UbuntuUpdates.org

Package "linux-cloud-tools-5.15.0-184-generic"

This package belongs to a PPA: Canonical Kernel Team

Name: linux-cloud-tools-5.15.0-184-generic

Description:

Linux kernel version specific cloud tools for version 5.15.0-184

Latest version: 5.15.0-184.194
Release: jammy (22.04)
Level: base
Repository: main
Head package: linux

Links


Download "linux-cloud-tools-5.15.0-184-generic"


Other versions of "linux-cloud-tools-5.15.0-184-generic" in Jammy

Repository Area Version
proposed main 5.15.0-184.194

Changelog

Version: 5.15.0-184.194 2026-05-25 22:08:53 UTC

 linux (5.15.0-184.194) jammy; urgency=medium
 .
   * jammy/linux: 5.15.0-184.194 -proposed tracker (LP: #2154219)
 .
   * Kernel regression (6.8.0-117.generic) (LP: #2153556)
     - net: bonding: update the slave array for broadcast mode
     - bonding: do not set usable_slaves for broadcast mode
 .
   * kernel null pointer BUG in 5.15 when disconnecting from cifs share
     (LP: #2150730)
     - SAUCE: cifs: fix null pointer dereference in find_ipc_from_server_path
 .
   * SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
     (LP: #2149767)
     - SUNRPC: Check if the xprt is connected before handling sysfs reads
     - SUNRPC: Do not dereference non-socket transports in sysfs
 .
   * SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
     (LP: #2149767) // CVE-2022-48816
     - SUNRPC: lock against ->sock changing during sysfs read
 .
   * iptables connlimit traffic loss (LP: #2149872)
     - netfilter: nf_conncount: fix tracking of connections from localhost
 .
   * Some powerpc test from ubuntu_kernel_selftests timeout with 45 seconds
     (LP: #2141536)
     - selftests/powerpc: Lower run time of count_stcx_fail test
     - selftests/powerpc: Give all tests 2 minutes timeout
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598)
     - x86/kfence: fix booting on 32bit non-PAE systems
     - platform/x86: intel_telemetry: Fix swapped arrays in PSS output
     - rbd: check for EOD after exclusive lock is ensured to be held
     - ARM: 9468/1: fix memset64() on big-endian
     - mm/kfence: randomize the freelist on initialization
     - Documentation: Remove bogus claim about del_timer_sync()
     - timers: Get rid of del_singleshot_timer_sync()
     - Documentation: Replace del_timer/del_timer_sync()
     - timers: Update the documentation to reflect on the new timer_shutdown()
       API
     - Bluetooth: hci_qca: Fix the teardown problem for real
     - binderfs: fix ida_alloc_max() upper bound
     - net: usb: sr9700: support devices with virtual driver CD
     - block,bfq: fix aux stat accumulation destination
     - HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL
     - HID: intel-ish-hid: Reset enum_devices_done before enumeration
     - HID: playstation: Center initial joystick axes to prevent spurious
       events
     - ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk
     - netfilter: replace -EEXIST with -EBUSY
     - HID: quirks: Add another Chicony HP 5MP Cameras to hid_ignore_list
     - HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30 (2d99:a101)
     - ring-buffer: Avoid softlockup in ring_buffer_resize() during memory free
     - wifi: mac80211: collect station statistics earlier when disconnect
     - ASoC: davinci-evm: Fix reference leak in davinci_evm_probe
     - ASoC: tlv320adcx140: Propagate error codes during probe
     - wifi: cfg80211: Fix bitrate calculation overflow for HE rates
     - wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt twice
     - platform/x86: intel_telemetry: Fix PSS event register mask
     - tipc: use kfree_sensitive() for session key material
     - hwmon: (occ) Mark occ_init_attribute() as __printf
     - nvmet-tcp: add an helper to free the cmd buffers
     - nvmet-tcp: fix memory leak when performing a controller reset
     - nvmet-tcp: fix regression in data_digest calculation
     - nvmet-tcp: don't map pages which can't come from HIGHMEM
     - tracing: Fix ftrace event field alignments
     - gve: Correct ethtool rx_dropped calculation
     - spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed
       transfer
     - spi: tegra210-quad: Move curr_xfer read inside spinlock
     - spi: tegra210-quad: Protect curr_xfer assignment in
       tegra_qspi_setup_transfer_one
     - spi: tegra210-quad: Protect curr_xfer clearing in
       tegra_qspi_non_combined_seq_xfer
     - nvmet-tcp: pass iov_len instead of sg->length to bvec_set_page()
     - riscv: Replace function-like macro by static inline function
     - Linux 5.15.200
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23182
     - spi: tegra: Fix a memory leak in tegra_slink_probe()
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23202
     - spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2025-71089
     - iommu: disable SVA when CONFIG_X86 is set
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2023-53673
     - Bluetooth: hci_event: call disconnect callback before deleting conn
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23262
     - gve: Fix stats report corruption on queue count change
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2025-40082
     - hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2025-37822
     - riscv: uprobes: Add missing fence.i after building the XOL buffer
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23190
     - ASoC: amd: fix memory leak in acp3x pdm dma ops
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23112
     - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23111
     - netfilter: nf_tables: fix inverted genmask check in
       nft_map_catchall_activate()
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23180
     - dpaa2-switch: add bounds check for if_id in IRQ handler
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23256
     - net: liquidio: Fix off-by-one error in VF setup_nic

