UbuntuUpdates.org

Package "linux-kvm"

This package belongs to a PPA: Canonical Kernel Team




Name: linux-kvm

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

Latest version: *DELETED*
Release: bionic (18.04)
Level: base
Repository: main

Links



Other versions of "linux-kvm" in Bionic

Repository Area Version
base main 4.15.0-1008.8
security main 4.15.0-1132.137
updates main 4.15.0-1142.147
proposed main 4.15.0-1142.147

Changelog

Version: 4.15.0-1136.141 2023-02-09 17:08:41 UTC

 linux-kvm (4.15.0-1136.141) bionic; urgency=medium
 .
   * bionic/linux-kvm: 4.15.0-1136.141 -proposed tracker (LP: #2004406)
 .
   * Bionic update: upstream stable patchset 2023-01-20 (LP: #2003596)
     - [Config] kvm: updateconfigs for INET_TABLE_PERTURB_ORDER
 .
   [ Ubuntu: 4.15.0-206.217 ]
 .
   * bionic/linux: 4.15.0-206.217 -proposed tracker (LP: #2004655)
   * CVE-2023-0461
     - SAUCE: Fix inet_csk_listen_start after CVE-2023-0461
 .
   [ Ubuntu: 4.15.0-205.216 ]
 .
   * bionic/linux: 4.15.0-205.216 -proposed tracker (LP: #2004414)
   * Bionic update: upstream stable patchset 2023-01-20 (LP: #2003596)
     - NFSv4.1: Handle RECLAIM_COMPLETE trunking errors
     - NFSv4.1: We must always send RECLAIM_COMPLETE after a reboot
     - nfs4: Fix kmemleak when allocate slot failed
     - net: dsa: Fix possible memory leaks in dsa_loop_init()
     - nfc: s3fwrn5: Fix potential memory leak in s3fwrn5_nci_send()
     - nfc: nfcmrvl: Fix potential memory leak in nfcmrvl_i2c_nci_send()
     - net: fec: fix improper use of NETDEV_TX_BUSY
     - ata: pata_legacy: fix pdc20230_set_piomode()
     - net: sched: Fix use after free in red_enqueue()
     - ipvs: use explicitly signed chars
     - rose: Fix NULL pointer dereference in rose_send_frame()
     - mISDN: fix possible memory leak in mISDN_register_device()
     - isdn: mISDN: netjet: fix wrong check of device registration
     - btrfs: fix inode list leak during backref walking at resolve_indirect_refs()
     - btrfs: fix ulist leaks in error paths of qgroup self tests
     - Bluetooth: L2CAP: fix use-after-free in l2cap_conn_del()
     - net: mdio: fix undefined behavior in bit shift for __mdiobus_register
     - net, neigh: Fix null-ptr-deref in neigh_table_clear()
     - media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE
     - media: dvb-frontends/drxk: initialize err to 0
     - i2c: xiic: Add platform module alias
     - Bluetooth: L2CAP: Fix attempting to access uninitialized memory
     - block, bfq: protect 'bfqd->queued' by 'bfqd->lock'
     - btrfs: fix type of parameter generation in btrfs_get_dentry
     - tcp/udp: Make early_demux back namespacified.
     - capabilities: fix potential memleak on error path from vfs_getxattr_alloc()
     - ALSA: usb-audio: Add quirks for MacroSilicon MS2100/MS2106 devices
     - efi: random: reduce seed size to 32 bytes
     - parisc: Make 8250_gsc driver dependend on CONFIG_PARISC
     - parisc: Export iosapic_serial_irq() symbol for serial port driver
     - ext4: fix warning in 'ext4_da_release_space'
     - KVM: x86: Mask off reserved bits in CPUID.80000008H
     - KVM: x86: emulator: em_sysexit should update ctxt->mode
     - KVM: x86: emulator: introduce emulator_recalc_and_set_mode
