2"
                },
                "to_version": {
                    "source_package_name": "python-typing-extensions",
                    "source_package_version": "4.16.0-4",
                    "version": "4.16.0-4"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Salsa CI: test nocheck & nodoc profiles",
                            "  * Implement nocheck & nodoc profiles",
                            ""
                        ],
                        "package": "python-typing-extensions",
                        "version": "4.16.0-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Alexandre Detiste <tchet@debian.org>",
                        "date": "Tue, 21 Jul 2026 17:49:13 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Mark python-typing-extensions-doc Multi-Arch: foreign.",
                            ""
                        ],
                        "package": "python-typing-extensions",
                        "version": "4.16.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Wed, 15 Jul 2026 15:39:21 +0100"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Team upload.",
                            "  * Build documentation using sphinx and ship in separate binary package.",
                            "  * Add patch to use local objects.inv in intersphinx mapping.",
                            "  * Use dh-sequence-python3.",
                            "  * Drop optional Priority field.",
                            "  * Set debhelper compatibility to 14.",
                            "  * Bump Standards-Version to 4.7.4.",
                            "  * Set X-Style: black and reformat.",
                            "  * Drop python3-setuptools from Build-Depends, it is not used.",
                            "  * Run tests using pytest.",
                            "  * Switch Testsuite to autopkgtest-pkg-pybuild.",
                            ""
                        ],
                        "package": "python-typing-extensions",
                        "version": "4.16.0-2",
                        "urgency": "low",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Michael Fladischer <fladi@debian.org>",
                        "date": "Tue, 07 Jul 2026 09:57:37 +0000"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Michael Fladischer ]",
                            "  * Use uscan version 5 GitHub template to have the documentation source",
                            "    included in the tarball.",
                            "",
                            "  [ Colin Watson ]",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "python-typing-extensions",
                        "version": "4.16.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 06 Jul 2026 09:31:06 +0100"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3.14",
                "from_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.6-1",
                    "version": "3.14.6-1"
                },
                "to_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.7-4ubuntu1",
                    "version": "3.14.7-4ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert the module-install-* autopkg tests to run with setuptools v78.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:51:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-13.",
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Re-enable the module-install-* autopkgtests, updated for setuptools 80.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:30:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-05.",
                            "  * Disable the module-install-* autopkg tests for now.",
                            "  * Update symbols file.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sat, 05 Sep 2026 07:55:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-01.",
                            "    - Reworks the test_typing stack test. Closes: #1146095.",
                            "  * Apply the OpenSSL 4.0 patches from the 3.15 branch. Closes: #1137595.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 11:47:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Python 3.14.7 release.",
                            "  * Drop the the min-pyrepl patch, handled by an upstream backport.",
                            "  * Refresh patches.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 11 Aug 2026 10:48:35 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3.14-gdbm",
                "from_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.6-1",
                    "version": "3.14.6-1"
                },
                "to_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.7-4ubuntu1",
                    "version": "3.14.7-4ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert the module-install-* autopkg tests to run with setuptools v78.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:51:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-13.",
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Re-enable the module-install-* autopkgtests, updated for setuptools 80.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:30:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-05.",
                            "  * Disable the module-install-* autopkg tests for now.",
                            "  * Update symbols file.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sat, 05 Sep 2026 07:55:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-01.",
                            "    - Reworks the test_typing stack test. Closes: #1146095.",
                            "  * Apply the OpenSSL 4.0 patches from the 3.15 branch. Closes: #1137595.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 11:47:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Python 3.14.7 release.",
                            "  * Drop the the min-pyrepl patch, handled by an upstream backport.",
                            "  * Refresh patches.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 11 Aug 2026 10:48:35 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3.14-minimal",
                "from_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.6-1",
                    "version": "3.14.6-1"
                },
                "to_version": {
                    "source_package_name": "python3.14",
                    "source_package_version": "3.14.7-4ubuntu1",
                    "version": "3.14.7-4ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Revert the module-install-* autopkg tests to run with setuptools v78.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:51:37 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-13.",
                            "",
                            "  [ Stefano Rivera ]",
                            "  * Re-enable the module-install-* autopkgtests, updated for setuptools 80.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-4",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sun, 13 Sep 2026 10:30:29 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-05.",
                            "  * Disable the module-install-* autopkg tests for now.",
                            "  * Update symbols file.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Sat, 05 Sep 2026 07:55:41 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to the 3.14 branch 2026-09-01.",
                            "    - Reworks the test_typing stack test. Closes: #1146095.",
                            "  * Apply the OpenSSL 4.0 patches from the 3.15 branch. Closes: #1137595.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 01 Sep 2026 11:47:32 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Python 3.14.7 release.",
                            "  * Drop the the min-pyrepl patch, handled by an upstream backport.",
                            "  * Refresh patches.",
                            ""
                        ],
                        "package": "python3.14",
                        "version": "3.14.7-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Matthias Klose <doko@debian.org>",
                        "date": "Tue, 11 Aug 2026 10:48:35 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "rsyslog",
                "from_version": {
                    "source_package_name": "rsyslog",
                    "source_package_version": "8.2608.0-4ubuntu1",
                    "version": "8.2608.0-4ubuntu1"
                },
                "to_version": {
                    "source_package_name": "rsyslog",
                    "source_package_version": "8.2608.0-4ubuntu3",
                    "version": "8.2608.0-4ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2147513
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/imdtls-dtlsv1-listen-openssl4-errno.patch: add-on fix for the",
                            "    imdtls openssl 4 patch",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2608.0-4ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Sun, 13 Sep 2026 14:36:09 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debian: configure journald with ForwardToSyslog=yes ourselves",
                            "    (LP: #2147513)",
                            ""
                        ],
                        "package": "rsyslog",
                        "version": "8.2608.0-4ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2147513
                        ],
                        "author": "Nick Rosbrook <enr0n@ubuntu.com>",
                        "date": "Tue, 08 Sep 2026 10:15:01 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "rust-coreutils",
                "from_version": {
                    "source_package_name": "rust-coreutils",
                    "source_package_version": "0.10.0-1ubuntu2",
                    "version": "0.10.0-1ubuntu2"
                },
                "to_version": {
                    "source_package_name": "rust-coreutils",
                    "source_package_version": "0.11.0-2ubuntu1",
                    "version": "0.11.0-2ubuntu1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2166225,
                    2152801,
                    2116290,
                    2130465,
                    2165041,
                    2164777,
                    2152801,
                    2164777,
                    2130465
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable. Remaining changes: (LP: #2166225)",
                            "    - Install hardlinks: Rename rust-coreutils.links to",
                            "      rust-coreutils.hardlinks.",
                            "    - Remove Build-Depends on lld and use the default linker because lld is",
                            "      unavailable on some partial architectures such as i386.",
                            "    - d/rules: Add the multiarch library path needed when linking systemd",
                            "      support (LP: #2152801).",
                            "    - d/rules: Use Ubuntu's dh-cargo-vendored-sources helper and skip known",
                            "      failing tests.",
                            "    - d/control: Regenerate XS-Vendored-Sources-Rust for Ubuntu.",
                            "    - d/p/Tweak-release-build-profile.patch: Balance binary size and debug",
                            "      information.",
                            "    - d/p/dd-ensure-full-writes.patch: Handle partial writes to slow pipes.",
                            "    - d/p/rust-vendor/glibc-2.42.patch: Support the glibc 2.42 speed_t change.",
                            "    - d/p/rustix-use-libc-backend.patch: Route rustix syscalls through libc.",
                            "    - d/p/require-utility-to-be-invoked-at-matching-path.patch: Preserve",
                            "      pathname-based AppArmor policy semantics.",
                            "    - d/p/df-statfs-fallback.patch: Retain the direct statfs fallback when",
                            "      mount table paths are inaccessible (LP: #2116290).",
                            "    - d/p/cp-stop-resolving-cwd.patch: Avoid resolving cwd for absolute",
                            "      recursive copies (LP: #2130465).",
                            "    - Remove Debian's fix-ppc64el-baudrate.diff, which fails on Launchpad's",
                            "      ppc64el builders.",
                            "    - Fix Lintian warnings.",
                            "  * Drop Changes:",
                            "    - Install libstdbuf.so: adopted by Debian in 0.11.0-1.",
                            "    - Enable feat_systemd_logind and add libsystemd-dev: adopted by Debian in",
                            "      0.11.0-1; the Ubuntu multiarch linker-path adjustment remains.",
                            "    - d/p/remove-workspace-members.patch: adopted by Debian in 0.11.0-1.",
                            "    - d/p/build-stty.patch: no longer needed by the 0.11 Unix feature set.",
                            "    - d/p/cp-fix-symlink-target-permissions.patch: fixed upstream",
                            "      (LP: #2165041).",
                            "    - d/p/cp-fix-umask-permission-denied.patch: fixed upstream",
                            "      (LP: #2164777).",
                            "    - The 0.10 vendored-crate refresh: superseded by Debian's 0.11 refresh.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.11.0-2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166225,
                            2152801,
                            2116290,
                            2130465,
                            2165041,
                            2164777
                        ],
                        "author": "Varun Varma <varun.varma@canonical.com>",
                        "date": "Mon, 07 Sep 2026 21:33:10 -0400"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Enable the upstream \"feat_diagnostics\" feature: errors are rendered",
                            "    against the argument list with a caret when stderr is a terminal.",
                            "    --no-default-features, so it has to be requested explicitly.",
                            "    https://uutils.org/blog/2026-08-error-diagnostics/",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.11.0-2",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Tue, 01 Sep 2026 22:43:12 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release.",
                            "  * Update the l10n component tarball to 0.11.0.",
                            "  * d/p/fix-locale-path.patch: refreshed. Upstream now installs the shared",
                            "    error locales (src/uucore/locales/errors); install them under",
                            "    /usr/share/coreutils/locales/uucore/errors like the rest.",
                            "  * d/p/use-l10n-translations-in-makefile.patch: refreshed.",
                            "  * Build the checksum utilities against the system OpenSSL: enable the",
                            "    upstream \"openssl\" feature so cksum, md5sum and the sha*sum family use",
                            "    libcrypto instead of the pure-Rust digests, with OPENSSL_NO_VENDOR=1 so",
                            "    openssl-sys links Debian's shared libcrypto rather than building the",
                            "    vendored openssl-src copy. Build-Depends on libssl-dev and pkgconf.",
                            "  * Build with profile-guided optimization on amd64 and arm64: the",
                            "    instrumented binary is built with the package's own build command, then",