Source diff to previous version
2153556 Kernel regression (6.8.0-117.generic)
2150730 kernel null pointer BUG in 5.15 when disconnecting from cifs share
2149767 SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
2149872 iptables connlimit traffic loss
2141536 Some powerpc test from ubuntu_kernel_selftests timeout with 45 seconds
2147598 Jammy update: v5.15.200 upstream stable release
2153962 net/rds: reset op_nents when zerocopy page pin fails
CVE-2022-48816 In the Linux kernel, the following vulnerability has been resolved: SUNRPC: lock against ->sock changing during sysfs read ->sock can be set to NUL
CVE-2026-23182 In the Linux kernel, the following vulnerability has been resolved: spi: tegra: Fix a memory leak in tegra_slink_probe() In tegra_slink_probe(), wh
CVE-2026-23202 In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer The curr_
CVE-2025-71089 In the Linux kernel, the following vulnerability has been resolved: iommu: disable SVA when CONFIG_X86 is set Patch series "Fix stale IOTLB entries
CVE-2023-53673 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: call disconnect callback before deleting conn In hci_cs_d
CVE-2026-23262 In the Linux kernel, the following vulnerability has been resolved: gve: Fix stats report corruption on queue count change The driver and the NIC s
CVE-2025-40082 In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() BUG: KASAN: slab-out-
CVE-2025-37822 In the Linux kernel, the following vulnerability has been resolved: riscv: uprobes: Add missing fence.i after building the XOL buffer The XOL (exec
CVE-2026-23190 In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: fix memory leak in acp3x pdm dma ops
CVE-2026-23112 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_i
CVE-2026-23111 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()
CVE-2026-23180 In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: add bounds check for if_id in IRQ handler The IRQ handler extract
CVE-2026-23256 In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup In setup_
CVE-2026-23257 In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup In setup_
CVE-2026-23258 In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Initialize netdev pointer before queue setup In setup_nic_device
CVE-2026-23206 In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: prevent ZERO_SIZE_PTR dereference when num_ifs is zero The driver
CVE-2026-23176 In the Linux kernel, the following vulnerability has been resolved: platform/x86: toshiba_haps: Fix memory leaks in add/remove routines toshiba_hap
CVE-2026-23216 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() In isc
CVE-2026-23193 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() In
CVE-2025-71220 In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_session_rpc_close() on error path in create_smb2_pipe()
CVE-2025-71222 In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: ensure skb headroom before skb_push This avoids occasional skb_un
CVE-2025-71224 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: ocb: skip rx_no_sta when interface is not joined ieee80211_ocb_
CVE-2025-68214 In the Linux kernel, the following vulnerability has been resolved: timers: Fix NULL function pointer race in timer_shutdown_sync() There is a race
CVE-2025-38201 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX Otherwise,
CVE-2026-23198 In the Linux kernel, the following vulnerability has been resolved: KVM: Don't clobber irqfd routing type when deassigning irqfd When deassigning a
CVE-2026-23272 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: unconditionally bump set->nelems before insertion In case
CVE-2026-31418 In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: drop logically empty buckets in mtype_del mtype_del() counts
CVE-2026-23278 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: always walk all pending catchall elements During transact
CVE-2026-46300 In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() c
CVE-2026-46333 In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fu
CVE-2026-43500 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA
CVE-2026-43284 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can atta
CVE-2026-31419 In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broadcast() bond_xmit_broadcast()
CVE-2026-31431 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commi
CVE-2026-31533 In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUS
CVE-2026-31504 In the Linux kernel, the following vulnerability has been resolved: net: fix fanout UAF in packet_release() via NETDEV_UP race `packet_release()` h

Version: 5.15.0-183.193 2026-05-23 02:08:51 UTC

 linux (5.15.0-183.193) jammy; urgency=medium
 .
   * jammy/linux: 5.15.0-183.193 -proposed tracker (LP: #2154032)
 .
   * kernel null pointer BUG in 5.15 when disconnecting from cifs share
     (LP: #2150730)
     - SAUCE: cifs: fix null pointer dereference in find_ipc_from_server_path
 .
   * SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
     (LP: #2149767)
     - SUNRPC: Check if the xprt is connected before handling sysfs reads
     - SUNRPC: Do not dereference non-socket transports in sysfs
 .
   * SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
     (LP: #2149767) // CVE-2022-48816
     - SUNRPC: lock against ->sock changing during sysfs read
 .
   * iptables connlimit traffic loss (LP: #2149872)
     - netfilter: nf_conncount: fix tracking of connections from localhost
 .
   * Some powerpc test from ubuntu_kernel_selftests timeout with 45 seconds
     (LP: #2141536)
     - selftests/powerpc: Lower run time of count_stcx_fail test
     - selftests/powerpc: Give all tests 2 minutes timeout
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598)
     - x86/kfence: fix booting on 32bit non-PAE systems
     - platform/x86: intel_telemetry: Fix swapped arrays in PSS output
     - rbd: check for EOD after exclusive lock is ensured to be held
     - ARM: 9468/1: fix memset64() on big-endian
     - mm/kfence: randomize the freelist on initialization
     - Documentation: Remove bogus claim about del_timer_sync()
     - timers: Get rid of del_singleshot_timer_sync()
     - Documentation: Replace del_timer/del_timer_sync()
     - timers: Update the documentation to reflect on the new timer_shutdown()
       API
     - Bluetooth: hci_qca: Fix the teardown problem for real
     - binderfs: fix ida_alloc_max() upper bound
     - net: usb: sr9700: support devices with virtual driver CD
     - block,bfq: fix aux stat accumulation destination
     - HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL
     - HID: intel-ish-hid: Reset enum_devices_done before enumeration
     - HID: playstation: Center initial joystick axes to prevent spurious
       events
     - ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk
     - netfilter: replace -EEXIST with -EBUSY
     - HID: quirks: Add another Chicony HP 5MP Cameras to hid_ignore_list
     - HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30 (2d99:a101)
     - ring-buffer: Avoid softlockup in ring_buffer_resize() during memory free
     - wifi: mac80211: collect station statistics earlier when disconnect
     - ASoC: davinci-evm: Fix reference leak in davinci_evm_probe
     - ASoC: tlv320adcx140: Propagate error codes during probe
     - wifi: cfg80211: Fix bitrate calculation overflow for HE rates
     - wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt twice
     - platform/x86: intel_telemetry: Fix PSS event register mask
     - tipc: use kfree_sensitive() for session key material
     - hwmon: (occ) Mark occ_init_attribute() as __printf
     - nvmet-tcp: add an helper to free the cmd buffers
     - nvmet-tcp: fix memory leak when performing a controller reset
     - nvmet-tcp: fix regression in data_digest calculation
     - nvmet-tcp: don't map pages which can't come from HIGHMEM
     - tracing: Fix ftrace event field alignments
     - gve: Correct ethtool rx_dropped calculation
     - spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed
       transfer
     - spi: tegra210-quad: Move curr_xfer read inside spinlock
     - spi: tegra210-quad: Protect curr_xfer assignment in
       tegra_qspi_setup_transfer_one
     - spi: tegra210-quad: Protect curr_xfer clearing in
       tegra_qspi_non_combined_seq_xfer
     - nvmet-tcp: pass iov_len instead of sg->length to bvec_set_page()
     - riscv: Replace function-like macro by static inline function
     - Linux 5.15.200
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23182
     - spi: tegra: Fix a memory leak in tegra_slink_probe()
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23202
     - spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2025-71089
     - iommu: disable SVA when CONFIG_X86 is set
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2023-53673
     - Bluetooth: hci_event: call disconnect callback before deleting conn
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23262
     - gve: Fix stats report corruption on queue count change
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2025-40082
     - hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2025-37822
     - riscv: uprobes: Add missing fence.i after building the XOL buffer
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23190
     - ASoC: amd: fix memory leak in acp3x pdm dma ops
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23112
     - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23111
     - netfilter: nf_tables: fix inverted genmask check in
       nft_map_catchall_activate()
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23180
     - dpaa2-switch: add bounds check for if_id in IRQ handler
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23256
     - net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23257
     - net: liquidio: Fix off-by-one error in PF setup_nic_devices() cl