     - KVM: x86: emulator: update the emulation mode after CR0 write
     - linux/const.h: prefix include guard of uapi/linux/const.h with _UAPI
     - linux/const.h: move UL() macro to include/linux/const.h
     - linux/bits.h: make BIT(), GENMASK(), and friends available in assembly
     - RDMA/qedr: clean up work queue on failure in qedr_alloc_resources()
     - net: tun: fix bugs for oversize packet when napi frags enabled
     - ipvs: fix WARNING in __ip_vs_cleanup_batch()
     - ipvs: fix WARNING in ip_vs_app_net_cleanup()
     - ipv6: fix WARNING in ip6_route_net_exit_late()
     - parisc: Avoid printing the hardware path twice
     - HID: hyperv: fix possible memory leak in mousevsc_probe()
     - net: gso: fix panic on frag_list with mixed head alloc types
     - bnxt_en: fix potentially incorrect return value for ndo_rx_flow_steer
     - net: fman: Unregister ethernet device on removal
     - capabilities: fix undefined behavior in bit shift for CAP_TO_MASK
     - net: lapbether: fix issue of dev reference count leakage in
       lapbeth_device_event()
     - hamradio: fix issue of dev reference count leakage in bpq_device_event()
     - drm/vc4: Fix missing platform_unregister_drivers() call in
       vc4_drm_register()
     - ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network
     - tipc: fix the msg->req tlv len check in
       tipc_nl_compat_name_table_dump_header
     - dmaengine: mv_xor_v2: Fix a resource leak in mv_xor_v2_remove()
     - drivers: net: xgene: disable napi when register irq failed in
       xgene_enet_open()
     - net: cxgb3_main: disable napi when bind qsets failed in cxgb_up()
     - ethernet: s2io: disable napi when start nic failed in s2io_card_up()
     - net: mv643xx_eth: disable napi when init rxq or txq failed in
       mv643xx_eth_open()
     - net: macvlan: fix memory leaks of macvlan_common_newlink
     - arm64: efi: Fix handling of misaligned runtime regions and drop warning
     - ALSA: hda: fix potential memleak in 'add_widget_node'
     - ALSA: usb-audio: Add quirk entry for M-Audio Micro
     - nilfs2: fix deadlock in nilfs_count_free_blocks()
     - drm/i915/dmabuf: fix sg_table handling in map_dma_buf
     - platform/x86: hp_wmi: Fix rfkill causing soft blocked wifi
     - btrfs: selftests: fix wrong error check in btrfs_free_dummy_root()
     - udf: Fix a slab-out-of-bounds write bug in udf_find_entry()
     - cert host tools: Stop complaining about deprecated OpenSSL functions
     - dmaengine: at_hdmac: Fix at_lli struct definition
     - dmaengine: at_hdmac: Don't start transactions at tx_submit level
     - dmaengine: at_hdmac: Fix completion of unissued descriptor in case of errors
     - dmaengine: at_hdmac: Don't allow CPU to reorder channel enable
     - dmaengine: at_hdmac: Fix impossible condition
     - dmaengine: at_hdmac: Check return code of dma_async_device_register
     - x86/cpu: Restore AMD's DE_CFG MSR after resume
     - selftests/futex: fix build for clang
     - drm/imx: imx-tve: Fix return type of imx_tve_connector_mode_valid
     - ASoC: core: Fix use-after-free in snd_soc_exit()
     - serial: 8250_omap: remove wait loop from Errata i202 workaround
     - serial: 8250: omap: Flush PM QOS work on