                            "    upstream's util/build-pgo.sh runs the training workloads and merges the",
                            "    profile, which the real build consumes through -Cprofile-use.",
                            "    d/p/pgo-use-prebuilt-binary.patch adds the --instrumented-binary option",
                            "    the script needs for that; using its own step 1 instead would train a",
                            "    binary built with a different feature set, whose profile -Cprofile-use",
                            "    then silently ignores. Restricted to those two",
                            "    arches because training has to run the instrumented binary and roughly",
                            "    doubles the build time (s390x already flirts with the buildd timeout,",
                            "    the 32-bit arches OOM). Disable with DEB_BUILD_OPTIONS=nopgo.",
                            "    Build-Depends on llvm [amd64 arm64].",
                            "  * Update the vendored crates.",
                            "  * Drop the Cargo.toml.orig cargo-vendor-filterer leaves in every vendored",
                            "    crate, and delete them in the 'vendor' target from now on: cargo never",
                            "    reads them and lintian reports them as debian-adds-patch-failure-file.",
                            "    Drops the override that used to hide the tag.",
                            "  * Blank the .cargo-checksum.json of every vendored crate, not just the",
                            "    ones matching the old sed: cargo-vendor-filterer now emits a \"$comment\"",
                            "    key, which the line-anchored regexp skipped. Left as it was,",
                            "    minimal-lexical failed to build because its checksum list mentions a",
                            "    .gitmodules that dpkg-source strips from the .debian.tar.",
                            "  * d/p/remove-workspace-members.patch: drop the workspace members array",
                            "    so dh-cargo stops walking the Cargo.toml of every crate in",
                            "    debian/rust-vendor/ (Ubuntu)",
                            "  * Re-enable stdbuf, disabled since 0.0.30-2: set LIBSTDBUF_DIR and",
                            "    ship /usr/libexec/rust-coreutils/libstdbuf.so instead of shipping a",
                            "    stdbuf link to a binary that did not implement it (Ubuntu)",
                            "  * Build with --features feat_systemd_logind so who, users, uptime and",
                            "    pinky read sessions from logind rather than an empty utmp; Build-",
                            "    Depends on libsystemd-dev (Ubuntu, LP: #2152801)",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.11.0-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [
                            2152801
                        ],
                        "author": "Sylvestre Ledru <sylvestre@debian.org>",
                        "date": "Tue, 01 Sep 2026 10:54:51 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Simon Johnsson ]",
                            "  * d/p/cp-fix-umask-permission-denied.patch: Fix an issue where cp would fail",
                            "    with \"Permission denied\" if umask masked the owner's write permission",
                            "    (LP: #2164777).",
                            "",
                            "  [ Varun Varma ]",
                            "  * d/p/cp-stop-resolving-cwd.patch: cp: avoid resolving cwd",
                            "    for absolute recursive copies (LP: #2130465).",
                            "  * Fix Lintian warnings.",
                            ""
                        ],
                        "package": "rust-coreutils",
                        "version": "0.10.0-1ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2164777,
                            2130465
                        ],
                        "author": "Varun Varma <varun.varma@canonical.com>",
                        "date": "Tue, 01 Sep 2026 12:04:54 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "snapd",
                "from_version": {
                    "source_package_name": "snapd",
                    "source_package_version": "2.76.3+ubuntu26.10",
                    "version": "2.76.3+ubuntu26.10"
                },
                "to_version": {
                    "source_package_name": "snapd",
                    "source_package_version": "2.77.1+ubuntu26.10.1",
                    "version": "2.77.1+ubuntu26.10.1"
                },
                "cves": [
                    {
                        "cve": "CVE-2024-5300",
                        "url": "https://ubuntu.com/security/CVE-2024-5300",
                        "cve_description": "An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns \"complete\" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-21 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-3888",
                        "url": "https://ubuntu.com/security/CVE-2026-3888",
                        "cve_description": "Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-03-17 14:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2024-5300",
                        "url": "https://ubuntu.com/security/CVE-2024-5300",
                        "cve_description": "An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns \"complete\" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-21 15:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-3888",
                        "url": "https://ubuntu.com/security/CVE-2026-3888",
                        "cve_description": "Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-03-17 14:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2158102,
                    2072331,
                    2110510,
                    2143934,
                    2160691,
                    2161982,
                    2158301,
                    2159940,
                    2157692,
                    2067006,
                    2157692,
                    2067006,
                    2154498,
                    2147606,
                    2148544,
                    2139213,
                    2125344,
                    2150683,
                    2152908,
                    1966067,
                    2110368,
                    2110368,
                    2144666,
                    2146337,
                    2147207
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2158102",
                            "    - Fix undo of unlink-component after its snap revision was discarded",
                            "    - interfaces: power-control | allow reading all battery state files",
                            "    - fix 26.04+ snapd deb versioning",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.77.1+ubuntu26.10.1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2158102
                        ],
                        "author": "Ernest Lotter <ernest.lotter@canonical.com>",
                        "date": "Wed, 02 Sep 2026 14:39:12 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "    - Account for differences in names of the binaries in the snapd FIPS",
                            "      build",
                            "    - Add code to calculate canonical subject name hash",
                            "    - Add commands for debugging or accessing snap mount namespaces",
                            "    - Add helpers for listing and iterating device mediation groups",
                            "    - Add package ebpf with helpers wrapping eBPF exposed objects with",
                            "      dependency on github.com/cilium/ebpf",
                            "    - Add secondary prerequisites task that acts as the synchronization",
                            "      point, which ensures that a snap's prerequisites are available",
                            "      before it's installed",
                            "    - Add support for shell conditional syntax in envs",
                            "    - Added /usr/share/{man,help,info} to system-packages-doc",
                            "    - asserts: add validation-sets confdb-schema builtin",
                            "    - asserts: ensure that compatibility labels are strings",
                            "    - asserts: extend on-classic constraints to accept \"distro/variant\",",
                            "      \"distro/*\", and \"distro/\" under a new snap-declaration format 7",
                            "    - asserts: validate serial in newDeviceIDFromString",
                            "    - Bump github.com/canonical/go-efilib to v1.8.0 to include fixes for",
                            "      efivars probe",
                            "    - confdb: add validation-sets handler and fix data loss when writing",
                            "      to new schemas or accounts",
                            "    - confdb: fix bug on reading uneven lists",
                            "    - confdb: literal subkeys are sorted after placeholders",
                            "    - confdb: run observe-view-* hooks after commit",
                            "    - confdb: support Encode/Decode for builtins",
                            "    - confdb: support sign-only external keypair backends",
                            "    - core-initrd: add missing libbpf and systemd dlopen dependencies,",
                            "      and increase mount burst",
                            "    - Drop task logs for delayed effects",
                            "    - During snap removal, clear-snap task errors early if there are",
                            "      user mounts in snap data dirs",
                            "    - Enable reverts to trigger a seed refresh",
                            "    - Ensure profiles are setup before running prepare-{slot, plug}*",
                            "      hooks",
                            "    - Ensure that prereqs created by initial refresh run before create-",
                            "      recovery-system",
                            "    - Exclude Georgian from translation linting",
                            "    - experimental features: graduate layouts, classic-preserves-xdg-",
                            "      runtime-dir, refresh-app-awareness, and dbus-activation features",
                            "    - experimental features: warn when setting graduated or default-",
                            "      enabled experimental features and do not store settings for",
                            "      graduated features",
                            "    - Expose individual certs as well as c_rehash emulation",
                            "    - Extend autogen with explicit --sysconfdir",
                            "    - External keypair manager: add shared external key manager",
                            "      implementation",
                            "    - External keypair manager: refactor GPG and external keypair",
                            "      managers to use extKeypairMgrImpl",
                            "    - External keypair manager: support external OPENPGP signing in",
                            "      ExternalKeypairManager",
                            "    - FDE: add post install actions API",
                            "    - FDE: add reprovision API",
                            "    - FDE: add reprovision recovery key generation API",
                            "    - FDE: add reseal check after snapd refresh",
                            "    - FDE: allow reprovision without factory reset",
                            "    - FDE: change makebootable part of the boot package to not take",
                            "      install observers as parameters",
                            "    - FDE: extend storage-encrypted system information",
                            "    - FDE: make reprovision only seal",
                            "    - FDE: remove all tmp keyslots on error",
                            "    - FDE: remove check for unchanged authentication options",
                            "    - FDE: run post install checks during auto repair",
                            "    - Filter seed-refresh based on model and seed presence",
                            "    - Fix failing snap remove when there are snapctl created mounts",
                            "      under snap global data dirs",
                            "    - Fix postNotices to validate before locking state",
                            "    - Guard the ensure check from running on classic",
                            "    - Implement remodeling fully in terms of updates",
                            "    - Implement ShutDown for HookManager",
                            "    - Include variables SNAP_APP_NAME, and when applicable",
                            "      SNAP_APP_COMMON_ID, SNAP_APP_DESKTOP_FILE and SNAP_APP_BUS_NAME in",
                            "      snap application environments",
                            "    - interfaces: add xdg-portal-permission-store interface",
                            "    - interfaces: allow gtk css in subdirectories",
                            "    - interfaces: allow systemd networkd link property changes via D-Bus",
                            "    - interfaces: allow the systemd networkctl command",
                            "    - interfaces: allow Wine to execute files accessed via the Document",
                            "      Portal",
                            "    - interfaces: apparmor-observe | add interface",
                            "    - interfaces: attempt to fix content with parallel installs",
                            "    - interfaces: devlxd | fix access for LXD containers",
                            "    - interfaces: docker | allow connecting to system-wide docker on",
                            "      classic",
                            "    - interfaces: grant default access to memory.high in a snap's cgroup",
                            "    - interfaces: iscsi-initiator | allow access to /var/lib/iscsi/nodes",
                            "    - interfaces: kernel-sched-ext-control | add the kernel sched-ext",
                            "      control interface implementation",
                            "    - interfaces: make polkit and upower implicit on Core systems only",
                            "    - interfaces: open-iscsi | add missing state paths",
                            "    - interfaces: opengl | expose wsl libraries",
                            "    - interfaces: u2f-devices | add atkey PID and relative VID support",
                            "    - List dir contents on failure to remove snap base data dir",
                            "    - List non-snapctl mounts in snap data dirs",
                            "    - LP: #2072331 Validate map keys in JSON config values",
                            "    - LP: #2110510 Interfaces: allow reading of /proc/self/smaps_rollup",
                            "    - LP: #2143934 Interfaces: network-control, network-manager | allow",
                            "      missing resolve1 link setters",
                            "    - LP: #2160691 Security logging: strip trailing whitespace from",
                            "      audit netlink message payload",
                            "    - LP: #2161982 Interfaces: vsock | add interface for VM guest",
