UbuntuUpdates.org

Package "linux-headers-6.17.0-11-generic"

This package belongs to a PPA: Canonical Kernel Team

Name: linux-headers-6.17.0-11-generic

Description:

Linux kernel headers for version 6.17.0

Latest version: 6.17.0-11.11~24.04.1
Release: noble (24.04)
Level: base
Repository: main
Head package: linux-hwe-6.17

Links


Download "linux-headers-6.17.0-11-generic"


Other versions of "linux-headers-6.17.0-11-generic" in Noble

No other version of this package is available in the Noble release.

Changelog

Version: 6.17.0-11.11~24.04.1 2025-12-20 10:09:04 UTC

 linux-hwe-6.17 (6.17.0-11.11~24.04.1) noble; urgency=medium
 .
   * noble/linux-hwe-6.17: 6.17.0-11.11~24.04.1 -proposed tracker (LP: #2136913)
 .
   [ Ubuntu: 6.17.0-11.11 ]
 .
   * questing/linux: 6.17.0-11.11 -proposed tracker (LP: #2136911)
   * Enable PMF on AMD HPT/STX/KRK (LP: #2125022)
     - platform/x86/amd/pmf: Add support for adjusting PMF PPT and PPT APU
       thresholds
     - platform/x86/amd/pmf: Extend custom BIOS inputs for more policies
     - platform/x86/amd/pmf: Update ta_pmf_action structure member
     - platform/x86/amd/pmf: Add helper to verify BIOS input notifications are
       enable/disable
     - platform/x86/amd/pmf: Add custom BIOS input support for AMD_CPU_ID_PS
     - platform/x86/amd/pmf: Preserve custom BIOS inputs for evaluating the
       policies
     - platform/x86/amd/pmf: Call enact function sooner to process early
       pending requests
     - platform/x86/amd/pmf: Add debug logs for pending requests and custom
       BIOS inputs
   * Questing update: v6.17.8 upstream stable release (LP: #2136850)
     - iommufd/selftest: Fix ioctl return value in _test_cmd_trigger_vevents()
     - drm/mediatek: Add pm_runtime support for GCE power control
     - drm/i915: Fix conversion between clock ticks and nanoseconds
     - drm/amdgpu: set default gfx reset masks for gfx6-8
     - drm/amd/display: Don't stretch non-native images by default in eDP
     - smb: client: fix refcount leak in smb2_set_path_attr
     - iommufd: Make vfio_compat's unmap succeed if the range is already empty
     - futex: Optimize per-cpu reference counting
     - drm/amd: Fix suspend failure with secure display TA
     - drm/xe: Move declarations under conditional branch
     - drm/xe: Do clean shutdown also when using flr
     - drm/amd/display: Add pixel_clock to amd_pp_display_configuration
     - drm/amd/pm: Use pm_display_cfg in legacy DPM (v2)
     - drm/amd/display: Disable fastboot on DCE 6 too
     - drm/amd/pm: Disable MCLK switching on SI at high pixel clocks
     - drm/amd: Disable ASPM on SI
     - arm64: kprobes: check the return value of set_memory_rox()
     - compiler_types: Move unused static inline functions warning to W=2
     - riscv: Build loader.bin exclusively for Canaan K210
     - RISC-V: clear hot-unplugged cores from all task mm_cpumasks to avoid
       rfence errors
     - riscv: acpi: avoid errors caused by probing DT devices when ACPI is used
     - fs: return EOPNOTSUPP from file_setattr/file_getattr syscalls
     - ASoC: nau8821: Avoid unnecessary blocking in IRQ handler
     - NFS4: Fix state renewals missing after boot
     - drm/amdkfd: fix suspend/resume all calls in mes based eviction path
     - NFS4: Apply delay_retrans to async operations
     - HID: intel-thc-hid: intel-quickspi: Add ARL PCI Device Id's
     - HID: quirks: avoid Cooler Master MM712 dongle wakeup bug
     - ixgbe: handle IXGBE_VF_GET_PF_LINK_STATE mailbox operation
     - HID: nintendo: Wait longer for initial probe
     - NFS: check if suid/sgid was cleared after a write as needed
     - HID: quirks: Add ALWAYS_POLL quirk for VRS R295 steering wheel
     - io_uring: fix unexpected placement on same size resizing
     - HID: logitech-hidpp: Add HIDPP_QUIRK_RESET_HI_RES_SCROLL
     - ASoC: max98090/91: fixed max98091 ALSA widget powering up/down
     - ALSA: hda/realtek: Fix mute led for HP Omen 17-cb0xxx
     - ixgbe: handle IXGBE_VF_FEATURES_NEGOTIATE mbox cmd
     - wifi: ath11k: zero init info->status in wmi_process_mgmt_tx_comp()
     - selftests: net: local_termination: Wait for interfaces to come up
     - net: fec: correct rx_bytes statistic for the case SHIFT16 is set
     - net: phy: micrel: Introduce lanphy_modify_page_reg
     - net: phy: micrel: Replace hardcoded pages with defines
     - net: phy: micrel: lan8814 fix reset of the QSGMII interface
     - rust: Add -fno-isolate-erroneous-paths-dereference to
       bindgen_skip_c_flags
     - NFSD: Skip close replay processing if XDR encoding fails
     - Bluetooth: 6lowpan: fix BDADDR_LE vs ADDR_LE_DEV address type confusion
     - Bluetooth: 6lowpan: Don't hold spin lock over sleeping functions
     - Bluetooth: hci_conn: Fix not cleaning up PA_LINK connections
     - net: dsa: tag_brcm: do not mark link local traffic as offloaded
     - net/smc: fix mismatch between CLC header and proposal
     - net/handshake: Fix memory leak in tls_handshake_accept()
     - net: ethernet: ti: am65-cpsw-qos: fix IET verify/response timeout
     - net: ethernet: ti: am65-cpsw-qos: fix IET verify retry mechanism
     - net: mdio: fix resource leak in mdiobus_register_device()
     - wifi: mac80211: skip rate verification for not captured PSDUs
     - Bluetooth: hci_event: Fix not handling PA Sync Lost event
     - net/mlx5e: Fix missing error assignment in mlx5e_xfrm_add_state()
     - net/mlx5e: Fix maxrate wraparound in threshold between units
     - net/mlx5e: Fix wraparound in rate limiting for values above 255 Gbps
     - net/mlx5e: Fix potentially misleading debug message
     - net/mlx5: Fix typo of MLX5_EQ_DOORBEL_OFFSET
     - net/mlx5: Store the global doorbell in mlx5_priv
     - net/mlx5e: Prepare for using different CQ doorbells
     - net_sched: limit try_bulk_dequeue_skb() batches
     - wifi: iwlwifi: mvm: fix beacon template/fixed rate
     - wifi: iwlwifi: mld: always take beacon ies in link grading
     - virtio-net: fix incorrect flags recording in big mode
     - hsr: Fix supervision frame sending on HSRv0
     - hsr: Follow standard for HSRv0 supervision frames
     - ACPI: CPPC: Detect preferred core availability on online CPUs
     - ACPI: CPPC: Check _CPC validity for only the online CPUs
     - ACPI: CPPC: Perform fast check switch only for online CPUs
     - ACPI: CPPC: Limit perf ctrs in PCC check only to online CPUs
     - cpufreq: intel_pstate: Check IDA only before MSR_IA32_PERF_CTL writes
     - Bluetooth: L2CAP: export l2cap_chan_hold for modules
     - io_uring/rsrc: don't use blk_rq_nr_