Source diff to previous version
2003596 Bionic update: upstream stable patchset 2023-01-20
1968681 rdpru in ubuntu_kvm_unit_tests failed on B-4.15 node riccioli with FAIL: RDPRU raises #UD
2003053 NFS: client permission error after adding user to permissible group
2002889 5.15.0-58.64 breaks xen bridge networking (pvh domU)
2002812 Revoke \u0026 rotate to new signing key
CVE-2023-0461 RESERVED
CVE-2022-3628 A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver. This issue occurs when a user connects to a malicious USB device
CVE-2022-3545 A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function area_cache_get of the file

Version: 4.15.0-1135.140 2023-01-12 17:09:43 UTC

 linux-kvm (4.15.0-1135.140) bionic; urgency=medium
 .
   * bionic/linux-kvm: 4.15.0-1135.140 -proposed tracker (LP: #2001868)
 .
   [ Ubuntu: 4.15.0-203.214 ]
 .
   * bionic/linux: 4.15.0-203.214 -proposed tracker (LP: #2001876)
   * Packaging resync (LP: #1786013)
     - [Packaging] update helper scripts
   * Bionic update: upstream stable patchset 2022-12-01 (LP: #1998542)
     - Revert "x86/cpu: Add a steppings field to struct x86_cpu_id"
     - x86/cpufeature: Add facility to check for min microcode revisions
     - x86/cpufeature: Fix various quality problems in the
       header
     - x86/devicetable: Move x86 specific macro out of generic code
     - x86/cpu: Add consistent CPU match macros
     - x86/cpu: Add a steppings field to struct x86_cpu_id
     - x86/entry: Remove skip_r11rcx
     - x86/cpufeatures: Move RETPOLINE flags to word 11
     - x86/bugs: Report AMD retbleed vulnerability
     - x86/bugs: Add AMD retbleed= boot parameter
     - x86/bugs: Keep a per-CPU IA32_SPEC_CTRL value
     - x86/entry: Add kernel IBRS implementation
     - x86/bugs: Optimize SPEC_CTRL MSR writes
     - x86/speculation: Add spectre_v2=ibrs option to support Kernel IBRS
     - x86/bugs: Split spectre_v2_select_mitigation() and
       spectre_v2_user_select_mitigation()
     - x86/bugs: Report Intel retbleed vulnerability
     - entel_idle: Disable IBRS during long idle
     - x86/speculation: Change FILL_RETURN_BUFFER to work with objtool
     - x86/speculation: Add LFENCE to RSB fill sequence
     - x86/speculation: Fix RSB filling with CONFIG_RETPOLINE=n
     - x86/speculation: Fix firmware entry SPEC_CTRL handling
     - x86/speculation: Fix SPEC_CTRL write on SMT state change
     - x86/speculation: Use cached host SPEC_CTRL value for guest entry/exit
     - x86/speculation: Remove x86_spec_ctrl_mask
     - KVM: VMX: Prevent guest RSB poisoning attacks with eIBRS
     - KVM: VMX: Fix IBRS handling after vmexit
     - x86/speculation: Fill RSB on vmexit for IBRS
     - x86/common: Stamp out the stepping madness
     - x86/cpu/amd: Enumerate BTC_NO
     - x86/bugs: Add Cannon lake to RETBleed affected CPU list
     - x86/speculation: Disable RRSBA behavior
     - x86/speculation: Use DECLARE_PER_CPU for x86_spec_ctrl_current
     - x86/bugs: Warn when "ibrs" mitigation is selected on Enhanced IBRS parts
     - x86/speculation: Add RSB VM Exit protections
     - ocfs2: clear dinode links count in case of error
     - ocfs2: fix BUG when iput after ocfs2_mknod fails
     - x86/microcode/AMD: Apply the patch early on every logical thread
     - ata: ahci-imx: Fix MODULE_ALIAS
     - ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS
     - KVM: arm64: vgic: Fix exit condition in scan_its_table()
     - [Config] updateconfigs for ARM64_ERRATUM_1742098
     - arm64: errata: Remove AES hwcap for COMPAT tasks
     - r8152: add PID for the Lenovo OneLink+ Dock
     - btrfs: fix processing of delayed data refs during backref walking
     - ACPI: extlog: Handle multiple records
     - HID: magicmouse: Do not set BTN_MOUSE on double report
     - net/atm: fix proc_mpc_write incorrect return value
     - net: hns: fix possible memory leak in hnae_ae_register()
     - iommu/vt-d: Clean up si_domain in the init_dmars() error path
     - media: v4l2-mem2mem: Apply DST_QUEUE_OFF_BASE on MMAP buffers across ioctls
     - ACPI: video: Force backlight native for more TongFang devices
     - ALSA: Use del_timer_sync() before freeing timer
     - ALSA: au88x0: use explicitly signed char
     - USB: add RESET_RESUME quirk for NVIDIA Jetson devices in RCM
     - usb: dwc3: gadget: Don't set IMI for no_interrupt
     - usb: bdc: change state when port disconnected
     - usb: xhci: add XHCI_SPURIOUS_SUCCESS to ASM1042 despite being a V0.96
       controller
     - xhci: Remove device endpoints from bandwidth list when freeing the device
     - tools: iio: iio_utils: fix digit calculation
     - iio: light: tsl2583: Fix module unloading
     - fbdev: smscufx: Fix several use-after-free bugs
     - mac802154: Fix LQI recording
     - drm/msm/hdmi: fix memory corruption with too many bridges
     - mmc: core: Fix kernel panic when remove non-standard SDIO card
     - kernfs: fix use-after-free in __kernfs_remove
     - s390/futex: add missing EX_TABLE entry to __futex_atomic_op()
     - Xen/gntdev: don't ignore kernel unmapping error
     - xen/gntdev: Prevent leaking grants
     - mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages
     - net: ieee802154: fix error return code in dgram_bind()
     - drm/msm: Fix return type of mdp4_lvds_connector_mode_valid
     - arc: iounmap() arg is volatile
     - ALSA: ac97: fix possible memory leak in snd_ac97_dev_register()
     - x86/unwind/orc: Fix unreliable stack dump with gcov
     - amd-xgbe: fix the SFP compliance codes check for DAC cables
     - amd-xgbe: add the bit rate quirk for Molex cables
     - kcm: annotate data-races around kcm->rx_psock
     - kcm: annotate data-races around kcm->rx_wait
     - net: lantiq_etop: don't free skb when returning NETDEV_TX_BUSY
     - tcp: fix indefinite deferral of RTO with SACK reneging
     - can: mscan: mpc5xxx: mpc5xxx_can_probe(): add missing put_clock() in error
       path
     - PM: hibernate: Allow hybrid sleep to work with s2idle
     - media: vivid: s_fbuf: add more sanity checks
     - media: vivid: dev->bitmap_cap wasn't freed in all cases
     - media: v4l2-dv-timings: add sanity checks for blanking values
     - media: videodev2.h: V4L2_DV_BT_BLANKING_HEIGHT should check 'interlaced'
     - i40e: Fix ethtool rx-flow-hash setting for X722
     - i40e: Fix flow-type by setting GL_HASH_INSET registers
     - net: ksz884x: fix missing pci_disable_device() on error in pcidev_init()
     - PM: domains: Fix handling of unavailable/disabled idle states
     - ALSA: aoa: i2sbus: fix possible memory leak in i2sbus_add_dev()
     - ALSA: aoa: Fix I2S device accounting
     - openvswitch: sw