                            "      services",
                            "    - Make arguments of debug mount-namespace consistent with other",
                            "      debug commands",
                            "    - Make bootloader logging less verbose",
                            "    - Make cert manager garbage check run after symlink migration",
                            "    - Make secondary prerequisite synchronization task handle same-",
                            "      change retries",
                            "    - mkversion.sh: do describe in worktrees too",
                            "    - multi-entry snapd: merge snap and snapd binaries",
                            "    - multi-entry snapd: move debug device-cgroup implementation file",
                            "      under cmd/snapd/cli",
                            "    - multi-entry snapd: move snap-gpio-helper sources around before",
                            "      transitioning to multi-entry dispatch",
                            "    - multi-entry snapd: move snapd-apparmor sources to a dedicated tool",
                            "      location",
                            "    - multi-entry snapd: move source files around in preparation for",
                            "      snapd/snap merge",
                            "    - multi-entry snapd: move the snap-preseed sources around in",
                            "      preparation",
                            "    - multi-entry snapd: move the sources of snapctl and snap-exec in",
                            "      preparation for the multi-entry dispatch",
                            "    - Never create seed refresh tasks during a remodel",
                            "    - packaging: assign a default label for /tmp/snap-private-tmp and",
                            "      set it during installation",
                            "    - packaging: build deb with Go 1.23 for noble and jammy, Go 1.22 for",
                            "      focal",
                            "    - packaging: drop SNAP_TAGS",
                            "    - packaging: drop symlinks for opensuse 15.5/15.6 packaging",
                            "    - packaging: fix service startup during install and session-agent",
                            "      socket handling on Ubuntu 26.04+",
                            "    - packaging: fix stderr redirection",
                            "    - packaging: restore gbp.conf output directory for Ubuntu 26.04",
                            "      builds",
                            "    - packaging: switch to apparmor 5.x with 5 ABI",
                            "    - packaging: update bundled AppArmor to 5.0.2 and accept the 5.0 ABI",
                            "      when running as deb",
                            "    - packaging: use a relative symlink for snapctl and update steam-",
                            "      support udev rules",
                            "    - Preserve component in hook security tags",
                            "    - Prevent removal of seed-refresh snaps when seed-refresh is enabled",
                            "    - Refactor base-declaration into 1st class builtin assertion",
                            "    - Refactor how the is-originating-from-snap-command advisory check",
                            "      works",
                            "    - Refactor prerequisites task handler to enable proper seed-refresh",
                            "      integration",
                            "    - Reintroduce fdstore helpers",
                            "    - remote device management: add task to validate request messages",
                            "    - remote device management: apply management messages, queue",
                            "      response messages, and improve sequencing and redelivery handling",
                            "    - Remove osutil unused AtomicWriteFollow flag",
                            "    - Remove xerrors dependency",
                            "    - Reuse existing seed-refresh implementation for free during single-",
                            "      path installation",
                            "    - Rework how SnapSetup.SnapPath is used",
                            "    - seccomp: allow rseq_slice_yield",
                            "    - security logging: add seclog API for administrative actions and",
                            "      token create/remove events",
                            "    - security logging: add security logging for adding, updating and",
                            "      removing a snapd user",
                            "    - Set target hostname from install-mode",
                            "    - snap-confine: improve loading of BPF programs, retry on failures",
                            "      to collect verifier logs",
                            "    - snap-confine: use profile and flags= in snap-confine and snap-",
                            "      update-ns' AppArmor profiles",
                            "    - snap-confine: work around kernel mnt_ns_loop() ordering bug on",
                            "      6.18.x",
                            "    - snap: add debug command for listing currently mediated devices for",
                            "      a given snap",
                            "    - snap: fix self-managed cgroup support checks",
                            "    - snap: report hidden file access for paths allowed by home when",
                            "      prompting is active",
                            "    - snap: report read-only file access for paths allowed by system-",
                            "      package-doc",
                            "    - snapctl async support: add --format json to snap tasks to be",
                            "      consistent with snapctl",
                            "    - snapctl async support: add snapctl tasks command",
                            "    - snapctl async support: async feature negotiation between snap",
                            "      client and daemon",
                            "    - snapctl async support: fix snapctl is-ready exit codes",
                            "    - snapctl async support: re-enable snapctl async functionality",
                            "    - snapshots: restore preserves snapctl created mounts",
                            "    - snapshots: save excludes all mount points",
                            "    - Support ca-certificate.crt only systems like core26",
                            "    - Turn on quota-groups by default",
                            "    - Use 0755 for certificate generation directories",
                            "    - Use CreateTemp for NewAtomicFile tmp file creation",
                            "    - Verify cached downloads in the do path and detect obvious",
                            "      corruption",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.77+ubuntu26.10",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2072331,
                            2110510,
                            2143934,
                            2160691,
                            2161982
                        ],
                        "author": "Sergio Cazzolato <sergio.cazzolato@canonical.com>",
                        "date": "Fri, 24 Jul 2026 20:45:05 -0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2158301",
                            "    - FDE: support keyboard configuration at install-time for first-boot",
                            "    - FDE: re-enable passphrases/PINs at install-time",
                            "    - FDE: require volumes authentication if HWROT is missing",
                            "    - FDE: bump secboot to rev 457b03a16d19",
                            "    - FDE: use new secboot API for reprovision TPM",
                            "    - Cross-distro: modify SELinux policy to use",
                            "      init_named_socket_activation() for allowing systemd to start snapd",
                            "      through socket activation",
                            "    - packaging: make sure that usr/bin/snap is built with correct build",
                            "      tags on debian sid",
                            "    - Ensure profiles are setup before running prepare-{slot, plug}*",
                            "      hooks",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76.3",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2158301
                        ],
                        "author": "Katie May <katie.may@canonical.com>",
                        "date": "Tue, 07 Jul 2026 10:06:48 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2159940",
                            "    - interfaces: steam-support, docker-support | fix mountinfo denial",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76.2",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2159940
                        ],
                        "author": "Katie May <katie.may@canonical.com>",
                        "date": "Tue, 07 Jul 2026 08:38:51 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2024-5300",
                                "url": "https://ubuntu.com/security/CVE-2024-5300",
                                "cve_description": "An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns \"complete\" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-21 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-3888",
                                "url": "https://ubuntu.com/security/CVE-2026-3888",
                                "cve_description": "Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-03-17 14:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2157692",
                            "    - LP: #2067006 CVE-2024-5300",
                            "    - CVE-2026-3888",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76.1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2157692,
                            2067006
                        ],
                        "author": "Ernest Lotter <ernest.lotter@canonical.com>",
                        "date": "Thu, 25 Jun 2026 13:09:05 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2024-5300",
                                "url": "https://ubuntu.com/security/CVE-2024-5300",
                                "cve_description": "An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns \"complete\" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-21 15:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-3888",
                                "url": "https://ubuntu.com/security/CVE-2026-3888",
                                "cve_description": "Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-03-17 14:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2157692",
                            "    - LP: #2067006 CVE-2024-5300",
                            "    - CVE-2026-3888",
                            "    - SNAPDENG-36017",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76.1",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2157692,
                            2067006
                        ],
                        "author": "Ernest Lotter <ernest.lotter@canonical.com>",
                        "date": "Sat, 20 Jun 2026 10:27:54 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * New upstream release, LP: #2154498",
                            "    - assertions: add helper for validating integrity data",
                            "    - assertions: drop incorrect/non-standard Ed25519 support",
                            "    - confdb: allow only API admin read access to confdb secrets",
                            "    - confdb: block concurrent confdb accesses",
                            "    - confdb: block concurrent snapctl accesses to configuration",
                            "      database",
                            "    - confdb: check for ephemeral data when missing save-view hook on",
                            "      commit",
                            "    - confdb: ignore not-found errors in confdb-schema refreshes",
                            "    - confdb: support --wait-for timeouts when accessing confdb",
                            "    - core-initrd: add group referenced in udev rules",
                            "    - core-initrd: add libbpf dependency to initramfs",
                            "    - core-initrd: add missing libbpf dependency in 24.04 packaging",
                            "    - core-initrd: ensure audio is a system group",
                            "    - core-initrd: fix /boot/uboot mount with u-boot env in dedicated",
                            "      partition",
                            "    - core-initrd: increase mount burst from 5 to 128 for faster boot",
                            "    - core-initrd: sync partition udev rules with the ones in core-base",
                            "    - core-initrd: sync with latest upload to snappy-dev PPA",
                            "    - core-initrd: synchronize changelogs with latest PPA upload",
                            "    - core-initrd: update changelog with latest PPA upload",
                            "    - core-initrd: add nfnetlink module to fix nf netlink",
                            "      socket speed regression (Ubuntu Core only)",
                            "    - cross-distro: allow snapd to manipulate systemd unit files in",
                            "      SELinux policy",
                            "    - cross-distro: FIPS bootstrap and dispatch via snap-fips-dispatch",
                            "    - desktop: fix common ID selection with multiple desktop plugs",
                            "    - FDE: allow user mode on core in secboot TPM handling",
                            "    - FDE: bump go-efilib dependency",
                            "    - FDE: bump secboot to rev cdcb64992e54 for FDE fixes",
                            "    - FDE: deprecate check-pin/passphrase API endpoints",
                            "    - LP: #2147606 FDE: give inactive state on classic",
                            "    - FDE: improve tracing for OP-TEE probing",
                            "    - FDE: move auto-repair logic to overlord/fdestate and provide state",
                            "    - FDE: update secboot for TPM/FDE bug fixes including Intel HAP and",
                            "      recovery key parsing",
                            "    - FDE: use any primary key matching digest when adding a keyslot",
                            "    - FDE: use ignore action for preinstall check in VM",
                            "    - interfaces: bluez | drop explicit deny send_destination in D-Bus",
                            "      configuration",
                            "    - interfaces: conditionally deny /proc/self/mountinfo to suppress Go",
                            "      1.25+ denials",
                            "    - interfaces: custom-device | fix for-device validation panic on",
                            "      non-string value",
                            "    - interfaces: disallow auto-connect to parallel installs",
                            "    - interfaces: docker | make plug implicit on classic systems",
                            "    - interfaces: ignore errors in disconnect hooks during explicit snap",
                            "      disconnect",
                            "    - interfaces: mediatek-accel | add plug interface base declaration",
