UbuntuUpdates.org

Bugs addressed in recent updates

All Launchpad Ubuntu Debian CVE

Origin Bug number Title Packages
CVE CVE-2026-53327 In the Linux kernel, the following vulnerability has been resolved: debugobjects: Do not fill_pool() if pi_blocked_on On RT enabled kernels, fill_p linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-64188 In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() rmnet_dell linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-43010 In the Linux kernel, the following vulnerability has been resolved: bpf: Reject sleepable kprobe_multi programs at attach time kprobe.multi program linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-53163 In the Linux kernel, the following vulnerability has been resolved: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued syzbot trigge linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-53388 In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before replacing page cache folio fuse_try_move_folio() u linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-53385 In the Linux kernel, the following vulnerability has been resolved: vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write A K linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-53383 In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject non-VALID session in compound request branch smb2_check_user_sess linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-53382 In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si syzbot reported linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-53381 In the Linux kernel, the following vulnerability has been resolved: virtiofs: fix UAF on submount umount iput() called from fuse_release_end() can linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-63807 In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level W linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-63836 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd The cwnd is always MSS linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-63835 In the Linux kernel, the following vulnerability has been resolved: batman-adv: v: prevent OGM aggregation on disabled hardif When an interface get linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-63834 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: restrict number of unacked list entries When the unacked_ linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-53366 In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), w linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-63833 In the Linux kernel, the following vulnerability has been resolved: ntfs3: reject direct userspace writes to reserved $LX* xattrs NTFS3 uses $LXUID linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-63831 In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: add skb_cow_data() before in-place crypto llsec_do_encrypt_un linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-64254 In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR W linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-63826 In the Linux kernel, the following vulnerability has been resolved: fbdev: fix use-after-free in store_modes() store_modes() replaces a framebuffer linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-63824 In the Linux kernel, the following vulnerability has been resolved: KEYS: fix overflow in keyctl_pkey_params_get_2() The length for the internal ou linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8
CVE CVE-2026-63823 In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() linux linux-hwe-6.8 linux linux-riscv-6.8 linux-lowlatency-hwe-6.8 linux-riscv-6.8



About   -   Send Feedback to @ubuntu_updates