Source diff to previous version
1786013 Packaging resync
1998542 Bionic update: upstream stable patchset 2022-12-01
1996650 Bionic update: upstream stable patchset 2022-11-15

Version: 4.15.0-1133.138 2022-12-02 19:09:30 UTC

 linux-kvm (4.15.0-1133.138) bionic; urgency=medium
 .
   * bionic/linux-kvm: 4.15.0-1133.138 -proposed tracker (LP: #1997863)
 .
   [ Ubuntu: 4.15.0-201.212 ]
 .
   * bionic/linux: 4.15.0-201.212 -proposed tracker (LP: #1997871)
   * Expose built-in trusted and revoked certificates (LP: #1996892)
     - [Packaging] Expose built-in trusted and revoked certificates
   * Bionic update: upstream stable patchset 2022-09-21 (LP: #1990434)
     - s390/archrandom: prevent CPACF trng invocations in interrupt context
   * BUG: scheduling while atomic: ip/1210/0x00000200 on xenial/hwe rumford
     (LP: #1995870)
     - tg3: prevent scheduling while atomic splat
   * Bionic update: upstream stable patchset 2022-10-18 (LP: #1993349)
     - bpf: Verifer, adjust_scalar_min_max_vals to always call update_reg_bounds()
     - selftests/bpf: Fix test_align verifier log patterns
     - drm/msm/dsi: Fix number of regulators for msm8996_dsi_cfg
     - platform/x86: pmc_atom: Fix SLP_TYPx bitfield mask
     - wifi: cfg80211: debugfs: fix return type in ht40allow_map_read()
     - ethernet: rocker: fix sleep in atomic context bug in neigh_timer_handler
     - kcm: fix strp_init() order and cleanup
     - serial: fsl_lpuart: RS485 RTS polariy is inverse
     - staging: rtl8712: fix use after free bugs
     - vt: Clear selection before changing the font
     - USB: serial: ftdi_sio: add Omron CS1W-CIF31 device id
     - binder: fix UAF of ref->proc caused by race condition
     - drm/i915/reg: Fix spelling mistake "Unsupport" -> "Unsupported"
     - Input: rk805-pwrkey - fix module autoloading
     - hwmon: (gpio-fan) Fix array out of bounds access
     - thunderbolt: Use the actual buffer in tb_async_error()
     - xhci: Add grace period after xHC start to prevent premature runtime suspend.
     - USB: serial: cp210x: add Decagon UCA device id
     - USB: serial: option: add support for OPPO R11 diag port
     - USB: serial: option: add Quectel EM060K modem
     - USB: serial: option: add support for Cinterion MV32-WA/WB RmNet mode
     - usb: dwc2: fix wrong order of phy_power_on and phy_init
     - USB: cdc-acm: Add Icom PMR F3400 support (0c26:0020)
     - usb-storage: Add ignore-residue quirk for NXP PN7462AU
     - s390/hugetlb: fix prepare_hugepage_range() check for 2 GB hugepages
     - s390: fix nospec table alignments
     - USB: core: Prevent nested device-reset calls
     - usb: gadget: mass_storage: Fix cdrom data transfers on MAC-OS
     - wifi: mac80211: Don't finalize CSA in IBSS mode if state is disconnected
     - net: mac802154: Fix a condition in the receive path
     - ALSA: seq: oss: Fix data-race for max_midi_devs access
     - ALSA: seq: Fix data-race at module auto-loading
     - efi: capsule-loader: Fix use-after-free in efi_capsule_write
     - wifi: iwlegacy: 4965: corrected fix for potential off-by-one overflow in
       il4965_rs_fill_link_cmd()
     - fs: only do a memory barrier for the first set_buffer_uptodate()
     - Revert "mm: kmemleak: take a full lowmem check in kmemleak_*_phys()"
     - drm/amdgpu: Check num_gfx_rings for gfx v9_0 rb setup.
     - drm/radeon: add a force flush to delay work when radeon
     - parisc: ccio-dma: Handle kmalloc failure in ccio_init_resources()
     - parisc: Add runtime check to prevent PA2.0 kernels on PA1.x machines
     - fbdev: chipsfb: Add missing pci_disable_device() in chipsfb_pci_init()
     - ALSA: emu10k1: Fix out of bounds access in snd_emu10k1_pcm_channel_alloc()
     - ALSA: aloop: Fix random zeros in capture data when using jiffies timer
     - ALSA: usb-audio: Fix an out-of-bounds bug in
       __snd_usb_parse_audio_interface()
     - kprobes: Prohibit probes in gate area
     - scsi: mpt3sas: Fix use-after-free warning
     - driver core: Don't probe devices after bus_type.match() probe deferral
     - netfilter: br_netfilter: Drop dst references before setting.
     - sch_sfb: Don't assume the skb is still around after enqueueing to child
     - tipc: fix shift wrapping bug in map_get()
     - ipv6: sr: fix out-of-bounds read when setting HMAC data.
     - tcp: fix early ETIMEDOUT after spurious non-SACK RTO
     - sch_sfb: Also store skb len before calling child enqueue
     - usb: dwc3: fix PHY disable sequence
     - USB: serial: ch341: fix lost character on LCR updates
     - USB: serial: ch341: fix disabled rx timer on older devices
     - MIPS: loongson32: ls1c: Fix hang during startup
     - SUNRPC: use _bh spinlocking on ->transport_lock
     - net: dp83822: disable false carrier interrupt
     - tcp: annotate data-race around challenge_timestamp
     - clk: core: Honor CLK_OPS_PARENT_ENABLE for clk gate ops
     - clk: core: Fix runtime PM sequence in clk_core_unprepare()
     - soc: brcmstb: pm-arm: Fix refcount leak and __iomem leak bugs
     - i40e: Fix kernel crash during module removal
     - mm: Fix TLB flush for not-first PFNMAP mappings in unmap_region()
     - drm/msm/rd: Fix FIFO-full deadlock
     - HID: ishtp-hid-clientHID: ishtp-hid-client: Fix comment typo
     - tg3: Disable tg3 device on system reboot to avoid triggering AER
     - ieee802154: cc2520: add rc code in cc2520_tx()
     - platform/x86: acer-wmi: Acer Aspire One AOD270/Packard Bell Dot keymap fixes
     - tracefs: Only clobber mode/uid/gid on remount if asked
     - net: dp83822: disable rx error interrupt
   * Bionic update: upstream stable patchset 2022-10-06 (LP: #1992112)
     - audit: fix potential double free on error path from fsnotify_add_inode_mark
     - parisc: Fix exception handler for fldw and fstw instructions
     - pinctrl: amd: Don't save/restore interrupt status and wake status bits
     - xfrm: fix refcount leak in __xfrm_policy_check()
     - rose: check NULL rose_loopback_neigh->loopback
     - bonding: 802.3ad: fix no transmission of LACPDUs
     - net: ipvtap - add __init/__exit annotations to module init/exit funcs
     - netfilter: ebtables: reject blobs that don't provide all entry points
     - netfi