Source diff to previous version
2150730 kernel null pointer BUG in 5.15 when disconnecting from cifs share
2149767 SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
2149872 iptables connlimit traffic loss
2141536 Some powerpc test from ubuntu_kernel_selftests timeout with 45 seconds
2147598 Jammy update: v5.15.200 upstream stable release
2153962 net/rds: reset op_nents when zerocopy page pin fails
CVE-2022-48816 In the Linux kernel, the following vulnerability has been resolved: SUNRPC: lock against ->sock changing during sysfs read ->sock can be set to NUL
CVE-2026-23182 In the Linux kernel, the following vulnerability has been resolved: spi: tegra: Fix a memory leak in tegra_slink_probe() In tegra_slink_probe(), wh
CVE-2026-23202 In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer The curr_
CVE-2025-71089 In the Linux kernel, the following vulnerability has been resolved: iommu: disable SVA when CONFIG_X86 is set Patch series "Fix stale IOTLB entries
CVE-2023-53673 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: call disconnect callback before deleting conn In hci_cs_d
CVE-2026-23262 In the Linux kernel, the following vulnerability has been resolved: gve: Fix stats report corruption on queue count change The driver and the NIC s
CVE-2025-40082 In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() BUG: KASAN: slab-out-
CVE-2025-37822 In the Linux kernel, the following vulnerability has been resolved: riscv: uprobes: Add missing fence.i after building the XOL buffer The XOL (exec
CVE-2026-23190 In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: fix memory leak in acp3x pdm dma ops
CVE-2026-23112 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_i
CVE-2026-23111 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()
CVE-2026-23180 In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: add bounds check for if_id in IRQ handler The IRQ handler extract
CVE-2026-23256 In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup In setup_
CVE-2026-23257 In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup In setup_
CVE-2026-23258 In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Initialize netdev pointer before queue setup In setup_nic_device
CVE-2026-23206 In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: prevent ZERO_SIZE_PTR dereference when num_ifs is zero The driver
CVE-2026-23176 In the Linux kernel, the following vulnerability has been resolved: platform/x86: toshiba_haps: Fix memory leaks in add/remove routines toshiba_hap
CVE-2026-23216 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() In isc
CVE-2026-23193 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() In
CVE-2025-71220 In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_session_rpc_close() on error path in create_smb2_pipe()
CVE-2025-71222 In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: ensure skb headroom before skb_push This avoids occasional skb_un
CVE-2025-71224 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: ocb: skip rx_no_sta when interface is not joined ieee80211_ocb_
CVE-2025-68214 In the Linux kernel, the following vulnerability has been resolved: timers: Fix NULL function pointer race in timer_shutdown_sync() There is a race
CVE-2025-38201 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX Otherwise,
CVE-2026-23198 In the Linux kernel, the following vulnerability has been resolved: KVM: Don't clobber irqfd routing type when deassigning irqfd When deassigning a
CVE-2026-23272 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: unconditionally bump set->nelems before insertion In case
CVE-2026-31418 In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: drop logically empty buckets in mtype_del mtype_del() counts
CVE-2026-23278 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: always walk all pending catchall elements During transact
CVE-2026-46333 In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fu
CVE-2026-43500 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA
CVE-2026-43284 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can atta
CVE-2026-31419 In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broadcast() bond_xmit_broadcast()
CVE-2026-31431 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commi
CVE-2026-31533 In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUS
CVE-2026-31504 In the Linux kernel, the following vulnerability has been resolved: net: fix fanout UAF in packet_release() via NETDEV_UP race `packet_release()` h