                            "    - interfaces: microceph-support | suppress noisy sudo denial audit",
                            "      logs",
                            "    - interfaces: podman | add new interface for podman socket access",
                            "    - interfaces: pulseaudio | fix security tag syntax inconsistency",
                            "    - interfaces: raw-usb | allow USB device enumeration on Fairphone 5",
                            "      with NexDock",
                            "    - interfaces: restore auto-connections on failed refresh undo",
                            "    - LP: #2148544 interfaces: bool-file | support deep SoC sysfs paths",
                            "      for LED brightness",
                            "    - LP: #2139213 packaging: make Ubuntu 16.04 packaging dep17",
                            "      compliant",
                            "    - packaging: add cross-distro build script and instructions",
                            "    - packaging: add openSUSE 16.0 spread support",
                            "    - packaging: Debian build improvements",
                            "    - packaging: default openSUSE to /var/lib/snapd/snap and sync from",
                            "      downstream",
                            "    - packaging: drop transitional packages only for Ubuntu 26.04",
                            "      (Resolute)",
                            "    - packaging: fix Launchpad FIPS build detection for snapd-fips job",
                            "    - packaging: refactor and clean up snapd.mk, standardize test-data",
                            "      directories",
                            "    - packaging: switch to golang-github-chai2010-gettext-go-dev",
                            "    - packaging: update bundled AppArmor 4.1.7 (snapd snap only)",
                            "    - prompting: escape paths in prompt constraints",
                            "    - prompting: improve API error handling and validation",
                            "    - prompting: improve error message when no handler service is",
                            "      present",
                            "    - prompting: re-enable the prompting notice backend",
                            "    - prompting: respond with full user-allowed permission set",
                            "    - prompting: validate permissions while unmarshalling",
                            "    - remote device management: implement dispatch-mgmt-messages task",
                            "      with sequencing support",
                            "    - LP: #2125344 snap: avoid empty channel forwarding message",
                            "    - LP: #2150683 snap: clarify snap install help text for --classic",
                            "      and --devmode",
                            "    - LP: #2152908 snap: print complex attributes in snap interface",
                            "      --attrs output",
                            "    - snap: add run-inhibit hint and inhibit info when a snap is",
                            "      disabled",
                            "    - snap: allow removing a snap and its base at the same time",
                            "    - snap: display detailed component information in snap info",
                            "    - snap: extend AlreadyInstalledError to multiple snaps and",
                            "      components",
                            "    - snap: extend set-quota command options description with accepted",
                            "      value formats",
                            "    - snap: implement snap delta command for computing snap deltas",
                            "    - snap: improve consistency for snap install when some snaps are",
                            "      already installed",
                            "    - snap: show hint in snap list that a snap has components",
                            "    - snap-confine: allow inheriting unix sockets from snaps",
                            "    - snap-confine: allow linking to libm in AppArmor profile",
                            "    - snap-confine: fix out-of-bounds read in mountinfo parser for",
                            "      partial escape sequences",
                            "    - snap-confine: harden bpffs mount with nosuid, nodev, noexec flags",
                            "    - snap-confine: remove experimental persistent per-user mount",
                            "      namespace feature",
                            "    - snap-confine: set FD_CLOEXEC on file descriptors returned by BPF",
                            "      helpers",
                            "    - snap-confine: support transparent_hugepage in AppArmor profile",
                            "    - snap-confine: use strchr after NUL-terminating in infofile parser",
                            "    - snap-update-ns: switch to a multi-pass process for constructing",
                            "      and updating mount namespaces",
                            "    - RemoveMountUnitFile now unmounts even if mount unit file is",
                            "      missing",
                            "    - Add explicit mount phase during single-reboot refresh to fix undo",
                            "      of kernel refreshes",
                            "    - Add security audit logging subsystem",
                            "    - Add base prioritized AppArmmor snippets for strictly confined or",
                            "      jailed snaps",
                            "    - Allow openshell snap to use experimental daemon-scope: user",
                            "    - Allow configuring mount unit options based on filesystem type",
                            "    - Allow equals signs in uevent values in netlink parser",
                            "    - Also bind-mount directories modified by kmod backend during",
                            "      preseed",
                            "    - Clean up potentially corrupted files during snap download undo",
                            "    - Complete the bootloader environment implementation",
                            "    - Copy integrity data files during snap install",
                            "    - Create hook for seed refresh mode",
                            "    - Create removal tasks for old seed-refresh seeds",
                            "    - Dispatch systemctl commands asynchronously when calling Stop()",
                            "    - Ensure /tmp/.X11-unix created inside mount namespace has correct",
                            "      permissions",
                            "    - Ensure exclusive changes conflict with refresh/revert",
                            "    - Ensure existing snap confinement flags are not dropped when",
                            "      installing or removing components",
                            "    - Export ubuntu-boot-state filename constant from bootloader package",
                            "    - Fix duplicate removal of apps under $SNAP_MOUNT_DIR/bin",
                            "    - Fix integration between prerequisites task and seed-refresh mode",
                            "    - Fix split-refresh overwriting provided lane",
                            "    - Fix use of umask in GetListener for socket activation",
                            "    - Ignore net.ErrClosed during daemon shutdown",
                            "    - Implement ResolveValidationSetsEnforcementError in terms of one",
                            "      call",
                            "    - Improve snapctl install consistency when components are already",
                            "      installed",
                            "    - Inject seed creation tasks into snap refresh flow",
                            "    - Introduce system options for custom certificates on Ubuntu Core",
                            "    - Keep idle services with activation units stopped on reload",
                            "    - List snap components in snap-debug-info via debug-tools",
                            "    - Look at gadget.yaml instead of marker file to determine ubootpart",
                            "      usage",
                            "    - LP: #1966067 Skip redundant xdg-settings confirmation prompt when",
                            "      setting is already correct",
                            "    - LP: #2110368 Fix component installation for private snaps via",
                            "      snapctl",
                            "    - LP: #2110368 Fix download of private snap components by setting",
                            "      UserID",
                            "    - LP: #2144666 Fix mount namespace updates with synthetic bind",
                            "      mounts on same target paths",
                            "    - LP: #2146337 Improve handling of failed downloads and retain",
                            "      partial files for resume",
                            "    - LP: #2147207 Fix snap enable/disable cycle forgetting components",
                            "    - Make run-inhibit hint for kill-snap-apps task based on kill reason",
                            "    - Merge content-provider prerequisite updates into seed-refresh",
                            "    - Move SortServices into Backend.StartServices",
                            "    - Move state to client change conversion to ctlcmd package",
                            "    - Omit misleading \"try to refresh snapd\" suggestion for ISA-related",
                            "      errors",
                            "    - Only create link-component tasks when needed during refresh to",
                            "      existing revision",
                            "    - Reconfigure piboot bootloader on gadget refreshes to preserve",
                            "      os_prefix",
                            "    - Reduce the number of AppArmor profile regenerations during snap",
                            "      operations",
                            "    - Refactor seed-refresh ownership to devicestate",
                            "    - Regenerate certificate database on remodels",
                            "    - Remove obsolete FIXME comment in VersionCompare",
                            "    - Remove unused GenerateDmVerityData helper from snap/integrity",
                            "    - Rename and document error type for ISA assumes flags",
                            "    - Restart snapd from daemon.Stop to improve restart reliability",
                            "    - Restart stopped services on error in stopSnapServices for",
                            "      transactionality",
                            "    - Simplify certificate-db updates on model-base refresh/installs",
                            "    - Support racing Loop and Stop correctly in overlord",
                            "    - Support sending file descriptors to systemd via sd_notify",
                            "    - Unroll CPU-heavy recursive function in snap state handlers",
                            "    - Update seccomp syscalls list for kernel 7.1.0",
                            "    - Use change ID to prevent nested seed-refresh spawned by",
                            "      prerequisites",
                            "    - Validate content interface plug target directories exist for",
                            "      core26+ snaps",
                            "    - Validate layout paths exist in snap tree for snaps using bare or",
                            "      core26+",
                            ""
                        ],
                        "package": "snapd",
                        "version": "2.76",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2154498,
                            2147606,
                            2148544,
                            2139213,
                            2125344,
                            2150683,
                            2152908,
                            1966067,
                            2110368,
                            2110368,
                            2144666,
                            2146337,
                            2147207
                        ],
                        "author": "Ernest Lotter <ernest.lotter@canonical.com>",
                        "date": "Thu, 28 May 2026 20:00:16 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-kernel-accessories",
                "from_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.575",
                    "version": "1.575"
                },
                "to_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.576",
                    "version": "1.576"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167086
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Refreshed dependencies",
                            "  * Removed busybox-static from standard (LP: #2167086)",
                            "  * Removed cpio from standard",
                            "  * Moved gnupg to server-raspi-recommends, server-recommends",
                            "  * Bump Standards-Version to 4.7.4",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "ubuntu-meta",
                        "version": "1.576",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167086
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Wed, 16 Sep 2026 19:56:52 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-minimal",
                "from_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.575",
                    "version": "1.575"
                },
                "to_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.576",
                    "version": "1.576"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167086
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Refreshed dependencies",
                            "  * Removed busybox-static from standard (LP: #2167086)",
                            "  * Removed cpio from standard",
                            "  * Moved gnupg to server-raspi-recommends, server-recommends",
                            "  * Bump Standards-Version to 4.7.4",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "ubuntu-meta",
                        "version": "1.576",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167086
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Wed, 16 Sep 2026 19:56:52 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-pro-client",
                "from_version": {
                    "source_package_name": "ubuntu-advantage-tools",
                    "source_package_version": "37.2ubuntu1",
                    "version": "37.2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "ubuntu-advantage-tools",
                    "source_package_version": "38ubuntu0",
                    "version": "38ubuntu0"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-9494",
                        "url": "https://ubuntu.com/security/CVE-2026-9494",
                        "cve_description": "An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11386",
                        "url": "https://ubuntu.com/security/CVE-2026-11386",
                        "cve_description": "An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-12391",
                        "url": "https://ubuntu.com/security/CVE-2026-12391",
                        "cve_description": "An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2131292