Source diff to previous version
1996892 Expose built-in trusted and revoked certificates
1990434 Bionic update: upstream stable patchset 2022-09-21
1995870 BUG: scheduling while atomic: ip/1210/0x00000200 on xenial/hwe rumford
1993349 Bionic update: upstream stable patchset 2022-10-18
1992112 Bionic update: upstream stable patchset 2022-10-06
CVE-2022-2663 An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall
CVE-2022-3061 Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() interface. The driver doesn't c

Version: 4.15.0-1130.135 2022-11-21 11:09:24 UTC

 linux-kvm (4.15.0-1130.135) bionic; urgency=medium
 .
   * bionic/linux-kvm: 4.15.0-1130.135 -proposed tracker (LP: #1996409)
 .
   [ Ubuntu: 4.15.0-198.209 ]
 .
   * bionic/linux: 4.15.0-198.209 -proposed tracker (LP: #1996417)
   * CVE-2022-42073
     - mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse
   * CVE-2022-42703
     - mm/rmap.c: don't reuse anon_vma if we just want a copy
     - mm: rmap: explicitly reset vma->anon_vma in unlink_anon_vmas()
   * Bionic update: upstream stable patchset 2022-09-21 (LP: #1990434)
     - s390/archrandom: prevent CPACF trng invocations in interrupt context
   * BUG: scheduling while atomic: ip/1210/0x00000200 on xenial/hwe rumford
     (LP: #1995870)
     - tg3: prevent scheduling while atomic splat
   * Bionic update: upstream stable patchset 2022-10-18 (LP: #1993349)
     - bpf: Verifer, adjust_scalar_min_max_vals to always call update_reg_bounds()
     - selftests/bpf: Fix test_align verifier log patterns
     - drm/msm/dsi: Fix number of regulators for msm8996_dsi_cfg
     - platform/x86: pmc_atom: Fix SLP_TYPx bitfield mask
     - wifi: cfg80211: debugfs: fix return type in ht40allow_map_read()
     - ethernet: rocker: fix sleep in atomic context bug in neigh_timer_handler
     - kcm: fix strp_init() order and cleanup
     - serial: fsl_lpuart: RS485 RTS polariy is inverse
     - staging: rtl8712: fix use after free bugs
     - vt: Clear selection before changing the font
     - USB: serial: ftdi_sio: add Omron CS1W-CIF31 device id
     - binder: fix UAF of ref->proc caused by race condition
     - drm/i915/reg: Fix spelling mistake "Unsupport" -> "Unsupported"
     - Input: rk805-pwrkey - fix module autoloading
     - hwmon: (gpio-fan) Fix array out of bounds access
     - thunderbolt: Use the actual buffer in tb_async_error()
     - xhci: Add grace period after xHC start to prevent premature runtime suspend.
     - USB: serial: cp210x: add Decagon UCA device id
     - USB: serial: option: add support for OPPO R11 diag port
     - USB: serial: option: add Quectel EM060K modem
     - USB: serial: option: add support for Cinterion MV32-WA/WB RmNet mode
     - usb: dwc2: fix wrong order of phy_power_on and phy_init
     - USB: cdc-acm: Add Icom PMR F3400 support (0c26:0020)
     - usb-storage: Add ignore-residue quirk for NXP PN7462AU
     - s390/hugetlb: fix prepare_hugepage_range() check for 2 GB hugepages
     - s390: fix nospec table alignments
     - USB: core: Prevent nested device-reset calls
     - usb: gadget: mass_storage: Fix cdrom data transfers on MAC-OS
     - wifi: mac80211: Don't finalize CSA in IBSS mode if state is disconnected
     - net: mac802154: Fix a condition in the receive path
     - ALSA: seq: oss: Fix data-race for max_midi_devs access
     - ALSA: seq: Fix data-race at module auto-loading
     - efi: capsule-loader: Fix use-after-free in efi_capsule_write
     - wifi: iwlegacy: 4965: corrected fix for potential off-by-one overflow in
       il4965_rs_fill_link_cmd()
     - fs: only do a memory barrier for the first set_buffer_uptodate()
     - Revert "mm: kmemleak: take a full lowmem check in kmemleak_*_phys()"
     - drm/amdgpu: Check num_gfx_rings for gfx v9_0 rb setup.
     - drm/radeon: add a force flush to delay work when radeon
     - parisc: ccio-dma: Handle kmalloc failure in ccio_init_resources()
     - parisc: Add runtime check to prevent PA2.0 kernels on PA1.x machines
     - fbdev: chipsfb: Add missing pci_disable_device() in chipsfb_pci_init()
     - ALSA: emu10k1: Fix out of bounds access in snd_emu10k1_pcm_channel_alloc()
     - ALSA: aloop: Fix random zeros in capture data when using jiffies timer
     - ALSA: usb-audio: Fix an out-of-bounds bug in
       __snd_usb_parse_audio_interface()
     - kprobes: Prohibit probes in gate area
     - scsi: mpt3sas: Fix use-after-free warning
     - driver core: Don't probe devices after bus_type.match() probe deferral
     - netfilter: br_netfilter: Drop dst references before setting.
     - sch_sfb: Don't assume the skb is still around after enqueueing to child
     - tipc: fix shift wrapping bug in map_get()
     - ipv6: sr: fix out-of-bounds read when setting HMAC data.
     - tcp: fix early ETIMEDOUT after spurious non-SACK RTO
     - sch_sfb: Also store skb len before calling child enqueue
     - usb: dwc3: fix PHY disable sequence
     - USB: serial: ch341: fix lost character on LCR updates
     - USB: serial: ch341: fix disabled rx timer on older devices
     - MIPS: loongson32: ls1c: Fix hang during startup
     - SUNRPC: use _bh spinlocking on ->transport_lock
     - net: dp83822: disable false carrier interrupt
     - tcp: annotate data-race around challenge_timestamp
     - clk: core: Honor CLK_OPS_PARENT_ENABLE for clk gate ops
     - clk: core: Fix runtime PM sequence in clk_core_unprepare()
     - soc: brcmstb: pm-arm: Fix refcount leak and __iomem leak bugs
     - i40e: Fix kernel crash during module removal
     - mm: Fix TLB flush for not-first PFNMAP mappings in unmap_region()
     - drm/msm/rd: Fix FIFO-full deadlock
     - HID: ishtp-hid-clientHID: ishtp-hid-client: Fix comment typo
     - tg3: Disable tg3 device on system reboot to avoid triggering AER
     - ieee802154: cc2520: add rc code in cc2520_tx()
     - platform/x86: acer-wmi: Acer Aspire One AOD270/Packard Bell Dot keymap fixes
     - tracefs: Only clobber mode/uid/gid on remount if asked
     - net: dp83822: disable rx error interrupt
   * Bionic update: upstream stable patchset 2022-10-06 (LP: #1992112)
     - audit: fix potential double free on error path from fsnotify_add_inode_mark
     - parisc: Fix exception handler for fldw and fstw instructions
     - pinctrl: amd: Don't save/restore interrupt status and wake status bits
     - xfrm: fix refcount leak in __xfrm_policy_check()
     - rose: check NULL rose_loopback_neigh->loopback
     - bonding: 802.3ad: fix no transmission of LACPDUs
     - net: ipvtap - add __init/__exit annotations to