Version: 5.15.0-180.190 2026-05-09 01:08:45 UTC

 linux (5.15.0-180.190) jammy; urgency=medium
 .
   * jammy/linux: 5.15.0-180.190 -proposed tracker (LP: #2152007)
 .
   * kernel null pointer BUG in 5.15 when disconnecting from cifs share
     (LP: #2150730)
     - SAUCE: cifs: fix null pointer dereference in find_ipc_from_server_path
 .
   * SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
     (LP: #2149767)
     - SUNRPC: Check if the xprt is connected before handling sysfs reads
     - SUNRPC: Do not dereference non-socket transports in sysfs
 .
   * SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
     (LP: #2149767) // CVE-2022-48816
     - SUNRPC: lock against ->sock changing during sysfs read
 .
   * iptables connlimit traffic loss (LP: #2149872)
     - netfilter: nf_conncount: fix tracking of connections from localhost
 .
   * Some powerpc test from ubuntu_kernel_selftests timeout with 45 seconds
     (LP: #2141536)
     - selftests/powerpc: Lower run time of count_stcx_fail test
     - selftests/powerpc: Give all tests 2 minutes timeout
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598)
     - x86/kfence: fix booting on 32bit non-PAE systems
     - platform/x86: intel_telemetry: Fix swapped arrays in PSS output
     - rbd: check for EOD after exclusive lock is ensured to be held
     - ARM: 9468/1: fix memset64() on big-endian
     - mm/kfence: randomize the freelist on initialization
     - Documentation: Remove bogus claim about del_timer_sync()
     - timers: Get rid of del_singleshot_timer_sync()
     - Documentation: Replace del_timer/del_timer_sync()
     - timers: Update the documentation to reflect on the new timer_shutdown()
       API
     - Bluetooth: hci_qca: Fix the teardown problem for real
     - binderfs: fix ida_alloc_max() upper bound
     - net: usb: sr9700: support devices with virtual driver CD
     - block,bfq: fix aux stat accumulation destination
     - HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL
     - HID: intel-ish-hid: Reset enum_devices_done before enumeration
     - HID: playstation: Center initial joystick axes to prevent spurious
       events
     - ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk
     - netfilter: replace -EEXIST with -EBUSY
     - HID: quirks: Add another Chicony HP 5MP Cameras to hid_ignore_list
     - HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30 (2d99:a101)
     - ring-buffer: Avoid softlockup in ring_buffer_resize() during memory free
     - wifi: mac80211: collect station statistics earlier when disconnect
     - ASoC: davinci-evm: Fix reference leak in davinci_evm_probe
     - ASoC: tlv320adcx140: Propagate error codes during probe
     - wifi: cfg80211: Fix bitrate calculation overflow for HE rates
     - wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt twice
     - platform/x86: intel_telemetry: Fix PSS event register mask
     - tipc: use kfree_sensitive() for session key material
     - hwmon: (occ) Mark occ_init_attribute() as __printf
     - nvmet-tcp: add an helper to free the cmd buffers
     - nvmet-tcp: fix memory leak when performing a controller reset
     - nvmet-tcp: fix regression in data_digest calculation
     - nvmet-tcp: don't map pages which can't come from HIGHMEM
     - tracing: Fix ftrace event field alignments
     - gve: Correct ethtool rx_dropped calculation
     - spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed
       transfer
     - spi: tegra210-quad: Move curr_xfer read inside spinlock
     - spi: tegra210-quad: Protect curr_xfer assignment in
       tegra_qspi_setup_transfer_one
     - spi: tegra210-quad: Protect curr_xfer clearing in
       tegra_qspi_non_combined_seq_xfer
     - nvmet-tcp: pass iov_len instead of sg->length to bvec_set_page()
     - riscv: Replace function-like macro by static inline function
     - Linux 5.15.200
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23182
     - spi: tegra: Fix a memory leak in tegra_slink_probe()
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23202
     - spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2025-71089
     - iommu: disable SVA when CONFIG_X86 is set
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2023-53673
     - Bluetooth: hci_event: call disconnect callback before deleting conn
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23262
     - gve: Fix stats report corruption on queue count change
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2025-40082
     - hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2025-37822
     - riscv: uprobes: Add missing fence.i after building the XOL buffer
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23190
     - ASoC: amd: fix memory leak in acp3x pdm dma ops
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23112
     - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23111
     - netfilter: nf_tables: fix inverted genmask check in
       nft_map_catchall_activate()
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23180
     - dpaa2-switch: add bounds check for if_id in IRQ handler
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23256
     - net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup
 .
   * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
     CVE-2026-23257
     - net: liquidio: Fix off-by-one error in PF setup_nic_devices() cl