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-9494",
                                "url": "https://ubuntu.com/security/CVE-2026-9494",
                                "cve_description": "An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11386",
                                "url": "https://ubuntu.com/security/CVE-2026-11386",
                                "cve_description": "An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-12391",
                                "url": "https://ubuntu.com/security/CVE-2026-12391",
                                "cve_description": "An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Information disclosure",
                            "    - Remove credentials out of argv into apt's own auth.conf.d facility.",
                            "    - CVE-2026-9494",
                            "  * SECURITY UPDATE: Improper input validation",
                            "    - enforce StrictStringDataValue to applicable fields in directives",
                            "    - reject newline, carriage return, spaces, and shell meta characters",
                            "      in StrictStringDataValue",
                            "    - CVE-2026-11386",
                            "  * SECURITY UPDATE: Symlink attack",
                            "    - reject symlink log files in user-controlled directory trees during",
                            "      pro collect-logs",
                            "    - restrict pro collect-logs generated support archive permission to",
                            "      root only",
                            "    - CVE-2026-12391",
                            ""
                        ],
                        "package": "ubuntu-advantage-tools",
                        "version": "37.2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Eduardo Barretto <eduardo.barretto@canonical.com>",
                        "date": "Mon, 06 Jul 2026 11:34:19 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/apparmor/ubuntu_pro_esm_cache.jinja2: fix \"DENIED\" messages when",
                            "    devicetree exists (LP: #2131292)",
                            ""
                        ],
                        "package": "ubuntu-advantage-tools",
                        "version": "37.2ubuntu",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2131292
                        ],
                        "author": "Renan Rodrigo <rr@ubuntu.com>",
                        "date": "Wed, 11 Mar 2026 10:27:02 -0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "ubuntu-pro-client-l10n",
                "from_version": {
                    "source_package_name": "ubuntu-advantage-tools",
                    "source_package_version": "37.2ubuntu1",
                    "version": "37.2ubuntu1"
                },
                "to_version": {
                    "source_package_name": "ubuntu-advantage-tools",
                    "source_package_version": "38ubuntu0",
                    "version": "38ubuntu0"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-9494",
                        "url": "https://ubuntu.com/security/CVE-2026-9494",
                        "cve_description": "An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-11386",
                        "url": "https://ubuntu.com/security/CVE-2026-11386",
                        "cve_description": "An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.",
                        "cve_priority": "high",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-12391",
                        "url": "https://ubuntu.com/security/CVE-2026-12391",
                        "cve_description": "An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-16 13:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2131292
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-9494",
                                "url": "https://ubuntu.com/security/CVE-2026-9494",
                                "cve_description": "An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-11386",
                                "url": "https://ubuntu.com/security/CVE-2026-11386",
                                "cve_description": "An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\\n) characters can successfully inject arbitrary, attacker-controlled deb configuration lines into root-owned APT sources. When combined with the unvalidated additionalPackages[] field—which is passed positionally into a root-executed apt-get install command—an attacker capable of spoofing or manipulating the contract response (e.g., via a compromised internal infrastructure, an intercepted connection utilizing a trusted CA, or local logical bugs) can force the client to fetch and install malicious packages. This ultimately leads to arbitrary code execution with root privileges on the affected system. This component is preinstalled on supported Ubuntu Server releases and auto-attaches by default on cloud provider Ubuntu Pro images.",
                                "cve_priority": "high",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-12391",
                                "url": "https://ubuntu.com/security/CVE-2026-12391",
                                "cve_description": "An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-16 13:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Information disclosure",
                            "    - Remove credentials out of argv into apt's own auth.conf.d facility.",
                            "    - CVE-2026-9494",
                            "  * SECURITY UPDATE: Improper input validation",
                            "    - enforce StrictStringDataValue to applicable fields in directives",
                            "    - reject newline, carriage return, spaces, and shell meta characters",
                            "      in StrictStringDataValue",
                            "    - CVE-2026-11386",
                            "  * SECURITY UPDATE: Symlink attack",
                            "    - reject symlink log files in user-controlled directory trees during",
                            "      pro collect-logs",
                            "    - restrict pro collect-logs generated support archive permission to",
                            "      root only",
                            "    - CVE-2026-12391",
                            ""
                        ],
                        "package": "ubuntu-advantage-tools",
                        "version": "37.2ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Eduardo Barretto <eduardo.barretto@canonical.com>",
                        "date": "Mon, 06 Jul 2026 11:34:19 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/apparmor/ubuntu_pro_esm_cache.jinja2: fix \"DENIED\" messages when",
                            "    devicetree exists (LP: #2131292)",
                            ""
                        ],
                        "package": "ubuntu-advantage-tools",
                        "version": "37.2ubuntu",
                        "urgency": "medium",
                        "distributions": "resolute",
                        "launchpad_bugs_fixed": [
                            2131292
                        ],
                        "author": "Renan Rodrigo <rr@ubuntu.com>",
                        "date": "Wed, 11 Mar 2026 10:27:02 -0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": true
            },
            {
                "name": "ubuntu-server",
                "from_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.575",
                    "version": "1.575"
                },
                "to_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.576",
                    "version": "1.576"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167086
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Refreshed dependencies",
                            "  * Removed busybox-static from standard (LP: #2167086)",
                            "  * Removed cpio from standard",
                            "  * Moved gnupg to server-raspi-recommends, server-recommends",
                            "  * Bump Standards-Version to 4.7.4",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "ubuntu-meta",
                        "version": "1.576",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167086
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Wed, 16 Sep 2026 19:56:52 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ubuntu-standard",
                "from_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.575",
                    "version": "1.575"
                },
                "to_version": {
                    "source_package_name": "ubuntu-meta",
                    "source_package_version": "1.576",
                    "version": "1.576"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167086
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Refreshed dependencies",
                            "  * Removed busybox-static from standard (LP: #2167086)",
                            "  * Removed cpio from standard",
                            "  * Moved gnupg to server-raspi-recommends, server-recommends",
                            "  * Bump Standards-Version to 4.7.4",
                            "  * Switch to debhelper 14",
                            ""
                        ],
                        "package": "ubuntu-meta",
                        "version": "1.576",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167086
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Wed, 16 Sep 2026 19:56:52 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "vim",
                "from_version": {
                    "source_package_name": "vim",
                    "source_package_version": "2:9.2.0858-1ubuntu1",
                    "version": "2:9.2.0858-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "vim",
                    "source_package_version": "2:9.2.0858-1ubuntu2",
                    "version": "2:9.2.0858-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2161203
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debversions: try getting data from distro-info",
                            "    (Closes: #1118059, LP: #2161203)",
                            ""
                        ],
                        "package": "vim",
                        "version": "2:9.2.0858-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161203
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Wed, 19 Aug 2026 18:13:45 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "vim-common",
                "from_version": {
                    "source_package_name": "vim",
                    "source_package_version": "2:9.2.0858-1ubuntu1",
                    "version": "2:9.2.0858-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "vim",
                    "source_package_version": "2:9.2.0858-1ubuntu2",
                    "version": "2:9.2.0858-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2161203
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debversions: try getting data from distro-info",
                            "    (Closes: #1118059, LP: #2161203)",
                            ""
                        ],
                        "package": "vim",
                        "version": "2:9.2.0858-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161203
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Wed, 19 Aug 2026 18:13:45 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "vim-runtime",
                "from_version": {
                    "source_package_name": "vim",
                    "source_package_version": "2:9.2.0858-1ubuntu1",
                    "version": "2:9.2.0858-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "vim",
                    "source_package_version": "2:9.2.0858-1ubuntu2",
                    "version": "2:9.2.0858-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2161203
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debversions: try getting data from distro-info",
                            "    (Closes: #1118059, LP: #2161203)",
                            ""
                        ],
                        "package": "vim",
                        "version": "2:9.2.0858-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161203
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Wed, 19 Aug 2026 18:13:45 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "vim-tiny",
                "from_version": {
                    "source_package_name": "vim",
                    "source_package_version": "2:9.2.0858-1ubuntu1",
                    "version": "2:9.2.0858-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "vim",
                    "source_package_version": "2:9.2.0858-1ubuntu2",
                    "version": "2:9.2.0858-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2161203
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debversions: try getting data from distro-info",
                            "    (Closes: #1118059, LP: #2161203)",
                            ""
                        ],
                        "package": "vim",
                        "version": "2:9.2.0858-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161203
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Wed, 19 Aug 2026 18:13:45 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "wget",
                "from_version": {
                    "source_package_name": "wget",
                    "source_package_version": "1.25.0-2ubuntu6",
                    "version": "1.25.0-2ubuntu6"
                },
                "to_version": {
                    "source_package_name": "wget",
                    "source_package_version": "1.25.0-3ubuntu1",
                    "version": "1.25.0-3ubuntu1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-58469",
                        "url": "https://ubuntu.com/security/CVE-2026-58469",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58470",
                        "url": "https://ubuntu.com/security/CVE-2026-58470",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58471",
                        "url": "https://ubuntu.com/security/CVE-2026-58471",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58472",
                        "url": "https://ubuntu.com/security/CVE-2026-58472",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15146",
                        "url": "https://ubuntu.com/security/CVE-2026-15146",
                        "cve_description": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-10 19:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58472",
                        "url": "https://ubuntu.com/security/CVE-2026-58472",
                        "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 21:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2163536,
                    2163754
                ],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58469",
                                "url": "https://ubuntu.com/security/CVE-2026-58469",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58470",
                                "url": "https://ubuntu.com/security/CVE-2026-58470",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58471",
                                "url": "https://ubuntu.com/security/CVE-2026-58471",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58472",
                                "url": "https://ubuntu.com/security/CVE-2026-58472",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2163536). Remaining changes:",