Source diff to previous version
1990434 Bionic update: upstream stable patchset 2022-09-21
1995870 BUG: scheduling while atomic: ip/1210/0x00000200 on xenial/hwe rumford
1993349 Bionic update: upstream stable patchset 2022-10-18
1992112 Bionic update: upstream stable patchset 2022-10-06
1994601 [UBUNTU 18.04] Ubuntu 18.04 kernel 4.15.0-194 crashes on IPL
CVE-2022-42073 Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=.
CVE-2022-42703 mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse.
CVE-2022-3239 A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for the Empia 28xx based TV cards.
CVE-2022-2663 An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall
CVE-2022-3061 Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() interface. The driver doesn't c

Version: 4.15.0-1129.134 2022-10-19 20:08:27 UTC

 linux-kvm (4.15.0-1129.134) bionic; urgency=medium
 .
   * bionic/linux-kvm: 4.15.0-1129.134 -proposed tracker (LP: #1992089)
 .
   [ Ubuntu: 4.15.0-195.206 ]
 .
   * bionic/linux: 4.15.0-195.206 -proposed tracker (LP: #1992097)
   * Memory leak while using NFQUEUE to delegate the decision on TCP packets to
     userspace processes (LP: #1991774)
     - SAUCE: netfilter: nf_queue: Fix memory leak in nf_queue_entry_get_refs
   * Bionic update: upstream stable patchset 2022-09-23 (LP: #1990698)
     - Bluetooth: L2CAP: Fix use-after-free caused by l2cap_chan_put
     - ntfs: fix use-after-free in ntfs_ucsncmp()
     - ARM: crypto: comment out gcc warning that breaks clang builds
     - mt7601u: add USB device ID for some versions of XiaoDu WiFi Dongle.
     - ACPI: video: Force backlight native for some TongFang devices
     - macintosh/adb: fix oob read in do_adb_query() function
     - Makefile: link with -z noexecstack --no-warn-rwx-segments
     - x86: link vdso and boot with -z noexecstack --no-warn-rwx-segments
     - ALSA: bcd2000: Fix a UAF bug on the error path of probing
     - add barriers to buffer_uptodate and set_buffer_uptodate
     - HID: wacom: Don't register pad_input for touch switch
     - KVM: SVM: Don't BUG if userspace injects an interrupt with GIF=0
     - KVM: x86: Mark TSS busy during LTR emulation _after_ all fault checks
     - KVM: x86: Set error code to segment selector on LLDT/LTR non-canonical #GP
     - ALSA: hda/conexant: Add quirk for LENOVO 20149 Notebook model
     - ALSA: hda/cirrus - support for iMac 12,1 model
     - vfs: Check the truncate maximum size in inode_newsize_ok()
     - fs: Add missing umask strip in vfs_tmpfile
     - usbnet: Fix linkwatch use-after-free on disconnect
     - parisc: Fix device names in /proc/iomem
     - drm/nouveau: fix another off-by-one in nvbios_addr
     - drm/amdgpu: Check BO's requested pinning domains against its
       preferred_domains
     - iio: light: isl29028: Fix the warning in isl29028_remove()
     - fuse: limit nsec
     - md-raid10: fix KASAN warning
     - ia64, processor: fix -Wincompatible-pointer-types in ia64_get_irr()
     - PCI: Add defines for normal and subtractive PCI bridges
     - powerpc/fsl-pci: Fix Class Code of PCIe Root Port
     - powerpc/powernv: Avoid crashing if rng is NULL
     - MIPS: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK
     - USB: HCD: Fix URB giveback issue in tasklet function
     - netfilter: nf_tables: fix null deref due to zeroed list head
     - arm64: Do not forget syscall when starting a new thread.
     - arm64: fix oops in concurrently setting insn_emulation sysctls
     - ext2: Add more validity checks for inode counts
     - ARM: dts: imx6ul: add missing properties for sram
     - ARM: dts: imx6ul: fix qspi node compatible
     - ARM: OMAP2+: display: Fix refcount leak bug
     - ACPI: PM: save NVS memory for Lenovo G40-45