Source diff to previous version
2136850 Questing update: v6.17.8 upstream stable release
2136833 Questing update: v6.17.8 upstream stable release
2136813 Questing update: v6.17.7 upstream stable release
CVE-2025-68204 In the Linux kernel, the following vulnerability has been resolved: pmdomain: arm: scmi: Fix genpd leak on provider registration failure If of_genp
CVE-2025-68203 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix lock warning in amdgpu_userq_fence_driver_process Fix a potenti
CVE-2025-40267 In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: ensure allocated iovec gets cleared for early failure A previous c
CVE-2025-68198 In the Linux kernel, the following vulnerability has been resolved: crash: fix crashkernel resource shrink When crashkernel is configured with a hi
CVE-2025-68199 In the Linux kernel, the following vulnerability has been resolved: codetag: debug: handle existing CODETAG_EMPTY in mark_objexts_empty for slabobj_
CVE-2025-40268 In the Linux kernel, the following vulnerability has been resolved: cifs: client: fix memory leak in smb3_fs_context_parse_param The user calls fsc
CVE-2025-40269 In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential overflow of PCM transfer buffer The PCM stream d
CVE-2025-68205 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/hdmi: Fix breakage at probing nvhdmi-mcp driver After restructuring a
CVE-2025-40270 In the Linux kernel, the following vulnerability has been resolved: mm, swap: fix potential UAF issue for VMA readahead Since commit 78524b05f1a3 (
CVE-2025-40271 In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through
CVE-2025-40272 In the Linux kernel, the following vulnerability has been resolved: mm/secretmem: fix use-after-free race in fault handler When a page fault occurs
CVE-2025-68245 In the Linux kernel, the following vulnerability has been resolved: net: netpoll: fix incorrect refcount handling causing incorrect cleanup commit
CVE-2025-68240 In the Linux kernel, the following vulnerability has been resolved: nilfs2: avoid having an active sc_timer before freeing sci Because kthread_stop
CVE-2025-68241 In the Linux kernel, the following vulnerability has been resolved: ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe The sit driv
CVE-2025-68211 In the Linux kernel, the following vulnerability has been resolved: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item Curr
CVE-2025-68246 In the Linux kernel, the following vulnerability has been resolved: ksmbd: close accepted socket when per-IP limit rejects connection When the per-
CVE-2025-40273 In the Linux kernel, the following vulnerability has been resolved: NFSD: free copynotify stateid in nfs4_free_ol_stateid() Typically copynotify st
CVE-2025-40212 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix refcount leak in nfsd_set_fh_dentry() nfsd exports a "pseudo root fil
CVE-2025-40274 In the Linux kernel, the following vulnerability has been resolved: KVM: guest_memfd: Remove bindings on memslot deletion when gmem is dying When u
CVE-2025-68202 In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix unsafe locking in the scx_dump_state() For built with CONFIG_PRE
CVE-2025-68239 In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write access before closing files opened by open_exec() bm
CVE-2025-68247 In the Linux kernel, the following vulnerability has been resolved: posix-timers: Plug potential memory leak in do_timer_create() When posix timer
CVE-2025-68208 In the Linux kernel, the following vulnerability has been resolved: bpf: account for current allocated stack depth in widen_imprecise_scalars() The
CVE-2025-68200 In the Linux kernel, the following vulnerability has been resolved: bpf: Add bpf_prog_run_data_pointers() syzbot found that cls_bpf_classify() is a
CVE-2025-40275 In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd In
CVE-2025-68242 In the Linux kernel, the following vulnerability has been resolved: NFS: Fix LTP test failures when timestamps are delegated The utimes01 and utime
CVE-2025-68243 In the Linux kernel, the following vulnerability has been resolved: NFS: Check the TLS certificate fields in nfs_match_client() If the TLS security
CVE-2025-40276 In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Flush shmem writes before mapping buffers CPU-uncached The shmem l
CVE-2025-40277 In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This dat
CVE-2025-68206 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: add seqadj extension for natted connections Sequence adjustm
CVE-2025-68209 In the Linux kernel, the following vulnerability has been resolved: mlx5: Fix default values in create CQ Currently, CQs without a completion funct
CVE-2025-40278 In the Linux kernel, the following vulnerability has been resolved: net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak Fix
CVE-2025-40279 In the Linux kernel, the following vulnerability has been resolved: net: sched: act_connmark: initialize struct tc_ife to fix kernel leak In tcf_co
CVE-2025-40214 In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF
CVE-2025-40280 In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_mon_reinit_self(). syzbot reported use-after-f
CVE-2025-40281 In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto syzbot
CVE-2025-40282 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: reset link-local header on ipv6 recv path Bluetooth 6lowpan
CVE-2025-40283 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF There is a K
CVE-2025-40284 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: cancel mesh send timer when hdev removed mesh_send_done timer
CVE-2025-68210 In the Linux kernel, the following vulnerability has been resolved: erofs: avoid infinite loop due to incomplete zstd-compressed data Currently, th
CVE-2025-40285 In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of
CVE-2025-40286 In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible memory leak in smb2_read() Memory leak occurs when ksm
CVE-2025-40287 In the Linux kernel, the following vulnerability has been resolved: exfat: fix improper check of dentry.stream.valid_size We found an infinite loop
CVE-2025-40288 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix NULL pointer dereference in VRAM logic for APU devices Previous
CVE-2025-40289 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM Otherwise accessing
CVE-2025-68201 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: remove two invalid BUG_ON()s Those can be triggered trivially by us
CVE-2025-68207 In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Synchronize Dead CT worker with unbind Cancel and wait for any Dead
CVE-2025-68244 In the Linux kernel, the following vulnerability has been resolved: drm/i915: Avoid lock inversion when pinning to GGTT on CHV/BXT+VTD On completio
CVE-2025-68316 In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix invalid probe error return value After DME Link Startup, t
CVE-2025-40292 In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix received length check in big packets Since commit 4959aebba8c0
CVE-2025-68180 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL deref in debugfs odm_combine_segments When a connecto
CVE-2025-40327 In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix system hang caused by cpu-clock usage cpu-clock usage by the asy
CVE-2025-40328 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_close_cached_fid() find_or_create_cached