Source diff to previous version
2150730 kernel null pointer BUG in 5.15 when disconnecting from cifs share
2149767 SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
2149872 iptables connlimit traffic loss
2141536 Some powerpc test from ubuntu_kernel_selftests timeout with 45 seconds
2147598 Jammy update: v5.15.200 upstream stable release
CVE-2022-48816 In the Linux kernel, the following vulnerability has been resolved: SUNRPC: lock against ->sock changing during sysfs read ->sock can be set to NUL
CVE-2026-23182 In the Linux kernel, the following vulnerability has been resolved: spi: tegra: Fix a memory leak in tegra_slink_probe() In tegra_slink_probe(), wh
CVE-2026-23202 In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer The curr_
CVE-2025-71089 In the Linux kernel, the following vulnerability has been resolved: iommu: disable SVA when CONFIG_X86 is set Patch series "Fix stale IOTLB entries
CVE-2023-53673 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: call disconnect callback before deleting conn In hci_cs_d
CVE-2026-23262 In the Linux kernel, the following vulnerability has been resolved: gve: Fix stats report corruption on queue count change The driver and the NIC s
CVE-2025-40082 In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() BUG: KASAN: slab-out-
CVE-2025-37822 In the Linux kernel, the following vulnerability has been resolved: riscv: uprobes: Add missing fence.i after building the XOL buffer The XOL (exec
CVE-2026-23190 In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: fix memory leak in acp3x pdm dma ops
CVE-2026-23112 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_i
CVE-2026-23111 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()
CVE-2026-23180 In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: add bounds check for if_id in IRQ handler The IRQ handler extract
CVE-2026-23256 In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup In setup_
CVE-2026-23257 In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup In setup_
CVE-2026-23258 In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Initialize netdev pointer before queue setup In setup_nic_device
CVE-2026-23206 In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: prevent ZERO_SIZE_PTR dereference when num_ifs is zero The driver
CVE-2026-23176 In the Linux kernel, the following vulnerability has been resolved: platform/x86: toshiba_haps: Fix memory leaks in add/remove routines toshiba_hap
CVE-2026-23216 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() In isc
CVE-2026-23193 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() In
CVE-2025-71220 In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_session_rpc_close() on error path in create_smb2_pipe()
CVE-2025-71222 In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: ensure skb headroom before skb_push This avoids occasional skb_un
CVE-2025-71224 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: ocb: skip rx_no_sta when interface is not joined ieee80211_ocb_
CVE-2025-68214 In the Linux kernel, the following vulnerability has been resolved: timers: Fix NULL function pointer race in timer_shutdown_sync() There is a race
CVE-2025-38201 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX Otherwise,
CVE-2026-23198 In the Linux kernel, the following vulnerability has been resolved: KVM: Don't clobber irqfd routing type when deassigning irqfd When deassigning a
CVE-2026-23272 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: unconditionally bump set->nelems before insertion In case
CVE-2026-31418 In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: drop logically empty buckets in mtype_del mtype_del() counts
CVE-2026-23278 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: always walk all pending catchall elements During transact
CVE-2026-31419 In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broadcast() bond_xmit_broadcast()
CVE-2026-31431 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commi
CVE-2026-31533 In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUS
CVE-2026-31504 In the Linux kernel, the following vulnerability has been resolved: net: fix fanout UAF in packet_release() via NETDEV_UP race `packet_release()` h

Version: 5.15.0-178.188 2026-04-12 10:09:50 UTC

 linux (5.15.0-178.188) jammy; urgency=medium
 .
   * jammy/linux: 5.15.0-178.188 -proposed tracker (LP: #2148097)
 .
   * Canonical Kmod 2025 key rotation (LP: #2147447)
     - [Packaging] ubuntu-compatible-signing -- make Ubuntu-Compatible-Signing
       extensible
     - [Packaging] ubuntu-compatible-signing -- allow consumption of positive
       certs
     - [Packaging] ubuntu-compatible-signing -- report the livepatch:2025 key
     - [Config] prepare for Canonical Kmod key rotation
     - [Packaging] ubuntu-compatible-signing -- report the kmod:2025 key
 .
   * ADATA SU680 causes repeated SATA resets and I/O errors on Ubuntu unless
     link power management is forced to max_performance (LP: #2144060)
     - ata: libata-core: disable LPM on ADATA SU680 SSD
 .
   * CVE-2024-50060
     - io_uring: check if we need to reschedule during overflow flush
 .
   * CVE-2024-35862
     - smb: client: fix potential UAF in smb2_is_network_name_deleted()
 .
   * CVE-2026-23274
     - netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
 .
   * CVE-2026-23351
     - netfilter: nf_tables: de-constify set commit ops function argument
     - netfilter: nft_set_pipapo: split gc into unlink and reclaim phase
 .
   * macvlan: observe an RCU grace period in macvlan_common_newlink() error
     path (LP: #2144380) // CVE-2026-23209
     - macvlan: observe an RCU grace period in macvlan_common_newlink() error
       path
 .
   * CVE-2023-2640 // CVE-2023-32629
     - SAUCE: overlayfs: default to userxattr when mounted from non initial
       user namespace
 .
   * CVE-2023-2640 // CVE-2023-2640 and CVE-2023-32629. // CVE-2023-32629
     - SAUCE: Revert "UBUNTU: SAUCE: overlayfs: Skip permission checking for
       trusted.overlayfs.* xattrs"
 .
   * CVE-2026-23112
     - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec

Source diff to previous version
2147447 Canonical Kmod 2025 key rotation
2144060 ADATA SU680 causes repeated SATA resets and I/O errors on Ubuntu unless link power management is forced to max_performance
2144380 macvlan: observe an RCU grace period in macvlan_common_newlink() error path
CVE-2024-50060 In the Linux kernel, the following vulnerability has been resolved: io_uring: check if we need to reschedule during overflow flush In terms of norm
CVE-2024-35862 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_network_name_deleted() Skip sessions
CVE-2026-23274 In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels IDLETIMER revi
CVE-2026-23351 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: split gc into unlink and reclaim phase Yiming Qian r
CVE-2026-23209 In the Linux kernel, the following vulnerability has been resolved: macvlan: fix error recovery in macvlan_common_newlink() valis provided a nice r
CVE-2023-2640 On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overl ...
CVE-2023-32629 Local privilege escalation vulnerability in Ubuntu Kernels overlayfs o ...
CVE-2026-23112 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_i