                            "    - d/rules: pass --with-ssl=openssl",
                            "    - d/p/wget-maybe-prepend-scheme-only-in-verbose-mode: Print message only in",
                            "      verbose mode (LP #2122484).",
                            "    - SECURITY UPDATE: Buffer overflow in metalink.",
                            "      + debian/patches/CVE-2026-58469.patch: Fix buffer overflow in",
                            "        src/metalink.c",
                            "      + CVE-2026-58469",
                            "    - SECURITY UPDATE: Integer overflow in http",
                            "      + debian/patches/CVE-2026-58470.patch: Fix integer overflow in src/http.c",
                            "      + CVE-2026-58470",
                            "    - SECURITY UPDATE: Buffer overflow in convert_fname.",
                            "      + debian/patches/CVE-2026-58471.patch: Fix buffer overflow in src/url.c",
                            "      + CVE-2026-58471",
                            "    - SECURITY UPDATE: Integer and buffer overflow in html_quote_string.",
                            "      + debian/patches/CVE-2026-58472.patch: Fix integer+buffer overflow in",
                            "        src/convert.c",
                            "      + CVE-2026-58472",
                            "    - SECURITY REGRESSION: Incomplete fix for CVE-2026-58472 (LP #2163754)",
                            "      + debian/patches/CVE-2026-58472-post1.patch: Fix buffer overflow in",
                            "        src/convert.c",
                            ""
                        ],
                        "package": "wget",
                        "version": "1.25.0-3ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163536
                        ],
                        "author": "Ural Tunaboyu <ural@ubuntu.com>",
                        "date": "Tue, 25 Aug 2026 17:45:24 -0700"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-15146",
                                "url": "https://ubuntu.com/security/CVE-2026-15146",
                                "cve_description": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-10 19:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * patch from upstream git to fix CVE-2026-15146 a problem with IP validation in FTP PASV. closes: Bug#1142284",
                            ""
                        ],
                        "package": "wget",
                        "version": "1.25.0-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Noël Köthe <noel@debian.org>",
                        "date": "Fri, 24 Jul 2026 15:53:14 +0200"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58472",
                                "url": "https://ubuntu.com/security/CVE-2026-58472",
                                "cve_description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 21:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY REGRESSION: Incomplete fix for CVE-2026-58472 (LP: #2163754)",
                            "    - debian/patches/CVE-2026-58472-post1.patch: Fix buffer overflow in",
                            "      src/convert.c",
                            ""
                        ],
                        "package": "wget",
                        "version": "1.25.0-2ubuntu7",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2163754
                        ],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Wed, 19 Aug 2026 17:56:06 -0600"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "xkb-data",
                "from_version": {
                    "source_package_name": "xkeyboard-config",
                    "source_package_version": "2.47-1",
                    "version": "2.47-1"
                },
                "to_version": {
                    "source_package_name": "xkeyboard-config",
                    "source_package_version": "2.48-1",
                    "version": "2.48-1"
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * control: Add Conflicts on keyboards-rg (Closes: #1133239)",
                            "  * New upstream release.",
                            ""
                        ],
                        "package": "xkeyboard-config",
                        "version": "2.48-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Timo Aaltonen <tjaalton@debian.org>",
                        "date": "Wed, 05 Aug 2026 10:41:18 +0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "xxd",
                "from_version": {
                    "source_package_name": "vim",
                    "source_package_version": "2:9.2.0858-1ubuntu1",
                    "version": "2:9.2.0858-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": "vim",
                    "source_package_version": "2:9.2.0858-1ubuntu2",
                    "version": "2:9.2.0858-1ubuntu2"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2161203
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * debversions: try getting data from distro-info",
                            "    (Closes: #1118059, LP: #2161203)",
                            ""
                        ],
                        "package": "vim",
                        "version": "2:9.2.0858-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2161203
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Wed, 19 Aug 2026 18:13:45 +0200"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "added": {
        "deb": [
            {
                "name": "busybox",
                "from_version": {
                    "source_package_name": "busybox",
                    "source_package_version": "1:1.38.0-3ubuntu1",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "busybox",
                    "source_package_version": "1:1.38.0-3ubuntu3",
                    "version": "1:1.38.0-3ubuntu3"
                },
                "cves": [],
                "launchpad_bugs_fixed": [
                    2167087
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * rename busybox to busybox-static in that package, and stop providing",
                            "    initramfs hools for busybox-static (Closes: #1147074, LP: #2167087)",
                            "  * d/control: udhcpc:Provides: dhcp-client (Closes: #1063504)",
                            "  * d/control: drop udhcpd:Provides: dhcpd (Closes: #1063505)",
                            ""
                        ],
                        "package": "busybox",
                        "version": "1:1.38.0-3ubuntu3",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2167087
                        ],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Mon, 14 Sep 2026 22:33:10 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * config: deb,static: enable nohup applet (Closes: #1147077)",
                            ""
                        ],
                        "package": "busybox",
                        "version": "1:1.38.0-3ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [],
                        "author": "Benjamin Drung <bdrung@ubuntu.com>",
                        "date": "Fri, 11 Sep 2026 14:54:51 +0200"
                    }
                ],
                "notes": "busybox version '1:1.38.0-3ubuntu3' (source package busybox version '1:1.38.0-3ubuntu3') was added. busybox version '1:1.38.0-3ubuntu3' has the same source package name, busybox, as removed package busybox-static. As such we can use the source package version of the removed package, '1:1.38.0-3ubuntu1', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "libperl5.42",
                "from_version": {
                    "source_package_name": "perl",
                    "source_package_version": "5.40.1-8ubuntu1",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "perl",
                    "source_package_version": "5.42.3-1",
                    "version": "5.42.3-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-7017",
                        "url": "https://ubuntu.com/security/CVE-2026-7017",
                        "cve_description": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-9538",
                        "url": "https://ubuntu.com/security/CVE-2026-9538",
                        "cve_description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42496",
                        "url": "https://ubuntu.com/security/CVE-2026-42496",
                        "cve_description": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42497",
                        "url": "https://ubuntu.com/security/CVE-2026-42497",
                        "cve_description": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-12087",
                        "url": "https://ubuntu.com/security/CVE-2026-12087",
                        "cve_description": "Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-15 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-13221",
                        "url": "https://ubuntu.com/security/CVE-2026-13221",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15649",
                        "url": "https://ubuntu.com/security/CVE-2025-15649",
                        "cve_description": "IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-7010",
                        "url": "https://ubuntu.com/security/CVE-2026-7010",
                        "cve_description": "HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 22:22:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-8376",
                        "url": "https://ubuntu.com/security/CVE-2026-8376",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 00:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48959",
                        "url": "https://ubuntu.com/security/CVE-2026-48959",
                        "cve_description": "IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48961",
                        "url": "https://ubuntu.com/security/CVE-2026-48961",
                        "cve_description": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48962",
                        "url": "https://ubuntu.com/security/CVE-2026-48962",
                        "cve_description": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-57432",
                        "url": "https://ubuntu.com/security/CVE-2026-57432",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-57433",
                        "url": "https://ubuntu.com/security/CVE-2026-57433",
                        "cve_description": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-7017",
                                "url": "https://ubuntu.com/security/CVE-2026-7017",
                                "cve_description": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-9538",
                                "url": "https://ubuntu.com/security/CVE-2026-9538",
                                "cve_description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42496",
                                "url": "https://ubuntu.com/security/CVE-2026-42496",
                                "cve_description": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42497",
                                "url": "https://ubuntu.com/security/CVE-2026-42497",
                                "cve_description": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-12087",
                                "url": "https://ubuntu.com/security/CVE-2026-12087",
                                "cve_description": "Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-15 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-13221",
                                "url": "https://ubuntu.com/security/CVE-2026-13221",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.3.",
                            "  * [SECURITY] includes various upstream fixes:",
                            "    + CVE-2026-7017: HTTP::Tiny credential forwarding on redirects.",
                            "        (Closes: #1141639)",
                            "    + CVE-2026-9538: Archive::Tar memory exhaustion.",
                            "        (Closes: #1138861)",
                            "    + CVE-2026-42496: Archive::Tar symlink extraction.",
                            "        (Closes: #1138860)",
                            "    + CVE-2026-42497: Archive::Tar hardlink extraction.",
                            "        (Closes: #1138859)",
                            "    + CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read.",
                            "        (Closes: #1140152)",
                            "    + CVE-2026-13221: silently incorrect regular expression matches.",
                            "        (Closes: #1142037)",
                            "  * Refresh cross support files for all architectures.",
                            "    + also update the architecture lists in d/cross/README",
                            "  * Disable salsa-ci.yml as nobody currently cares about the results.",
                            "  * Update debian/copyright based on DFSG team review.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Mon, 17 Aug 2026 22:59:18 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add 5.42.2 to debian/released-versions.",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Wed, 22 Jul 2026 22:26:36 +0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2025-15649",
                                "url": "https://ubuntu.com/security/CVE-2025-15649",
                                "cve_description": "IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-7010",
                                "url": "https://ubuntu.com/security/CVE-2026-7010",
                                "cve_description": "HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 22:22:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-8376",
                                "url": "https://ubuntu.com/security/CVE-2026-8376",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 00:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48959",
                                "url": "https://ubuntu.com/security/CVE-2026-48959",
                                "cve_description": "IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48961",
                                "url": "https://ubuntu.com/security/CVE-2026-48961",
                                "cve_description": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48962",
                                "url": "https://ubuntu.com/security/CVE-2026-48962",
                                "cve_description": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-57432",
                                "url": "https://ubuntu.com/security/CVE-2026-57432",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-57433",
                                "url": "https://ubuntu.com/security/CVE-2026-57433",
                                "cve_description": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * [SECURITY] backport various fixes from upstream:",
                            "    + CVE-2025-15649: header parsing in IO::Uncompress::Unzip.",
                            "        (Closes: #1138863)",
                            "    + CVE-2026-7010:  CRLF-validation in HTTP::Tiny.",
                            "        (Closes: #1138858)",
                            "    + CVE-2026-8376:  Buffer overflow in Perl_study_chunk.",
                            "        (Closes: #1137345)",
                            "    + CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip.",
                            "        (Closes: #1138856)",