CVE-2025-40291 In the Linux kernel, the following vulnerability has been resolved: io_uring: fix regbuf vector size truncation There is a report of io_estimate_bv
CVE-2025-68322 In the Linux kernel, the following vulnerability has been resolved: parisc: Avoid crash due to unaligned access in unwinder Guenter Roeck reported
CVE-2025-40293 In the Linux kernel, the following vulnerability has been resolved: iommufd: Don't overflow during division for dirty tracking If pgshift is 63 the
CVE-2025-40294 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern() In the parse_adv
CVE-2025-40329 In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix deadlock in drm_sched_entity_kill_jobs_cb The Mesa issue referen
CVE-2025-40295 In the Linux kernel, the following vulnerability has been resolved: fscrypt: fix left shift underflow when inode->i_blkbits > PAGE_SHIFT When simul
CVE-2025-40296 In the Linux kernel, the following vulnerability has been resolved: platform/x86: int3472: Fix double free of GPIO device during unregister regulat
CVE-2025-40297 In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix use-after-free due to MST port state bypass syzbot reported[1]
CVE-2025-68320 In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix sleeping in atomic context The following warning was seen when we
CVE-2025-68169 In the Linux kernel, the following vulnerability has been resolved: netpoll: Fix deadlock in memory allocation under spinlock Fix a AA deadlock in
CVE-2025-68197 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix null pointer dereference in bnxt_bs_trace_check_wrap() With older
CVE-2025-40330 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Shutdown FW DMA in bnxt_shutdown() The netif_close() call in bnxt_shut
CVE-2025-68192 In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup Raw IP pack
CVE-2025-40331 In the Linux kernel, the following vulnerability has been resolved: sctp: Prevent TOCTOU out-of-bounds write For the following path not holding the
CVE-2025-68187 In the Linux kernel, the following vulnerability has been resolved: net: mdio: Check regmap pointer returned by device_node_to_regmap() The call to
CVE-2025-68167 In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix invalid pointer access in debugfs If the memory allocation in gpio
CVE-2025-68319 In the Linux kernel, the following vulnerability has been resolved: netconsole: Acquire su_mutex before navigating configs hierarchy There is a rac
CVE-2025-40298 In the Linux kernel, the following vulnerability has been resolved: gve: Implement settime64 with -EOPNOTSUPP ptp_clock_settime() assumes every ptp
CVE-2025-40299 In the Linux kernel, the following vulnerability has been resolved: gve: Implement gettimex64 with -EOPNOTSUPP gve implemented a ptp_clock for sole
CVE-2025-40301 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: validate skb length for unknown CC opcode In hci_cmd_comp
CVE-2025-40358 In the Linux kernel, the following vulnerability has been resolved: riscv: stacktrace: Disable KASAN checks for non-current tasks Unwinding the sta
CVE-2025-68186 In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Do not warn in ring_buffer_map_get_reader() when reader catches up
CVE-2025-68184 In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Disable AFBC support on Mediatek DRM driver Commit c410fa9b07c3 (
CVE-2025-40302 In the Linux kernel, the following vulnerability has been resolved: media: videobuf2: forbid remove_bufs when legacy fileio is active vb2_ioctl_rem
CVE-2025-40303 In the Linux kernel, the following vulnerability has been resolved: btrfs: ensure no dirty metadata is written back for an fs with errors [BUG] Dur
CVE-2025-40362 In the Linux kernel, the following vulnerability has been resolved: ceph: fix multifs mds auth caps issue The mds auth caps check should also valid
CVE-2025-40332 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix mmap write lock not release If mmap write lock is taken while d
CVE-2025-40304 In the Linux kernel, the following vulnerability has been resolved: fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds Add bounds
CVE-2025-40305 In the Linux kernel, the following vulnerability has been resolved: 9p/trans_fd: p9_fd_request: kick rx thread if EPOLLIN p9_read_work() doesn't se
CVE-2025-68318 In the Linux kernel, the following vulnerability has been resolved: clk: thead: th1520-ap: set all AXI clocks to CLK_IS_CRITICAL The AXI crossbar o
CVE-2025-40209 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak of qgroup_list in btrfs_add_qgroup_relation When btrfs_a
CVE-2025-68183 In the Linux kernel, the following vulnerability has been resolved: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr Current
CVE-2025-68173 In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix softlockup in ftrace_module_enable A soft lockup was observed when
CVE-2025-40306 In the Linux kernel, the following vulnerability has been resolved: orangefs: fix xattr related buffer overflow... Willy Tarreau <w@1wt.eu> forward
CVE-2025-40307 In the Linux kernel, the following vulnerability has been resolved: exfat: validate cluster allocation bits of the allocation bitmap syzbot created
CVE-2025-40308 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bcsp: receive data only if registered Currently, bcsp_recv() can be
CVE-2025-40309 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix UAF on sco_conn_free BUG: KASAN: slab-use-after-free in sco
CVE-2025-68174 In the Linux kernel, the following vulnerability has been resolved: amd/amdkfd: enhance kfd process check in switch partition current switch partit
CVE-2025-40310 In the Linux kernel, the following vulnerability has been resolved: amd/amdkfd: resolve a race in amdgpu_amdkfd_device_fini_sw There is race in amd
CVE-2025-40361 In the Linux kernel, the following vulnerability has been resolved: fs: ext4: change GFP_KERNEL to GFP_NOFS to avoid deadlock The parent function e
CVE-2025-40311 In the Linux kernel, the following vulnerability has been resolved: accel/habanalabs: support mapping cb with vmalloc-backed coherent memory When I
CVE-2025-68185 In the Linux kernel, the following vulnerability has been resolved: nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing
CVE-2025-68176 In the Linux kernel, the following vulnerability has been resolved: PCI: cadence: Check for the existence of cdns_pcie::ops before using it cdns_pc
CVE-2025-68190 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_lock
CVE-2025-68168 In the Linux kernel, the following vulnerability has been resolved: jfs: fix uninitialized waitqueue in transaction manager The transaction manager
CVE-2025-40312 In the Linux kernel, the following vulnerability has been resolved: jfs: Verify inode mode when loading from disk The inode mode loaded from corrup
CVE-2025-40333 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix infinite loop in __insert_extent_tree() When we get wrong extent info
CVE-2025-68321 In the Linux kernel, the following vulnerability has been resolved: page_pool: always add GFP_NOWARN for ATOMIC allocations Driver authors often fo
CVE-2025-40334 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate userq buffer virtual address and size It needs to validate
CVE-2025-68191 In the Linux kernel, the following vulnerability has been resolved: udp_tunnel: use netdev_warn() instead of netdev_WARN() netdev_WARN() uses WARN/