Version: 5.15.0-176.186 2026-03-13 15:09:19 UTC

 linux (5.15.0-176.186) jammy; urgency=medium
 .
   * jammy/linux: 5.15.0-176.186 -proposed tracker (LP: #2143539)
 .
   * Jammy update: v5.15.199 upstream stable release (LP: #2143343)
     - nvmet-tcp: remove boilerplate code
     - SAUCE: Fix skb_vlan_inet_prepare() usage
     - net: update netdev_lock_{type,name}
     - vsock/test: add a final full barrier after run all tests
     - net/mlx5e: Restore destroying state bit after profile cleanup
     - selftests: drv-net: fix RPS mask handling for high CPU numbers
     - ASoC: tlv320adcx140: fix word length
     - textsearch: describe @list member in ts_ops search
     - mm, kfence: describe @slab parameter in __kfence_obj_info()
     - dmaengine: xilinx_dma: Fix uninitialized addr_width when
       "xlnx,addrwidth" property is missing
     - phy: broadcom: ns-usb3: Fix Wvoid-pointer-to-enum-cast warning (again)
     - HID: usbhid: paper over wrong bNumDescriptor field
     - ALSA: pcm: Improve the fix for race of buffer access at PCM OSS layer
     - x86/kaslr: Recognize all ZONE_DEVICE users as physaddr consumers
     - phy: rockchip: inno-usb2: fix disconnection in gadget mode
     - phy: rockchip: inno-usb2: fix communication disruption in gadget mode
     - phy: tegra: xusb: Explicitly configure HS_DISCON_LEVEL to 0x7
     - usb: dwc3: Check for USB4 IP_NAME
     - USB: OHCI/UHCI: Add soft dependencies on ehci_platform
     - USB: serial: option: add Telit LE910 MBIM composition
     - USB: serial: ftdi_sio: add support for PICAXE AXE027 cable
     - nvme-pci: disable secondary temp for Wodposit WPBSNM8
     - hrtimer: Fix softirq base check in update_needs_ipi()
     - EDAC/x38: Fix a resource leak in x38_probe1()
     - EDAC/i3200: Fix a resource leak in i3200_probe1()
     - x86/resctrl: Add missing resctrl initialization for Hygon
     - x86/resctrl: Fix memory bandwidth counter width for Hygon
     - mm/page_alloc: make percpu_pagelist_high_fraction reads lock-free
     - drm/nouveau/disp/nv50-: Set lock_core in curs507a_prepare
     - drm/vmwgfx: Fix an error return check in vmw_compat_shader_add()
     - dmaengine: sh: rz-dmac: Fix rz_dmac_terminate_all()
     - dmaengine: ti: dma-crossbar: fix device leak on dra7x route allocation
     - dmaengine: ti: k3-udma: fix device leak on udma lookup
     - posix-clock: introduce posix_clock_context concept
     - Fix memory leak in posix_clock_open()
     - posix-clock: Store file pointer in struct posix_clock_context
     - ptp: Add PHC file mode checks. Allow RO adjtime() without FMODE_WRITE.
     - testptp: add option to shift clock by nanoseconds
     - testptp: Add support for testing ptp_clock_info .adjphase callback
     - selftests/ptp: Add -x option for testing PTP_SYS_OFFSET_EXTENDED
     - selftests/ptp: Add -X option for testing PTP_SYS_OFFSET_PRECISE
     - ptp: add testptp mask test
     - selftest/ptp: update ptp selftest to exercise the gettimex options
     - testptp: Add option to open PHC in readonly mode
     - net: usb: dm9601: remove broken SR9700 support
     - amd-xgbe: avoid misleading per-packet error log
     - netlink: add a proto specification for FOU
     - net: fou: rename the source for linking
     - net: fou: use policy and operation tables generated from the spec
     - comedi: dmm32at: serialize use of paged registers
     - w1: fix redundant counter decrement in w1_attach_slave_device()
     - Revert "nfc/nci: Add the inconsistency check between the input data
       length and count"
     - Input: i8042 - add quirks for MECHREVO Wujie 15X Pro
     - Input: i8042 - add quirk for ASUS Zenbook UX425QA_UM425QA
     - scsi: storvsc: Process unsupported MODE_SENSE_10
     - x86/kfence: avoid writing L1TF-vulnerable PTEs
     - staging:iio:adc:ad7280a: Register define cleanup.
     - iio: adc: ad7280a: handle spi_setup() errors in probe()
     - ALSA: usb: Increase volume range that triggers a warning
     - net: hns3: fix wrong GENMASK() for HCLGE_FD_AD_COUNTER_NUM_M
     - net: hns3: fix the HCLGE_FD_AD_NXT_KEY error setting issue
     - usbnet: limit max_mtu based on device's hard_mtu
     - drm/amd/pm: Don't clear SI SMC table when setting power limit
     - drm/amd/pm: Workaround SI powertune issue on Radeon 430 (v2)
     - octeontx2-af: Fix error handling
     - x86: make page fault handling disable interrupts properly
     - of: fix reference count leak in of_alias_scan()
     - iio: adc: ad9467: fix ad9434 vref mask
     - iio: dac: ad5686: add AD5695R to ad5686_chip_info_tbl
     - mmc: rtsx_pci_sdmmc: implement sdmmc_card_busy function
     - wifi: mwifiex: Fix a loop in mwifiex_update_ampdu_rxwinsize()
     - octeontx2: Fix otx2_dma_map_page() error return code
     - slimbus: core: fix runtime PM imbalance on report present
     - perf/x86/intel: Do not enable BTS for guests
     - net/mlx5: Fix memory leak in esw_acl_ingress_lgcy_setup()
     - net: mvpp2: cls: Fix memory leak in mvpp2_ethtool_cls_rule_ins()
     - ipv6: use the right ifindex when replying to icmpv6 from localhost
     - ice: stop counting UDP csum mismatch as rx_errors
     - net/mlx5: Add HW definitions of vport debug counters
     - net/mlx5e: Expose rx_oversize_pkts_buffer counter
     - net/mlx5e: Report rx_discards_phy via rx_dropped
     - net/mlx5e: Account for netdev stats in ndo_get_stats64
     - net: bridge: fix static key check
     - scsi: firewire: sbp-target: Fix overflow in sbp_make_tpg()
     - gpiolib: acpi: use BIT_ULL() for u64 mask in address space handler
     - dma/pool: distinguish between missing and exhausted atomic pools
     - ASoC: fsl: imx-card: Do not force slot width to sample width
     - scsi: be2iscsi: Fix a memory leak in beiscsi_boot_get_sinfo()
     - scsi: qla2xxx: edif: Fix dma_free_coherent() size
     - mptcp: only reset subflow errors when propagated
     - net: Add locking to protect skb->dev access in ip_output
     - comedi: Fix getting range information for subdevices 16 to 255
     - of: platform: Use default match tabl