                            "    + CVE-2026-48961: crash in zipdetails.",
                            "        (Closes: #1138855)",
                            "    + CVE-2026-48962: code execution in IO-Compress via output globs.",
                            "        (Closes: #1138854)",
                            "    + CVE-2026-57432: out of bound heap reads in pack() and unpack().",
                            "        (Closes: #1138905)",
                            "    + CVE-2026-57433: signed integer overflow in Storable.",
                            "        (Closes: #1138906)",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sat, 06 Jun 2026 18:02:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.2.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Fri, 24 Apr 2026 22:39:00 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Helmut Grohne ]",
                            "  * Add libcrypt-dev to libperl-dev's Depends. (Closes: #1102978)",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Mon, 17 Nov 2025 21:03:18 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Reinstate Provides: libtest2-suite-perl. (See #1080359)",
                            "  * Refresh cross build support files for most architectures.",
                            "  * Update lintian overrides for 5.42.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sun, 24 Aug 2025 11:55:37 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.0.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sat, 16 Aug 2025 18:44:35 +0300"
                    }
                ],
                "notes": "libperl5.42 version '5.42.3-1' (source package perl version '5.42.3-1') was added. libperl5.42 version '5.42.3-1' has the same source package name, perl, as removed package libperl5.40. As such we can use the source package version of the removed package, '5.40.1-8ubuntu1', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            },
            {
                "name": "openssh-common",
                "from_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "to_version": {
                    "source_package_name": "openssh",
                    "source_package_version": "1:10.5p1-1ubuntu2",
                    "version": "1:10.5p1-1ubuntu2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-73281",
                        "url": "https://ubuntu.com/security/CVE-2026-73281",
                        "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73282",
                        "url": "https://ubuntu.com/security/CVE-2026-73282",
                        "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-73283",
                        "url": "https://ubuntu.com/security/CVE-2026-73283",
                        "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-08-11 20:18:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [
                    2150273,
                    2166924,
                    2166081
                ],
                "changes": [
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * d/p/lp-2150273-openssh-pam-upn: Fix PAM user mismatch with",
                            "    alternative UPN suffixes by comparing account UIDs instead of",
                            "    username strings (LP: #2150273)",
                            "  * d/t/password-auth-no-pam: create /run/sshd for the custom test",
                            "    service (LP: #2166924)",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu2",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2150273,
                            2166924
                        ],
                        "author": "Finn Rayk Gartner <finn.gartner@canonical.com>",
                        "date": "Wed, 09 Sep 2026 21:08:58 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Merge with Debian unstable (LP: #2166081). Remaining changes:",
                            "    - debian/rules: modify dh_installsystemd invocations for",
                            "      socket-activated sshd",
                            "    - debian/README.Debian: document systemd socket activation.",
                            "    - debian/.gitignore: drop file",
                            "    - debian/openssh-server.ucf-md5sum: update for Ubuntu delta",
                            "    - d/p/systemd-socket-activation.patch:",
                            "      + Fix sshd re-execution behavior when socket activation is used",
                            "      + Adapt sshd-session and sshd-auth for systemd socket activation",
                            "      + Allow AF_VSOCK sockets",
                            "    - debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket",
                            "      activation functionality.",
                            "    - debian/patches: Immediately report interactive instructions to PAM clients",
                            "    - debian/control: Build-Depends: systemd-dev",
                            "    - d/p/sshd-socket-generator.patch: add generator for socket activation",
                            "    - debian/openssh-server.install: install sshd-socket-generator",
                            "    - debian/openssh-server.postinst: restart whichever systemd unit is enabled",
                            "    - d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator",
                            "    - ssh.socket: adjust unit for socket activation by default",
                            "    - debian/rules: explicitly enable LTO",
                            "    - d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests",
                            "    - d/openssh-server.links: add full sshd.service -> ssh.service alias",
                            "      (LP #2087949)",
                            "    - document /etc/ssh/sshd_config.d/*.conf better in sshd_config",
                            "      (LP #2088207)",
                            "    - d/rules,d/control: do not build with wtmpdb support",
                            "    - d/t/control: add breaks-testbed restriction to tests",
                            "    - d/tests: do not fail when $HOME/.ssh exists",
                            "    - test: workaround test failure caused by uutils dd (LP #2125943)",
                            "    - d/rules: only act on files from bin:openssh-tests if it's being",
                            "      built (LP #2165026)",
                            "    - d/t/control: disable regress test on i386, since bin:openssh-tests",
                            "      is not built for that architecture in Ubuntu",
                            "  * Dropped:",
                            "    - d/t/password-auth-no-pam: create the privilege separation",
                            "      directory manually for this test, as it doesn't use the systemd",
                            "      service unit to start sshd",
                            "      [Not needed since 1:10.5p1-1]",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1ubuntu1",
                        "urgency": "medium",
                        "distributions": "stonking",
                        "launchpad_bugs_fixed": [
                            2166081
                        ],
                        "author": "Andreas Hasenack <andreas.hasenack@canonical.com>",
                        "date": "Tue, 01 Sep 2026 14:45:43 -0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-73281",
                                "url": "https://ubuntu.com/security/CVE-2026-73281",
                                "cve_description": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73282",
                                "url": "https://ubuntu.com/security/CVE-2026-73282",
                                "cve_description": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-73283",
                                "url": "https://ubuntu.com/security/CVE-2026-73283",
                                "cve_description": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-08-11 20:18:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * New upstream release (closes: #1144192):",
                            "    - CVE-2026-73281: ssh-agent(1): fix an interaction between agent locking",
                            "      and the session-bind@openssh.com extension that is used to identify",
                            "      forwarded agents. These binding requests were refused when the agent",
                            "      was locked, with the result that operations that were intended to be",
                            "      limited to local use only could be performed remotely, including the",
                            "      ability to add PKCS#11 tokens and make use of keys that had",
                            "      destination restrictions applied.",
                            "    - CVE-2026-73282: ssh(1): avoid potential realloc use-after-free in the",
                            "      client if a remote forwarding is added via the local session",
                            "      multiplexing socket while a remote forwarding open request is pending",
                            "      with the server.",
                            "    - CVE-2026-73283: sshd(8): make the authorized_keys \"restrict\" keyword",
                            "      apply correctly to tunnel forwarding too (which is administratively",
                            "      disabled by default).",
                            "    - ssh-keygen(1): add ability to set or clear the touch-required and",
                            "      verify-required flags on FIDO private keys when resetting a private",
                            "      key's passphrase.",
                            "    - ssh(1): tweak ordering of certificates tried during pubkey",
                            "      authentication to prefer FIDO keys that do not require user presence",
                            "      (touch) first, and FIDO keys that require user verification via PIN or",
                            "      biometrics last. This effectively tries low-friction authenticators",
                            "      before higher friction ones.",
                            "    - ssh(1): add a \"ssh -Z user@host\" mode that prints the keys that will",
                            "      be tried for public key authentication in the order that they will be",
                            "      used.",
                            "    - sshd(8) use setproctitle(3) to identify sshd-session when it's acting",
                            "      as a post-authentication monitor.",
                            "    - ssh-keyscan(1): make reading the server banner a non-blocking",
                            "      operation to prevent a stuck server from blocking a many-host keyscan",
                            "      from proceeding.",
                            "    - sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the",
                            "      packet code as this provides context of the failing peer (address,",
                            "      port, user, etc).",
                            "    - sshd(8): when signing hostkey proofs for a client UpdateHostKeys",
                            "      request, allow each hostkey to perform at most one signature",
                            "      operation.",
                            "    - ssh-keygen(1): pass back errors from ed25519 key generation, which",
                            "      theoretically can fail.",
                            "    - sshd(8): move check of public key type against allowed algorithms to",
                            "      before parsing of the key sent by the peer. This removes at least some",
                            "      key parsing and verification paths from the pre-auth attack surface.",
                            "    - ssh-keygen(1): fix double frees (impossible to reach outside of a test",
                            "      harness), and also use freezero where possible.",
                            "    - sshd(8): fix ChannelTimeout and RekeyLimit not being applied in",
                            "      sshd_config Match blocks.",
                            "    - sshd(8): in sshd config dump mode, write all directives in mixed case",
                            "      for consistency.",
                            "    - sshd(8): re-allow PAMServiceName inside a Match block, which was",
                            "      incorrectly disabled during a refactoring in openssh-10.4.",
                            ""
                        ],
                        "package": "openssh",
                        "version": "1:10.5p1-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Colin Watson <cjwatson@debian.org>",
                        "date": "Mon, 31 Aug 2026 20:53:27 +0100"
                    }
                ],
                "notes": "For a newly added package only the three most recent changelog entries are shown.",
                "is_version_downgrade": false
            },
            {
                "name": "perl-modules-5.42",
                "from_version": {
                    "source_package_name": "perl",
                    "source_package_version": "5.40.1-8ubuntu1",
                    "version": null
                },
                "to_version": {
                    "source_package_name": "perl",
                    "source_package_version": "5.42.3-1",
                    "version": "5.42.3-1"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-7017",
                        "url": "https://ubuntu.com/security/CVE-2026-7017",
                        "cve_description": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-07 19:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-9538",
                        "url": "https://ubuntu.com/security/CVE-2026-9538",
                        "cve_description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42496",
                        "url": "https://ubuntu.com/security/CVE-2026-42496",
                        "cve_description": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-42497",
                        "url": "https://ubuntu.com/security/CVE-2026-42497",
                        "cve_description": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 02:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-12087",
                        "url": "https://ubuntu.com/security/CVE-2026-12087",
                        "cve_description": "Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-15 22:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-13221",
                        "url": "https://ubuntu.com/security/CVE-2026-13221",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2025-15649",
                        "url": "https://ubuntu.com/security/CVE-2025-15649",
                        "cve_description": "IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-7010",
                        "url": "https://ubuntu.com/security/CVE-2026-7010",
                        "cve_description": "HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-11 22:22:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-8376",
                        "url": "https://ubuntu.com/security/CVE-2026-8376",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-26 00:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48959",
                        "url": "https://ubuntu.com/security/CVE-2026-48959",
                        "cve_description": "IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48961",