CVE-2025-68309 In the Linux kernel, the following vulnerability has been resolved: PCI/AER: Fix NULL pointer access by aer_info The kzalloc(GFP_KERNEL) may return
CVE-2025-40313 In the Linux kernel, the following vulnerability has been resolved: ntfs3: pretend $Extend records as regular files Since commit af153bb63a33 ("vfs
CVE-2025-40335 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate userq input args This will help on validating the userq in
CVE-2025-40314 In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: gadget: Use-after-free during failed initialization and exit of cdns
CVE-2025-40336 In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: fix hmm_pfn_to_map_order() usage Handle the case where the hmm rang
CVE-2025-68193 In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Add devm release action to safely tear down CT When a buffer object
CVE-2025-68175 In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: Fix streaming cleanup on release The current implementati
CVE-2025-68188 In the Linux kernel, the following vulnerability has been resolved: tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() Use RCU to av
CVE-2025-68315 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to detect potential corrupted nid in free_nid_list As reported, on-di
CVE-2025-40337 In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Correctly handle Rx checksum offload errors The stmmac_rx function
CVE-2025-40338 In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Do not share the name pointer between components By sharing '
CVE-2025-40339 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix nullptr err of vm_handle_moved If a amdgpu_bo_va is fpriv->prt_
CVE-2025-68194 In the Linux kernel, the following vulnerability has been resolved: media: imon: make send_packet() more robust syzbot is reporting that imon has t
CVE-2025-40363 In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix field-spanning memcpy warning in AH output Fix field-spanning me
CVE-2025-68311 In the Linux kernel, the following vulnerability has been resolved: tty: serial: ip22zilog: Use platform device for probing After commit 84a9582fd2
CVE-2025-40340 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix oops in xe_gem_fault when running core_hotunplug test. I saw an oop
CVE-2025-68196 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Cache streams targeting link when performing LT automation [WH
CVE-2025-68178 In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix possible deadlock while configuring policy Following deadlock c
CVE-2025-40341 In the Linux kernel, the following vulnerability has been resolved: futex: Don't leak robust_list pointer on exec race sys_get_robust_list() and co
CVE-2025-40342 In the Linux kernel, the following vulnerability has been resolved: nvme-fc: use lock accessing port_state and rport state nvme_fc_unregister_remot
CVE-2025-40343 In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid scheduling association deletion twice When forcefully shutting
CVE-2025-68177 In the Linux kernel, the following vulnerability has been resolved: cpufreq/longhaul: handle NULL policy in longhaul_exit longhaul_exit() was calli
CVE-2025-68317 In the Linux kernel, the following vulnerability has been resolved: io_uring/zctx: check chained notif contexts Send zc only links ubuf_info for re
CVE-2025-40315 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix epfile null pointer access after ep enable. A race condi
CVE-2025-40316 In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix device use-after-free on unbind A recent change fixed device
CVE-2025-40360 In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: Do not dereference NULL pointer in plane reset The plane state in __
CVE-2025-68179 In the Linux kernel, the following vulnerability has been resolved: s390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP As reported by Luiz Capitulino
CVE-2025-68310 In the Linux kernel, the following vulnerability has been resolved: s390/pci: Avoid deadlock between PCI error recovery and mlx5 crdump Do not bloc
CVE-2025-40317 In the Linux kernel, the following vulnerability has been resolved: regmap: slimbus: fix bus_context pointer in regmap init calls Commit 4e65bda827
CVE-2025-40359 In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix KASAN global-out-of-bounds warning When running "perf mem r
CVE-2025-68181 In the Linux kernel, the following vulnerability has been resolved: drm/radeon: Remove calls to drm_put_dev() Since the allocation of the drivers m
CVE-2025-68170 In the Linux kernel, the following vulnerability has been resolved: drm/radeon: Do not kfree() devres managed rdev Since the allocation of the driv
CVE-2025-40213 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a BU
CVE-2025-40318 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once hci_cmd_sync_dequeue
CVE-2025-68312 In the Linux kernel, the following vulnerability has been resolved: usbnet: Prevents free active kevent The root cause of this issue are: 1. When p
CVE-2025-40344 In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Disable periods-elapsed work when closing PCM avs_dai_fe_shut
CVE-2025-68172 In the Linux kernel, the following vulnerability has been resolved: crypto: aspeed - fix double free caused by devm The clock obtained via devm_clk
CVE-2025-40319 In the Linux kernel, the following vulnerability has been resolved: bpf: Sync pending IRQ work before freeing ring buffer Fix a race where irq_work
CVE-2025-68182 In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix potential use after free in iwl_mld_remove_link() This code
CVE-2025-68314 In the Linux kernel, the following vulnerability has been resolved: drm/msm: make sure last_fence is always updated Update last_fence in the vm-bin
CVE-2025-68189 In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix GEM free for imported dma-bufs Imported dma-bufs also have obj->re
CVE-2025-68171 In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Ensure XFD state on signal delivery Sean reported [1] the following sp
CVE-2025-68313 In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Add RDSEED fix for Zen5 There's an issue with RDSEED's 16-bit and
CVE-2025-40320 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential cfid UAF in smb2_query_info_compound When smb2_query
CVE-2025-40321 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode Cur
CVE-2025-40322 In the Linux kernel, the following vulnerability has been resolved: fbdev: bitblit: bound-check glyph index in bit_putcs* bit_putcs_aligned()/unali
CVE-2025-40211 In the Linux kernel, the following vulnerability has been resolved: ACPI: video: Fix use-after-free in acpi_video_switch_brightness() The switch_br
CVE-2025-40323 In the Linux kernel, the following vulnerability has been resolved: fbcon: Set fb_display[i]->mode to NULL when the mode is released Recently, we d
CVE-2025-40210 In the Linux kernel, the following vulnerability has been resolved: Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" I've f
CVE-2025-40324 In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix crash in nfsd4_read_release() When tracing is enabled, the trace_nfsd
CVE-2025-40326 In the Linux kernel, the following vulnerability has been resolved: NFSD: Define actions for the new time_deleg FATTR4 attributes NFSv4 clients won