2143343 Jammy update: v5.15.199 upstream stable release
2143033 ADT test for linux package failed with \
2141276 efi: Fix swapped arguments to bsearch() in efi_status_to_*() SAUCE patch
CVE-2025-68340 In the Linux kernel, the following vulnerability has been resolved: team: Move team device type change at the end of team_port_add Attempting to ad
CVE-2026-23170 In the Linux kernel, the following vulnerability has been resolved: drm/imx/tve: fix probe device leak Make sure to drop the reference taken to the
CVE-2026-23075 In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: esd_usb_read_bulk_callback(): fix URB memory leak Fix similar mem
CVE-2025-38408 In the Linux kernel, the following vulnerability has been resolved: genirq/irq_sim: Initialize work context pointers properly Initialize `ops` memb
CVE-2023-54207 In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Correct devm device reference for hidinput input_dev name Referen
CVE-2023-53520 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix hci_suspend_sync crash If hci_unregister_dev() frees the hci_dev
CVE-2025-38125 In the Linux kernel, the following vulnerability has been resolved: net: stmmac: make sure that ptp_rate is not 0 before configuring EST If the ptp
CVE-2025-40164 In the Linux kernel, the following vulnerability has been resolved: usbnet: Fix using smp_processor_id() in preemptible code warnings Syzbot report
CVE-2025-38232 In the Linux kernel, the following vulnerability has been resolved: NFSD: fix race between nfsd registration and exports_proc As of now nfsd calls
CVE-2023-53662 In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leaks in ext4_fname_{setup_filename,prepare_lookup} If the fil
CVE-2025-38057 In the Linux kernel, the following vulnerability has been resolved: espintcp: fix skb leaks A few error paths are missing a kfree_skb.
CVE-2023-53421 In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: Reinit blkg_iostat_set after clearing in blkcg_reset_stats() When b
CVE-2025-68365 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize allocated memory before use KMSAN reports: Multiple uninit
CVE-2025-68817 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency Under hig
CVE-2022-50390 In the Linux kernel, the following vulnerability has been resolved: drm/ttm: fix undefined behavior in bit shift for TTM_TT_FLAG_PRIV_POPULATED Shi
CVE-2025-68211 In the Linux kernel, the following vulnerability has been resolved: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item Curr
CVE-2026-23093 In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbd: fix dma_unmap_sg() nents The dma_unmap_sg() functions should be ca
CVE-2026-23078 In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Fix buffer overflow in config retrieval The scarlett2_usb_get_
CVE-2025-71186 In the Linux kernel, the following vulnerability has been resolved: dmaengine: stm32: dmamux: fix device leak on route allocation Make sure to drop
CVE-2025-71197 In the Linux kernel, the following vulnerability has been resolved: w1: therm: Fix off-by-one buffer overflow in alarms_store The sysfs buffer pass
CVE-2026-23087 In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Fix potential memory leak in scsiback_remove() Memory allo
CVE-2025-40149 In the Linux kernel, the following vulnerability has been resolved: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). get_netdev_
CVE-2026-23167 In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix race between rfkill and nci_unregister_device(). syzbot reported
CVE-2026-23150 In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: Fix memleak in nfc_llcp_send_ui_frame(). syzbot reported various mem
CVE-2026-23164 In the Linux kernel, the following vulnerability has been resolved: rocker: fix memory leak in rocker_world_port_post_fini() In rocker_world_port_p
CVE-2026-23146 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix null-ptr-deref in hci_uart_write_work hci_uart_set_pro
CVE-2025-38591 In the Linux kernel, the following vulnerability has been resolved: bpf: Reject narrower access to pointer ctx fields The following BPF program, si
CVE-2025-68725 In the Linux kernel, the following vulnerability has been resolved: bpf: Do not let BPF test infra emit invalid GSO types to stack Yinhao et al. re
CVE-2026-23097 In the Linux kernel, the following vulnerability has been resolved: migrate: correct lock ordering for hugetlb file folios Syzbot has found a deadl
CVE-2026-23108 In the Linux kernel, the following vulnerability has been resolved: can: usb_8dev: usb_8dev_read_bulk_callback(): fix URB memory leak Fix similar m
CVE-2026-23080 In the Linux kernel, the following vulnerability has been resolved: can: mcba_usb: mcba_usb_read_bulk_callback(): fix URB memory leak Fix similar m
CVE-2026-23061 In the Linux kernel, the following vulnerability has been resolved: can: kvaser_usb: kvaser_usb_read_bulk_callback(): fix URB memory leak Fix simil
CVE-2026-23058 In the Linux kernel, the following vulnerability has been resolved: can: ems_usb: ems_usb_read_bulk_callback(): fix URB memory leak Fix similar mem
CVE-2026-23085 In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Avoid truncating memory addresses On 32-bit machines with C
CVE-2026-23098 In the Linux kernel, the following vulnerability has been resolved: netrom: fix double-free in nr_route_frame() In nr_route_frame(), old_skb is imm
CVE-2026-23063 In the Linux kernel, the following vulnerability has been resolved: uacce: ensure safe queue release with state management Directly calling `put_qu
CVE-2026-23056 In the Linux kernel, the following vulnerability has been resolved: uacce: implement mremap in uacce_vm_ops to return -EPERM The current uacce_vm_o
CVE-2026-23096 In the Linux kernel, the following vulnerability has been resolved: uacce: fix cdev handling in the cleanup path When cdev_device_add fails, it int
CVE-2026-23091 In the Linux kernel, the following vulnerability has been resolved: intel_th: fix device leak on output open() Make sure to drop the reference take
CVE-2026-23090 In the Linux kernel, the following vulnerability has been resolved: slimbus: core: fix device reference leak on report present Slimbus devices can