     - ACPI: LPSS: Fix missing check in register_device_clock()
     - PM: hibernate: defer device probing when resuming from hibernation
     - selinux: Add boundary check in put_entry()
     - ARM: findbit: fix overflowing offset
     - ARM: bcm: Fix refcount leak in bcm_kona_smc_init
     - x86/pmem: Fix platform-device leak in error path
     - ARM: dts: ast2500-evb: fix board compatible
     - soc: fsl: guts: machine variable might be unset
     - cpufreq: zynq: Fix refcount leak in zynq_get_revision
     - ARM: dts: qcom: pm8841: add required thermal-sensor-cells
     - arm64: dts: qcom: msm8916: Fix typo in pronto remoteproc node
     - regulator: of: Fix refcount leak bug in of_get_regulation_constraints()
     - thermal/tools/tmon: Include pthread and time headers in tmon.h
     - dm: return early from dm_pr_call() if DM device is suspended
     - drm/radeon: fix potential buffer overflow in ni_set_mc_special_registers()
     - drm/mediatek: Add pull-down MIPI operation in mtk_dsi_poweroff function
     - i2c: Fix a potential use after free
     - wifi: iwlegacy: 4965: fix potential off-by-one overflow in
       il4965_rs_fill_link_cmd()
     - drm: bridge: adv7511: Add check for mipi_dsi_driver_register
     - media: hdpvr: fix error value returns in hdpvr_read
     - drm/vc4: dsi: Correct DSI divider calculations
     - drm/rockchip: vop: Don't crash for invalid duplicate_state()
     - drm/mediatek: dpi: Remove output format of YUV
     - drm: bridge: sii8620: fix possible off-by-one
     - media: platform: mtk-mdp: Fix mdp_ipi_comm structure alignment
     - tcp: make retransmitted SKB fit into the send window
     - selftests: timers: valid-adjtimex: build fix for newer toolchains
     - selftests: timers: clocksource-switch: fix passing errors from child
     - fs: check FMODE_LSEEK to control internal pipe splicing
     - wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi()
     - wifi: p54: Fix an error handling path in p54spi_probe()
     - wifi: p54: add missing parentheses in p54_flush()
     - can: pch_can: do not report txerr and rxerr during bus-off
     - can: rcar_can: do not report txerr and rxerr during bus-off
     - can: sja1000: do not report txerr and rxerr during bus-off
     - can: hi311x: do not report txerr and rxerr during bus-off
     - can: sun4i_can: do not report txerr and rxerr during bus-off
     - can: usb_8dev: do not report txerr and rxerr during bus-off
     - can: error: specify the values of data[5..7] of CAN error frames
     - can: pch_can: pch_can_error(): initialize errc before using it
     - Bluetooth: hci_intel: Add check for platform_driver_register
     - i2c: cadence: Support PEC for SMBus block read
     - i2c: mux-gpmux: Add of_node_put() when breaking out of loop
     - wifi: wil6210: debugfs: fix uninitialized variable use in
       `wil_write_file_wmi()`
     - wifi: libertas: Fix possible refcount leak in if_usb_probe()
     - net: rose: fix netdev reference changes
     - dccp: put dccp_qpolicy_full() and dccp_qpolicy_push() in the same lock
     - mtd: maps:

1991774 Memory leak while using NFQUEUE to delegate the decision on TCP packets to userspace processes
1990698 Bionic update: upstream stable patchset 2022-09-23
1990434 Bionic update: upstream stable patchset 2022-09-21
1989144 unprivileged users may trigger page cache invalidation WARN
1990690 Users belonging to video group may trigger a deadlock WARN
1990985 ACPI: processor idle: Practically limit \
CVE-2022-3028 A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurr
CVE-2022-2978 A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following c
CVE-2022-40768 drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecomman



About   -   Send Feedback to @ubuntu_updates