Version: 6.17.0-10.10~24.04.2 2025-12-17 01:13:05 UTC

 linux-hwe-6.17 (6.17.0-10.10~24.04.2) noble; urgency=medium
 .
   * noble/linux-hwe-6.17: 6.17.0-10.10~24.04.2 -proposed tracker (LP: #2136294)
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] update variants
 .
   [ Ubuntu: 6.17.0-10.10 ]
 .
   * questing/linux: 6.17.0-10.10 -proposed tracker (LP: #2135908)
   * [UBUNTU 24.04] KVM: s390: improve interrupt cpu for wakeup (LP: #2132317)
     - KVM: s390: improve interrupt cpu for wakeup
   * Questing update: v6.17.6 upstream stable release (LP: #2134982)
     - sched/fair: Block delayed tasks on throttled hierarchy during dequeue
     - vfio/cdx: update driver to build without CONFIG_GENERIC_MSI_IRQ
     - expfs: Fix exportfs_can_encode_fh() for EXPORT_FH_FID
     - cgroup/misc: fix misc_res_type kernel-doc warning
     - dlm: move to rinfo for all middle conversion cases
     - exec: Fix incorrect type for ret
     - s390/pkey: Forward keygenflags to ep11_unwrapkey
     - hfs: clear offset and space out of valid records in b-tree node
     - hfs: make proper initalization of struct hfs_find_data
     - hfs: validate record offset in hfsplus_bmap_alloc
     - hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat()
     - dlm: check for defined force value in dlm_lockspace_release
     - hfsplus: return EIO when type of hidden directory mismatch in
       hfsplus_fill_super()
     - PCI: Test for bit underflow in pcie_set_readrq()
     - lkdtm: fortify: Fix potential NULL dereference on kmalloc failure
     - arm64: sysreg: Correct sign definitions for EIESB and DoubleLock
     - m68k: bitops: Fix find_*_bit() signatures
     - powerpc/32: Remove PAGE_KERNEL_TEXT to fix startup failure
     - riscv: mm: Return intended SATP mode for noXlvl options
     - riscv: mm: Use mmu-type from FDT to limit SATP mode
     - riscv: cpufeature: add validation for zfa, zfh and zfhmin
     - drivers/perf: hisi: Relax the event ID check in the framework
     - s390/mm: Use __GFP_ACCOUNT for user page table allocations
     - smb: client: queue post_recv_credits_work also if the peer raises the
       credit target
     - smb: client: limit the range of info->receive_credit_target
     - smb: client: make use of ib_wc_status_msg() and skip IB_WC_WR_FLUSH_ERR
       logging
     - smb: server: let smb_direct_flush_send_list() invalidate a remote key
       first
     - Unbreak 'make tools/*' for user-space targets
     - platform/mellanox: mlxbf-pmc: add sysfs_attr_init() to count_clock init
     - cpufreq/amd-pstate: Fix a regression leading to EPP 0 after hibernate
     - net/mlx5e: Return 1 instead of 0 in invalid case in
       mlx5e_mpwrq_umr_entry_size()
     - rtnetlink: Allow deleting FDB entries in user namespace
     - net: enetc: fix the deadlock of enetc_mdio_lock
     - net: enetc: correct the value of ENETC_RXB_TRUESIZE
     - dpaa2-eth: fix the pointer passed to PTR_ALIGN on Tx path
     - net: phy: realtek: fix rtl8221b-vm-cg name
     - can: bxcan: bxcan_start_xmit(): use can_dev_dropped_skb() instead of
       can_dropped_invalid_skb()
     - can: esd: acc_start_xmit(): use can_dev_dropped_skb() instead of
       can_dropped_invalid_skb()
     - can: rockchip-canfd: rkcanfd_start_xmit(): use can_dev_dropped_skb()
       instead of can_dropped_invalid_skb()
     - selftests: net: fix server bind failure in sctp_vrf.sh
     - net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for legacy RQ
     - net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding
       RQ
     - net/smc: fix general protection fault in __smc_diag_dump
     - net: ethernet: ti: am65-cpts: fix timestamp loss due to race conditions
     - arm64, mm: avoid always making PTE dirty in pte_mkwrite()
     - erofs: avoid infinite loops due to corrupted subpage compact indexes
     - net: hibmcge: select FIXED_PHY
     - ptp: ocp: Fix typo using index 1 instead of i in SMA initialization loop
     - net: hsr: prevent creation of HSR device with slaves from another netns
     - espintcp: use datagram_poll_queue for socket readiness
     - net: datagram: introduce datagram_poll_queue for custom receive queues
     - ovpn: use datagram_poll_queue for socket readiness in TCP
     - net: bonding: fix possible peer notify event loss or dup issue
     - hung_task: fix warnings caused by unaligned lock pointers
     - mm: don't spin in add_stack_record when gfp flags don't allow
     - dma-debug: don't report false positives with
       DMA_BOUNCE_UNALIGNED_KMALLOC
     - arch_topology: Fix incorrect error check in
       topology_parse_cpu_capacity()
     - riscv: hwprobe: Fix stale vDSO data for late-initialized keys at boot
     - io_uring/sqpoll: switch away from getrusage() for CPU accounting
     - io_uring/sqpoll: be smarter on when to update the stime usage
     - btrfs: send: fix duplicated rmdir operations when using extrefs
     - btrfs: ref-verify: fix IS_ERR() vs NULL check in btrfs_build_ref_tree()
     - gpio: pci-idio-16: Define maximum valid register address offset
     - gpio: 104-idio-16: Define maximum valid register address offset
     - xfs: fix locking in xchk_nlinks_collect_dir
     - platform/x86: alienware-wmi-wmax: Add AWCC support to Dell G15 5530
     - Revert "cpuidle: menu: Avoid discarding useful information"
     - riscv: cpufeature: avoid uninitialized variable in
       has_thead_homogeneous_vlenb()
     - rust: device: fix device context of Device::parent()
     - slab: Avoid race on slab->obj_exts in alloc_slab_obj_exts
     - slab: Fix obj_ext mistakenly considered NULL due to race condition
     - smb: client: get rid of d_drop() in cifs_do_rename()
     - ACPICA: Work around bogus -Wstringop-overread warning since GCC 11
     - arm64: mte: Do not warn if the page is already tagged in copy_highpage()
     - can: netlink: can_changelink(): allow disabling of automatic restart
     - cifs: Fix TCP_Server_Info::credits to be signed
     - devcoredump: Fix circular locking dependency with devcd->mutex.
 

