Sudo pro fix USN-8442-1

Hi Ubuntu Support,

Ubuntu Version:
22.04 LTS

Problem Description:

Running sudo pro fix USN-8442-1 I see:

USN-8442-1: kitty vulnerabilities
Associated CVEs:

Fixing requested USN-8442-1
1 affected source package is installed: kitty
(1/1) kitty:
A fix is available in Ubuntu Pro: ESM Apps.

  • Cannot install package kitty version 0.21.2-1ubuntu0.22.04.1+esm1
  • Cannot install package kitty-doc version 0.21.2-1ubuntu0.22.04.1+esm1
  • Cannot install package kitty-terminfo version 0.21.2-1ubuntu0.22.04.1+esm1

1 package is still affected: kitty
✘ USN-8442-1 is not resolved.

But when I look up the CVE’s it says they are resolved.

I have tried apt clean, apt update, apt upgrade, detecting pro and reattaching, rebooting the machine but I still can’t update to the latest esm1 kitty package.

e.g. apt-cache policy kitty-terminfo
kitty-terminfo:
Installed: 0.21.2-1ubuntu0.22.04.1
Candidate: 0.21.2-1ubuntu0.22.04.1
Version table:
*** 0.21.2-1ubuntu0.22.04.1 500
500 http://security.ubuntu.com/ubuntu jammy-security/universe amd64 Packages
500 Index of /ubuntu jammy-updates/universe amd64 Packages
100 /var/lib/dpkg/status
0.21.2-1build1 500
500 Index of /ubuntu jammy/universe amd64 Packag

Any ideas as to why the update cannot be installed?

1 Like

Hi there and welcome to the Ubuntu Discourse, @thoughtmachine! Nice nickname, BTW. :slight_smile:

For ESM Apps security support, your machine needs to be attached to an Ubuntu Pro subscription; it’s free for personal use on up to five machines.

You may also want to give this a read:

2 Likes

Hi,

Thanks for responding, I should clarify this is with Ubuntu Pro installed and esm-apps enabled. I’ve tried on two different Ubuntu Jammy machines and still can’t get the latest esm packages as per the USN/CSV.

Many Thanks,
Tania

1 Like

You know what you are doing better than I do. I am having to research. Sometimes some one looking with fresh eyes sees things that we surely know but have not noticed.

I see that these CVE fixes should come through the normal apt update/apt upgrade process. And the Ubuntu web page says specifically “restart kitty.”

And then there is this statement: Fix a specific CVE with the Ubuntu Pro client.

If you want to get the fixes for a specific CVE, make sure you have the Ubuntu Pro Client installed, updated and set up. Then run this command on your terminal, replacing CVE-YYYY-XXXX with a valid CVE ID:

sudo pro fix CVE-YYYY-XXXX

Fixing CVE’s

I noticed that your command is for fixing a USN. Just a thought by an uneducated Ubuntu user.

Regards

1 Like

What does

apt list --upgradeable

show?

1 Like

HI,

I also tried pro fix with the csv numbers, here is the result:

sudo pro fix CVE-2026-33642
CVE-2026-33642: kitty vulnerabilities
 - https://ubuntu.com/security/CVE-2026-33642

1 affected source package is installed: kitty
(1/1) kitty:
A fix is available in Ubuntu Pro: ESM Apps.
- Cannot install package kitty version 0.21.2-1ubuntu0.22.04.1+esm1
- Cannot install package kitty-doc version 0.21.2-1ubuntu0.22.04.1+esm1
- Cannot install package kitty-terminfo version 0.21.2-1ubuntu0.22.04.1+esm1

1 package is still affected: kitty
✘ CVE-2026-33642 is not resolved.

and

sudo pro fix CVE-2026-33633
CVE-2026-33633: kitty vulnerabilities
 - https://ubuntu.com/security/CVE-2026-33633

1 affected source package is installed: kitty
(1/1) kitty:
A fix is available in Ubuntu Pro: ESM Apps.
- Cannot install package kitty version 0.21.2-1ubuntu0.22.04.1+esm1
- Cannot install package kitty-doc version 0.21.2-1ubuntu0.22.04.1+esm1
- Cannot install package kitty-terminfo version 0.21.2-1ubuntu0.22.04.1+esm1

1 package is still affected: kitty
✘ CVE-2026-33633 is not resolved.

