{
    "summary": {
        "snap": {
            "added": [],
            "removed": [],
            "diff": []
        },
        "deb": {
            "added": [],
            "removed": [],
            "diff": [
                "libfreetype6",
                "libpng16-16t64",
                "sudo"
            ]
        }
    },
    "diff": {
        "deb": [
            {
                "name": "libfreetype6",
                "from_version": {
                    "source_package_name": "freetype",
                    "source_package_version": "2.13.2+dfsg-1ubuntu0.1",
                    "version": "2.13.2+dfsg-1ubuntu0.1"
                },
                "to_version": {
                    "source_package_name": "freetype",
                    "source_package_version": "2.13.2+dfsg-1ubuntu0.2",
                    "version": "2.13.2+dfsg-1ubuntu0.2"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-95512",
                        "url": "https://ubuntu.com/security/CVE-2026-95512",
                        "cve_description": "A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-10-02 09:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-95512",
                                "url": "https://ubuntu.com/security/CVE-2026-95512",
                                "cve_description": "A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-10-02 09:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: DoS in CID font loader",
                            "    - debian/patches/CVE-2026-95512.patch: * src/cid/cidload.c (cid_read_subrs):",
                            "      Limit overlaps. in src/cid/cidload.c.",
                            "    - CVE-2026-95512",
                            ""
                        ],
                        "package": "freetype",
                        "version": "2.13.2+dfsg-1ubuntu0.2",
                        "urgency": "medium",
                        "distributions": "noble-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Mon, 05 Oct 2026 10:43:12 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libpng16-16t64",
                "from_version": {
                    "source_package_name": "libpng1.6",
                    "source_package_version": "1.6.43-5ubuntu0.6",
                    "version": "1.6.43-5ubuntu0.6"
                },
                "to_version": {
                    "source_package_name": "libpng1.6",
                    "source_package_version": "1.6.43-5ubuntu0.7",
                    "version": "1.6.43-5ubuntu0.7"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-46675",
                        "url": "https://ubuntu.com/security/CVE-2026-46675",
                        "cve_description": "[Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression]",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-29"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-46675",
                                "url": "https://ubuntu.com/security/CVE-2026-46675",
                                "cve_description": "[Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression]",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-29"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: Use-after-free in png_read_end",
                            "    - debian/patches/CVE-2026-46675.patch: Clear stale zstream pointers when",
                            "      releasing the inflate stream in pngrutil.c",
                            "    - CVE-2026-46675",
                            ""
                        ],
                        "package": "libpng1.6",
                        "version": "1.6.43-5ubuntu0.7",
                        "urgency": "medium",
                        "distributions": "noble-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Kyle Kernick <kyle.kernick@canonical.com>",
                        "date": "Mon, 05 Oct 2026 15:37:18 -0600"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "sudo",
                "from_version": {
                    "source_package_name": "sudo",
                    "source_package_version": "1.9.15p5-3ubuntu5.24.04.3",
                    "version": "1.9.15p5-3ubuntu5.24.04.3"
                },
                "to_version": {
                    "source_package_name": "sudo",
                    "source_package_version": "1.9.15p5-3ubuntu5.24.04.4",
                    "version": "1.9.15p5-3ubuntu5.24.04.4"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-96512",
                        "url": "https://ubuntu.com/security/CVE-2026-96512",
                        "cve_description": "A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-09-23 14:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-96512",
                                "url": "https://ubuntu.com/security/CVE-2026-96512",
                                "cve_description": "A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-09-23 14:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: NOTBEFORE or NOTAFTER restrictions bypass via TZ",
                            "    - debian/patches/CVE-2026-96512-pre1.patch: sudo: ignore user-specified TZ",
                            "      environment variable in src/sudo.c.",
                            "    - debian/patches/CVE-2026-96512.patch: Remove TZ from sudo's working",
                            "      environment without modifying envp. in src/sudo.c.",
                            "    - CVE-2026-96512",
                            ""
                        ],
                        "package": "sudo",
                        "version": "1.9.15p5-3ubuntu5.24.04.4",
                        "urgency": "medium",
                        "distributions": "noble-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Marc Deslauriers <marc.deslauriers@ubuntu.com>",
                        "date": "Tue, 06 Oct 2026 09:51:33 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "added": {
        "deb": [],
        "snap": []
    },
    "removed": {
        "deb": [],
        "snap": []
    },
    "notes": "Changelog diff for Ubuntu 24.04 noble image from release image serial 20261001 to 20261008",
    "from_series": "noble",
    "to_series": "noble",
    "from_serial": "20261001",
    "to_serial": "20261008",
    "from_manifest_filename": "release_manifest.previous",
    "to_manifest_filename": "manifest.current"
}