Source diff to previous version
1786013 Packaging resync
2132317 [UBUNTU 24.04] KVM: s390: improve interrupt cpu for wakeup
2134982 Questing update: v6.17.6 upstream stable release
2133557 Questing update: v6.17.5 upstream stable release
CVE-2025-40084 In the Linux kernel, the following vulnerability has been resolved: ksmbd: transport_ipc: validate payload size before reading handle handle_respon
CVE-2025-40222 In the Linux kernel, the following vulnerability has been resolved: tty: serial: sh-sci: fix RSCI FIFO overrun handling The receive error handling
CVE-2025-40223 In the Linux kernel, the following vulnerability has been resolved: most: usb: Fix use-after-free in hdm_disconnect hdm_disconnect() calls most_der
CVE-2025-40106 In the Linux kernel, the following vulnerability has been resolved: comedi: fix divide-by-zero in comedi_buf_munge() The comedi_buf_munge() functio
CVE-2025-40224 In the Linux kernel, the following vulnerability has been resolved: hwmon: (cgbc-hwmon) Add missing NULL check after devm_kzalloc() The driver allo
CVE-2025-40225 In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix kernel panic on partial unmap of a GPU VA region This commit a
CVE-2025-40226 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Account for failed debug initialization When the SCMI debug
CVE-2025-40227 In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: dealloc commit test ctx always The damon_ctx for testing online
CVE-2025-40228 In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: catch commit test ctx alloc failure Patch series "mm/damon/sysf
CVE-2025-40229 In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: fix potential memory leak by cleaning ops_filter in damon_destroy
CVE-2025-40230 In the Linux kernel, the following vulnerability has been resolved: mm: prevent poison consumption when splitting THP When performing memory error
CVE-2025-40231 In the Linux kernel, the following vulnerability has been resolved: vsock: fix lock inversion in vsock_assign_transport() Syzbot reported a potenti
CVE-2025-40233 In the Linux kernel, the following vulnerability has been resolved: ocfs2: clear extent cache after moving/defragmenting extents The extent map cac
CVE-2025-40235 In the Linux kernel, the following vulnerability has been resolved: btrfs: directly free partially initialized fs_info in btrfs_check_leaked_roots()
CVE-2025-40236 In the Linux kernel, the following vulnerability has been resolved: virtio-net: zero unused hash fields When GSO tunnel is negotiated virtio_net_hd
CVE-2025-40237 In the Linux kernel, the following vulnerability has been resolved: fs/notify: call exportfs_encode_fid with s_umount Calling intotify_show_fdinfo(
CVE-2025-40238 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix IPsec cleanup over MPV device When we do mlx5e_detach_netdev() we
CVE-2025-40239 In the Linux kernel, the following vulnerability has been resolved: net: phy: micrel: always set shared->phydev for LAN8814 Currently, during the L
CVE-2025-40240 In the Linux kernel, the following vulnerability has been resolved: sctp: avoid NULL dereference when chunk data buffer is missing chunk->skb point
CVE-2025-40241 In the Linux kernel, the following vulnerability has been resolved: erofs: fix crafted invalid cases for encoded extents Robert recently reported t
CVE-2025-40242 In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix unlikely race in gdlm_put_lock In gdlm_put_lock(), there is a small w
CVE-2025-40243 In the Linux kernel, the following vulnerability has been resolved: hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits() The syzbot report
CVE-2025-40244 In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent() The syzbo
CVE-2025-40245 In the Linux kernel, the following vulnerability has been resolved: nios2: ensure that memblock.current_limit is set when setting pfn limits On nio
CVE-2025-40086 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't allow evicting of BOs in same VM in array of VM binds An array of
CVE-2025-40087 In the Linux kernel, the following vulnerability has been resolved: NFSD: Define a proc_layoutcommit for the FlexFiles layout type Avoid a crash if
CVE-2025-40088 In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp() The hfsplus_strcas
CVE-2025-40162 In the Linux kernel, the following vulnerability has been resolved: ASoC: amd/sdw_utils: avoid NULL deref when devm_kasprintf() fails devm_kasprint
CVE-2025-40085 In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card In try_to_r
CVE-2025-40172 In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages() Currentl
CVE-2025-40177 In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Fix bootlog initialization ordering As soon as we queue MHI buffers
CVE-2025-40163 In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Stop dl_server before CPU goes offline IBM CI tool reported ker
CVE-2025-40174 In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix SMP ordering in switch_mm_irqs_off() Stephen noted that it is possi
CVE-2025-40089 In the Linux kernel, the following vulnerability has been resolved: cxl/features: Add check for no entries in cxl_feature_info cxl EDAC calls cxl_f
CVE-2025-40176 In the Linux kernel, the following vulnerability has been resolved: tls: wait for pending async decryptions if tls_strp_msg_hold fails Async decryp
CVE-2025-40164 In the Linux kernel, the following vulnerability has been resolved: usbnet: Fix using smp_processor_id() in preemptible code warnings Syzbot report
CVE-2025-40091 In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix too early devlink_free() in ixgbe_remove() Since ixgbe_adapter is em
CVE-2025-40175 In the Linux kernel, the following vulnerability has been resolved: idpf: cleanup remaining SKBs in PTP flows When the driver requests Tx timestamp
CVE-2025-40173 In the Linux kernel, the following vulnerability has been resolved: net/ip6_tunnel: Prevent perpetual tunnel growth Similarly to ipv4 tunnel, ipv6
CVE-2025-40092 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Refactor bind path to use __free() After an bind/unbind cyc
CVE-2025-40093 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ecm: Refactor bind path to use __free() After an bind/unbind cyc
CVE-2025-40094 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_acm: Refactor bind path to use __free() After an bind/unbind cyc
CVE-2025-40095 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_rndis: Refactor bind path to use __free() After an bind/unbind c
CVE-2025-40165 In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: m2m: Fix streaming cleanup on release If streamon/streamo
CVE-2025-40096 In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies Whe
CVE-2025-40097 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix missing pointer check in hda_component_manager_init function The
CVE-2025-40098 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state(
CVE-2025-40099 In the Linux kernel, the following vulnerability has been resolved: cifs: parse_dfs_referrals: prevent oob on malformed input Malicious SMB server
CVE-2025-40100 In the Linux kernel, the following vulnerability has been resolved: btrfs: do not assert we found block group item when creating free space tree Cu
CVE-2025-40101 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leaks when rejecting a non SINGLE data profile without an RST
CVE-2025-40167 In the Linux kernel, the following vulnerability has been resolved: ext4: detect invalid INLINE_DATA + EXTENTS flag combination syzbot reported a B
CVE-2025-40102 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Prevent access to vCPU events before init Another day, another syzk
CVE-2025-40103 In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix refcount leak for cifs_sb_tlink Fix three refcount inconsisten
CVE-2025-40104 In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix mailbox API compatibility by negotiating supported features There
CVE-2025-40166 In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Check GuC running state before deregistering exec queue In normal o
CVE-2025-40105 In the Linux kernel, the following vulnerability has been resolved: vfs: Don't leak disconnected dentries on umount When user calls open_by_handle_