I tried:

 apt list --upgradeable
Listing... Done
containers-common/jammy 100:1-22 all [upgradable from: 100:1-22]
docker.io/jammy 20.10.21-0ubuntu1~20.04.2 amd64 [upgradable from: 20.10.21-0ubuntu1~20.04.2]
session-manager-plugin/jammy 1.2.764.0-1 amd64 [upgradable from: 1.2.764.0-1]

Also by specifying the packages that should be there:

sudo apt-get install kitty=0.21.2-1ubuntu0.22.04.1+esm1 kitty-terminfo=0.21.2-1ubuntu0.22.04.1+esm1 kitty-doc=0.21.2-1ubuntu0.22.04.1+esm1
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Package kitty is not available, but is referred to by another package.
This may mean that the package is missing, has been obsoleted, or
is only available from another source
However the following packages replace it:
  kitty-doc

Package kitty-terminfo is not available, but is referred to by another package.
This may mean that the package is missing, has been obsoleted, or
is only available from another source

Package kitty-doc is not available, but is referred to by another package.
This may mean that the package is missing, has been obsoleted, or
is only available from another source

E: Version '0.21.2-1ubuntu0.22.04.1+esm1' for 'kitty' was not found
E: Version '0.21.2-1ubuntu0.22.04.1+esm1' for 'kitty-terminfo' was not found
E: Version '0.21.2-1ubuntu0.22.04.1+esm1' for 'kitty-doc' was not found

I also cleaned via apt clean in case of caching issues.

I’m wondering if this a dependency issue, where although both CSVs are fixed, one of the kitty packages isn’t and that’s why the update/fix isn’t working?

Many Thanks,

Tania

1 Like

Please show us the complete output of the following three commands:

sudo apt update
sudo apt upgrade
pro status
2 Likes

Hi,

sudo apt update
Hit:1 http://security.ubuntu.com/ubuntu jammy-security InRelease
Hit:2 http://gb.archive.ubuntu.com/ubuntu jammy-backports InRelease                                                    
Hit:3 http://gb.archive.ubuntu.com/ubuntu jammy-updates InRelease                                                      
Hit:4 http://gb.archive.ubuntu.com/ubuntu jammy InRelease                                                              
Ign:5 http://dl.google.com/linux/chrome-remote-desktop/deb stable InRelease                                            
Hit:6 http://HTTPS///artifacts.elastic.co/packages/7.x/apt stable InRelease                                            
Hit:7 https://packages.microsoft.com/repos/azure-cli jammy InRelease                                                   
Hit:8 https://packages.microsoft.com/repos/vscode stable InRelease                                                     
Hit:9 https://packages.microsoft.com/repos/code stable InRelease                                                       
Hit:10 http://dl.google.com/linux/chrome/deb stable InRelease                                                          
Hit:11 http://dl.google.com/linux/chrome-remote-desktop/deb stable Release                                             
Hit:12 http://HTTPS///tm-apt-repo-prod.s3.amazonaws.com jammy InRelease                                                
Hit:13 https://dl.google.com/linux/chrome-stable/deb stable InRelease                                                  
Hit:14 http://packages.cloud.google.com/apt cloud-sdk InRelease                                                        
Hit:15 http://packages.cloud.google.com/apt endpoint-verification InRelease                                            
Hit:16 http://pkg.osquery.io/deb deb InRelease                                                                         
Hit:17 http://apt.puppetlabs.com jammy InRelease                                                                       
Hit:18 http://apt.puppet.com jammy InRelease                        
Hit:19 https://esm.ubuntu.com/apps/ubuntu jammy-apps-security InRelease
Hit:21 https://esm.ubuntu.com/infra/ubuntu jammy-infra-security InRelease
Hit:22 https://esm.ubuntu.com/infra/ubuntu jammy-infra-updates InRelease
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
3 packages can be upgraded. Run 'apt list --upgradable' to see them.




sudo apt upgrade
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Calculating upgrade... Done
The following packages have been kept back:
  containers-common docker.io session-manager-plugin
0 upgraded, 0 newly installed, 0 to remove and 3 not upgraded.



sudo pro status
SERVICE          ENTITLED  STATUS       DESCRIPTION
anbox-cloud      yes       disabled     Scalable Android in the cloud
esm-apps         yes       enabled      Expanded Security Maintenance for Applications
esm-infra        yes       enabled      Expanded Security Maintenance for Infrastructure
fips-preview     yes       disabled     Preview of FIPS crypto packages undergoing certification with NIST
fips-updates     yes       disabled     FIPS compliant crypto packages with stable security updates
livepatch        yes       enabled      Canonical Livepatch service
realtime-kernel* yes       disabled     Ubuntu kernel with PREEMPT_RT patches integrated
usg              yes       disabled     Security compliance and audit tools

 * Service has variants

For a list of all Ubuntu Pro services and variants, run 'pro status --all'
Enable services with: pro enable <service>

                Account: XXX
           Subscription: Ubuntu Pro Desktop
            Valid until: Sat Jul 31 00:59:59 2027 BST
Technical support level: essential

Thanks,

Tania

The kitty packages are not listed in https://esm.ubuntu.com/apps/ubuntu/dists/jammy-apps-security/main/binary-amd64/Packages (or Packages.gz) so I’m a little surprised apt even knows about them. I guess they’re referenced by other packages? They’re present in focal’s and noble’s esm-apps packages list, but for some reason not jammy’s at the moment.

I don’t have Pro enabled so I can’t view the contents of https://esm.ubuntu.com/apps/ubuntu/pool to see if the packages are in there.

Their unavailability is probably a temporary thing, though.

This topic was automatically closed after 30 days. New replies are no longer allowed.