CVE-2026-23128 In the Linux kernel, the following vulnerability has been resolved: arm64: Set __nocfi on swsusp_arch_resume() A DABT is reported[1] on an android
CVE-2026-23073 In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: Fix memory corruption due to not set vif driver data size The struct
CVE-2026-23133 In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: fix dma_free_coherent() pointer dma_alloc_coherent() allocates a
CVE-2026-23089 In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free() When snd_usb_create
CVE-2026-23076 In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Fix potential OOB access in audio mixer handling In the audio mixe
CVE-2025-71199 In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91-sama5d2_adc: Fix potential use-after-free in sama5d2_adc driver
CVE-2026-23101 In the Linux kernel, the following vulnerability has been resolved: leds: led-class: Only Add LED to leds_list when it is fully ready Before this c
CVE-2026-23064 In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ife: avoid possible NULL deref tcf_ife_encode() must make sure i
CVE-2026-23119 In the Linux kernel, the following vulnerability has been resolved: bonding: provide a net pointer to __skb_flow_dissect() After 3cbf4ffba5ee ("net
CVE-2026-23084 In the Linux kernel, the following vulnerability has been resolved: be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list When the param
CVE-2026-23124 In the Linux kernel, the following vulnerability has been resolved: ipv6: annotate data-race in ndisc_router_discovery() syzbot found that ndisc_ro
CVE-2026-23121 In the Linux kernel, the following vulnerability has been resolved: mISDN: annotate data-race around dev->work dev->work can re read locklessly in
CVE-2026-23071 In the Linux kernel, the following vulnerability has been resolved: regmap: Fix race condition in hwspinlock irqsave routine Previously, the addres
CVE-2026-23105 In the Linux kernel, the following vulnerability has been resolved: net/sched: qfq: Use cl_is_active to determine whether class is active in qfq_rm_
CVE-2026-23103 In the Linux kernel, the following vulnerability has been resolved: ipvlan: Make the addrs_lock be per port Make the addrs_lock be per port, not pe
CVE-2026-23120 In the Linux kernel, the following vulnerability has been resolved: l2tp: avoid one data-race in l2tp_tunnel_del_work() We should read sk->sk_socke
CVE-2026-23083 In the Linux kernel, the following vulnerability has been resolved: fou: Don't allow 0 for FOU_ATTR_IPPROTO. fou_udp_recv() has the same problem me
CVE-2026-23095 In the Linux kernel, the following vulnerability has been resolved: gue: Fix skb memleak with inner IP protocol 0. syzbot reported skb memleak belo
CVE-2026-23125 In the Linux kernel, the following vulnerability has been resolved: sctp: move SCTP_CMD_ASSOC_SHKEY right after SCTP_CMD_PEER_INIT A null-ptr-deref
CVE-2026-23099 In the Linux kernel, the following vulnerability has been resolved: bonding: limit BOND_MODE_8023AD to Ethernet devices BOND_MODE_8023AD makes sens
CVE-2025-71194 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock in wait_current_trans() due to ignored transaction type Whe
CVE-2025-71185 In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: dma-crossbar: fix device leak on am335x route allocation Make su
CVE-2026-23026 In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() Fix a memory l
CVE-2025-71188 In the Linux kernel, the following vulnerability has been resolved: dmaengine: lpc18xx-dmamux: fix device leak on route allocation Make sure to dro
CVE-2025-71163 In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix device leaks on compat bind and unbind Make sure to drop t
CVE-2025-71190 In the Linux kernel, the following vulnerability has been resolved: dmaengine: bcm-sba-raid: fix device leak on probe Make sure to drop the referen
CVE-2025-71191 In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_hdmac: fix device leak on of_dma_xlate() Make sure to drop the re
CVE-2026-23049 In the Linux kernel, the following vulnerability has been resolved: drm/panel-simple: fix connector type for DataImage SCF0700C48GGU18 panel The co
CVE-2026-23145 In the Linux kernel, the following vulnerability has been resolved: ext4: fix iloc.bh leak in ext4_xattr_inode_update_ref The error branch for ext4
CVE-2026-22997 In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon rece
CVE-2026-23033 In the Linux kernel, the following vulnerability has been resolved: dmaengine: omap-dma: fix dma_pool resource leak in error paths The dma_pool cre
CVE-2025-71196 In the Linux kernel, the following vulnerability has been resolved: phy: stm32-usphyc: Fix off by one in probe() The "index" variable is used as an
CVE-2025-71162 In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-after-free bug exists in the Te
CVE-2026-22999 In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: do not free existing class in qfq_change_class() Fixes qfq_
CVE-2026-23011 In the Linux kernel, the following vulnerability has been resolved: ipv4: ip_gre: make ipgre_header() robust Analog to commit db5b4e39c4e6 ("ip6_gr
CVE-2026-23001 In the Linux kernel, the following vulnerability has been resolved: macvlan: fix possible UAF in macvlan_forward_source() Add RCU protection on (st
CVE-2026-23003 In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() Blamed commit did no
CVE-2026-22998 In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec Commit efa
CVE-2026-23037 In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: allow partial RX URB allocation to succeed When es58x_alloc_rx
CVE-2026-23038 In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_all
CVE-2026-23111 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()
CVE-2026-23209 In the Linux kernel, the following vulnerability has been resolved: macvlan: fix error recovery in macvlan_common_newlink() valis provided a nice r
CVE-2025-37849 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fa
CVE-2026-23074 In the Linux kernel, the following vulnerability has been resolved: net/sched: Enforce that teql can only be used as root qdisc Design intent of te
CVE-2026-23060 In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec au



About   -   Send Feedback to @ubuntu_updates