                        "url": "https://ubuntu.com/security/CVE-2026-48961",
                        "cve_description": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-48962",
                        "url": "https://ubuntu.com/security/CVE-2026-48962",
                        "cve_description": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-27 04:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-57432",
                        "url": "https://ubuntu.com/security/CVE-2026-57432",
                        "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-57433",
                        "url": "https://ubuntu.com/security/CVE-2026-57433",
                        "cve_description": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-13 17:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-7017",
                                "url": "https://ubuntu.com/security/CVE-2026-7017",
                                "cve_description": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-07 19:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-9538",
                                "url": "https://ubuntu.com/security/CVE-2026-9538",
                                "cve_description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42496",
                                "url": "https://ubuntu.com/security/CVE-2026-42496",
                                "cve_description": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-42497",
                                "url": "https://ubuntu.com/security/CVE-2026-42497",
                                "cve_description": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 02:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-12087",
                                "url": "https://ubuntu.com/security/CVE-2026-12087",
                                "cve_description": "Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-15 22:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-13221",
                                "url": "https://ubuntu.com/security/CVE-2026-13221",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.3.",
                            "  * [SECURITY] includes various upstream fixes:",
                            "    + CVE-2026-7017: HTTP::Tiny credential forwarding on redirects.",
                            "        (Closes: #1141639)",
                            "    + CVE-2026-9538: Archive::Tar memory exhaustion.",
                            "        (Closes: #1138861)",
                            "    + CVE-2026-42496: Archive::Tar symlink extraction.",
                            "        (Closes: #1138860)",
                            "    + CVE-2026-42497: Archive::Tar hardlink extraction.",
                            "        (Closes: #1138859)",
                            "    + CVE-2026-12087: Socket: pack_ip_mreq_source() out-of-bounds heap read.",
                            "        (Closes: #1140152)",
                            "    + CVE-2026-13221: silently incorrect regular expression matches.",
                            "        (Closes: #1142037)",
                            "  * Refresh cross support files for all architectures.",
                            "    + also update the architecture lists in d/cross/README",
                            "  * Disable salsa-ci.yml as nobody currently cares about the results.",
                            "  * Update debian/copyright based on DFSG team review.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.3-1",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Mon, 17 Aug 2026 22:59:18 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Add 5.42.2 to debian/released-versions.",
                            "  * Upload to unstable.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-3",
                        "urgency": "medium",
                        "distributions": "unstable",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Wed, 22 Jul 2026 22:26:36 +0300"
                    },
                    {
                        "cves": [
                            {
                                "cve": "CVE-2025-15649",
                                "url": "https://ubuntu.com/security/CVE-2025-15649",
                                "cve_description": "IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-7010",
                                "url": "https://ubuntu.com/security/CVE-2026-7010",
                                "cve_description": "HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-11 22:22:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-8376",
                                "url": "https://ubuntu.com/security/CVE-2026-8376",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-26 00:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48959",
                                "url": "https://ubuntu.com/security/CVE-2026-48959",
                                "cve_description": "IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48961",
                                "url": "https://ubuntu.com/security/CVE-2026-48961",
                                "cve_description": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-48962",
                                "url": "https://ubuntu.com/security/CVE-2026-48962",
                                "cve_description": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-27 04:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-57432",
                                "url": "https://ubuntu.com/security/CVE-2026-57432",
                                "cve_description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-57433",
                                "url": "https://ubuntu.com/security/CVE-2026-57433",
                                "cve_description": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-13 17:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * [SECURITY] backport various fixes from upstream:",
                            "    + CVE-2025-15649: header parsing in IO::Uncompress::Unzip.",
                            "        (Closes: #1138863)",
                            "    + CVE-2026-7010:  CRLF-validation in HTTP::Tiny.",
                            "        (Closes: #1138858)",
                            "    + CVE-2026-8376:  Buffer overflow in Perl_study_chunk.",
                            "        (Closes: #1137345)",
                            "    + CVE-2026-48959: CPU exhaustion in IO::Uncompress::Unzip.",
                            "        (Closes: #1138856)",
                            "    + CVE-2026-48961: crash in zipdetails.",
                            "        (Closes: #1138855)",
                            "    + CVE-2026-48962: code execution in IO-Compress via output globs.",
                            "        (Closes: #1138854)",
                            "    + CVE-2026-57432: out of bound heap reads in pack() and unpack().",
                            "        (Closes: #1138905)",
                            "    + CVE-2026-57433: signed integer overflow in Storable.",
                            "        (Closes: #1138906)",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sat, 06 Jun 2026 18:02:30 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.2.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.2-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Fri, 24 Apr 2026 22:39:00 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  [ Helmut Grohne ]",
                            "  * Add libcrypt-dev to libperl-dev's Depends. (Closes: #1102978)",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-3",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Mon, 17 Nov 2025 21:03:18 +0200"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Reinstate Provides: libtest2-suite-perl. (See #1080359)",
                            "  * Refresh cross build support files for most architectures.",
                            "  * Update lintian overrides for 5.42.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-2",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sun, 24 Aug 2025 11:55:37 +0300"
                    },
                    {
                        "cves": [],
                        "log": [
                            "",
                            "  * Update to new upstream version 5.42.0.",
                            ""
                        ],
                        "package": "perl",
                        "version": "5.42.0-1",
                        "urgency": "medium",
                        "distributions": "experimental",
                        "launchpad_bugs_fixed": [],
                        "author": "Niko Tyni <ntyni@debian.org>",
                        "date": "Sat, 16 Aug 2025 18:44:35 +0300"
                    }
                ],
                "notes": "perl-modules-5.42 version '5.42.3-1' (source package perl version '5.42.3-1') was added. perl-modules-5.42 version '5.42.3-1' has the same source package name, perl, as removed package libperl5.40. As such we can use the source package version of the removed package, '5.40.1-8ubuntu1', as the starting point in our changelog diff. Kernel packages are an example of where the binary package name changes for the same source package. Using the removed package source package version as our starting point means we can still get meaningful changelog diffs even for what appears to be a new package.",
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "removed": {
        "deb": [
            {
                "name": "bpfcc-tools",
                "from_version": {
                    "source_package_name": "bpfcc",
                    "source_package_version": "0.35.0+ds-1ubuntu2",
                    "version": "0.35.0+ds-1ubuntu2"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "bpftrace",
                "from_version": {
                    "source_package_name": "bpftrace",
                    "source_package_version": "0.25.0-1ubuntu1",
                    "version": "0.25.0-1ubuntu1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "busybox-static",
                "from_version": {
                    "source_package_name": "busybox",
                    "source_package_version": "1:1.38.0-3ubuntu1",
                    "version": "1:1.38.0-3ubuntu1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "cpio",
                "from_version": {
                    "source_package_name": "cpio",
                    "source_package_version": "2.15+dfsg-2.1ubuntu1",
                    "version": "2.15+dfsg-2.1ubuntu1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "ieee-data",
                "from_version": {
                    "source_package_name": "ieee-data",
                    "source_package_version": "20260625",
                    "version": "20260625"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libbpfcc",
                "from_version": {
                    "source_package_name": "bpfcc",
                    "source_package_version": "0.35.0+ds-1ubuntu2",
                    "version": "0.35.0+ds-1ubuntu2"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc-dev-bin",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2.3",
                    "version": "2.43-2ubuntu2.3"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libc6-dev",
                "from_version": {
                    "source_package_name": "glibc",
                    "source_package_version": "2.43-2ubuntu2.3",
                    "version": "2.43-2ubuntu2.3"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libclang-cpp21",
                "from_version": {
                    "source_package_name": "llvm-toolchain-21",
                    "source_package_version": "1:21.1.8-6ubuntu1",
                    "version": "1:21.1.8-6ubuntu1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libclang1-21",
                "from_version": {
                    "source_package_name": "llvm-toolchain-21",
                    "source_package_version": "1:21.1.8-6ubuntu1",
                    "version": "1:21.1.8-6ubuntu1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libllvm21",
                "from_version": {
                    "source_package_name": "llvm-toolchain-21",
                    "source_package_version": "1:21.1.8-6ubuntu1",
                    "version": "1:21.1.8-6ubuntu1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libperl5.40",
                "from_version": {
                    "source_package_name": "perl",
                    "source_package_version": "5.40.1-8ubuntu1",
                    "version": "5.40.1-8ubuntu1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libproc2-0",
                "from_version": {
                    "source_package_name": "procps",
                    "source_package_version": "2:4.0.4-9ubuntu1",
                    "version": "2:4.0.4-9ubuntu1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "linux-libc-dev",
                "from_version": {
                    "source_package_name": "linux",
                    "source_package_version": "7.2.0-5.5",
                    "version": "7.2.0-5.5"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "manpages-dev",
                "from_version": {
                    "source_package_name": "manpages",
                    "source_package_version": "6.18-1",
                    "version": "6.18-1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "perl-modules-5.40",
                "from_version": {
                    "source_package_name": "perl",
                    "source_package_version": "5.40.1-8ubuntu1",
                    "version": "5.40.1-8ubuntu1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-bpfcc",
                "from_version": {
                    "source_package_name": "bpfcc",
                    "source_package_version": "0.35.0+ds-1ubuntu2",
                    "version": "0.35.0+ds-1ubuntu2"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-netaddr",
                "from_version": {
                    "source_package_name": "python-netaddr",
                    "source_package_version": "1.3.0-2",
                    "version": "1.3.0-2"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-pyasn1",
                "from_version": {
                    "source_package_name": "pyasn1",
                    "source_package_version": "0.6.4-1",
                    "version": "0.6.4-1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "python3-pyasn1-modules",
                "from_version": {
                    "source_package_name": "python-pyasn1-modules",
                    "source_package_version": "0.4.1-2build1",
                    "version": "0.4.1-2build1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "rpcsvc-proto",
                "from_version": {
                    "source_package_name": "rpcsvc-proto",
                    "source_package_version": "1.4.4-1",
                    "version": "1.4.4-1"
                },
                "to_version": {
                    "source_package_name": null,
                    "source_package_version": null,
                    "version": null
                },
                "cves": [],
                "launchpad_bugs_fixed": [],
                "changes": [],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "notes": "Changelog diff for Ubuntu 26.10 stonking image from daily image serial 20260911 to 20260918",
    "from_series": "stonking",
    "to_series": "stonking",
    "from_serial": "20260911",
    "to_serial": "20260918",
    "from_manifest_filename": "daily_manifest.previous",
    "to_manifest_filename": "manifest.current"
}