Version: 6.17.0-9.9~24.04.2 2025-12-01 15:10:23 UTC

 linux-hwe-6.17 (6.17.0-9.9~24.04.2) noble; urgency=medium
 .
   * noble/linux-hwe-6.17: 6.17.0-9.9~24.04.2 -proposed tracker (LP: #2132312)
     - SAUCE: tools: clamp sizeof in perf_cpu_map__merge
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] update variants
     - [Packaging] update Ubuntu.md
 .
   * kexec reports it cannot determine the file type of arm64 kernel images
     (LP: #2131154)
     - Revert "UBUNTU: [Packaging] Install compressed vmlinuz.efi on arm64"
 .
   * linux-hwe-6.14-tools-6.14.0-24:amd64 == 6.14.0-24.24~24.04.3 is missing
     the perf and bpftool binaries (LP: #2117147)
     - [Packaging] Add do_tools_noble_hwe to include perf and bpftool in
       SRCPKGNAME-tools-$(abi_release)
     - [Packaging] hwe-6.17: Set do_tools_noble_hwe = true in hooks.mk
 .
   [ Ubuntu: 6.17.0-9.9 ]
 .
   * questing/linux: 6.17.0-9.9 -proposed tracker (LP: #2132302)
   * The machine didn’t go into suspend and got stuck (LP: #2132095)
     - platform/x86: alienware-wmi-wmax: Fix NULL pointer dereference in sleep
       handlers
   * CAP_PERFMON insufficient to get perf data (LP: #2131046)
     - SAUCE: perf/core: Allow CAP_PERFMON for paranoid level 4
   * Poweroff not working consistently after upgrading kernel 6.14.0-17.17 or
     later (LP: #2115860)
     - drm/amd: Unify shutdown() callback behavior
     - drm/amd: Stop exporting amdgpu_device_ip_suspend() outside amdgpu_device
     - drm/amd: Remove comment about handling errors in
       amdgpu_device_ip_suspend_phase1()
     - drm/amd: Don't always set IP block HW status to false
     - drm/amd: Pass IP suspend errors up to callers
     - drm/amd: Avoid evicting resources at S5
   * kernel crash on bootup for some arm64 machines (LP: #2129770)
     - KVM: arm64: Guard PMSCR_EL1 initialization with SPE presence check
   * crash when reading from /sys/kernel/tracing/rv/enabled_monitors
     (LP: #2131136)
     - rv: Fully convert enabled_monitors to use list_head as iterator
   * i40e driver is triggering VF resets on every link state change
     (LP: #2130552)
     - i40e: avoid redundant VF link state updates
   * Re-enable INTEL_SKL_INT3472 for kernels >= 6.16 for Intel IPU camera
     (LP: #2128792)
     - Revert "UBUNTU: [Config] FTBFS: disable INTEL_SKL_INT3472"
     - Revert "UBUNTU: SAUCE: platform/x86: int3472: Add handshake GPIO
       function"
   * Support Samsung S5K3J1 sensor for Intel MIPI camera (LP: #2121852)
     - SAUCE: media: ipu-bridge: Support s5k3j1 sensor
   * Questing update: v6.17.4 upstream stable release (LP: #2131259)
     - fs: always return zero on success from replace_fd()
     - fscontext: do not consume log entries when returning -EMSGSIZE
     - btrfs: fix the incorrect max_bytes value for find_lock_delalloc_range()
     - arm64: map [_text, _stext) virtual address range non-executable+read-
       only
     - rseq: Protect event mask against membarrier IPI
     - statmount: don't call path_put() under namespace semaphore
     - listmount: don't call path_put() under namespace semaphore
     - clocksource/drivers/clps711x: Fix resource leaks in error paths
     - memcg: skip cgroup_file_notify if spinning is not allowed
     - page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches
     - PM: runtime: Update kerneldoc return codes
     - dma-mapping: fix direction in dma_alloc direction traces
     - cpufreq: Make drivers using CPUFREQ_ETERNAL specify transition latency
     - nfsd: unregister with rpcbind when deleting a transport
     - KVM: x86: Add helper to retrieve current value of user return MSR
     - KVM: SVM: Emulate PERF_CNTR_GLOBAL_STATUS_SET for PerfMonV2
     - iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE
     - media: v4l2-subdev: Fix alloc failure check in
       v4l2_subdev_call_state_try()
     - asm-generic/io.h: Skip trace helpers if rwmmio events are disabled
     - clk: npcm: select CONFIG_AUXILIARY_BUS
     - clk: thead: th1520-ap: describe gate clocks with clk_gate
     - clk: thead: th1520-ap: fix parent of padctrl0 clock
     - clk: thead: Correct parent for DPU pixel clocks
     - clk: renesas: r9a08g045: Add MSTOP for GPIO
     - perf disasm: Avoid undefined behavior in incrementing NULL
     - perf test trace_btf_enum: Skip if permissions are insufficient
     - perf evsel: Avoid container_of on a NULL leader
     - libperf event: Ensure tracing data is multiple of 8 sized
     - clk: qcom: common: Fix NULL vs IS_ERR() check in qcom_cc_icc_register()
     - clk: qcom: Select the intended config in QCS_DISPCC_615
     - perf parse-events: Handle fake PMUs in CPU terms
     - clk: at91: peripheral: fix return value
     - clk: renesas: cpg-mssr: Fix memory leak in cpg_mssr_reserved_init()
     - perf: Completely remove possibility to override MAX_NR_CPUS
     - perf drm_pmu: Fix fd_dir leaks in for_each_drm_fdinfo_in_dir()
     - perf util: Fix compression checks returning -1 as bool
     - rtc: x1205: Fix Xicor X1205 vendor prefix
     - rtc: optee: fix memory leak on driver removal
     - perf arm_spe: Correct setting remote access
     - perf arm_spe: Correct memory level for remote access
     - perf vendor events arm64 AmpereOneX: Fix typo - should be
       l1d_cache_access_prefetches
     - perf test: AMD IBS swfilt skip kernel tests if paranoia is >1
     - perf test shell lbr: Avoid failures with perf event paranoia
     - perf trace: Fix IS_ERR() vs NULL check bug
     - perf session: Fix handling when buffer exceeds 2 GiB
     - perf test: Don't leak workload gopipe in PERF_RECORD_*
     - perf evsel: Fix uniquification when PMU given without suffix
     - perf test: Avoid uncore_imc/clockticks in uniquification test
     - perf evsel: Ensure the fallback message is always written to
     - perf build-id: Ensure snprintf string is empty when size is 0
     - clk: mediatek: mt8195-infra_ao: Fix parent for infra_ao_hdmi_26m
     - clk: mediatek: clk-mux: Do not pass flags to
       clk_mux_determine_rate_flags(

Source diff to previous version
1786013 Packaging resync
2131154 kexec reports it cannot determine the file type of arm64 kernel images
2117147 linux-hwe-6.14-tools-6.14.0-24:amd64 == 6.14.0-24.24~24.04.3 is missing the perf and bpftool binaries
2132095 The machine didn\u2019t go into suspend and got stuck
2131046 CAP_PERFMON insufficient to get perf data
2129770 kernel crash on bootup for some arm64 machines
2131136 crash when reading from /sys/kernel/tracing/rv/enabled_monitors
2130552 i40e driver is triggering VF resets on every link state change
2128792 Re-enable INTEL_SKL_INT3472 for kernels \u003e= 6.16 for Intel IPU camera
2131259 Questing update: v6.17.4 upstream stable release
2131702 Race condition in perf build causes build failure due to missing unistd_64.h header on arm64
2129610 Questing update: v6.17.3 upstream stable release
CVE-2025-40019 In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-place encryption Move the ssi
CVE-2025-40018 In the Linux kernel, the following vulnerability has been resolved: ipvs: Defer ip_vs_ftp unregister during netns cleanup On the netns cleanup path

Version: 6.17.0-9.9~24.04.1 2025-11-28 14:09:41 UTC

 linux-hwe-6.17 (6.17.0-9.9~24.04.1) noble; urgency=medium
 .
   * noble/linux-hwe-6.17: 6.17.0-9.9~24.04.1 -proposed tracker (LP: #2132312)
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] update variants
     - [Packaging] update Ubuntu.md
 .
   * kexec reports it cannot determine the file type of arm64 kernel images
     (LP: #2131154)
     - Revert "UBUNTU: [Packaging] Install compressed vmlinuz.efi on arm64"
 .
   * linux-hwe-6.14-tools-6.14.0-24:amd64 == 6.14.0-24.24~24.04.3 is missing
     the perf and bpftool binaries (LP: #2117147)
     - [Packaging] Add do_tools_noble_hwe to include perf and bpftool in
       SRCPKGNAME-tools-$(abi_release)
     - [Packaging] hwe-6.17: Set do_tools_noble_hwe = true in hooks.mk
 .
   [ Ubuntu: 6.17.0-9.9 ]
 .
   * questing/linux: 6.17.0-9.9 -proposed tracker (LP: #2132302)
   * The machine didn’t go into suspend and got stuck (LP: #2132095)
     - platform/x86: alienware-wmi-wmax: Fix NULL pointer dereference in sleep
       handlers
   * CAP_PERFMON insufficient to get perf data (LP: #2131046)
     - SAUCE: perf/core: Allow CAP_PERFMON for paranoid level 4
   * Poweroff not working consistently after upgrading kernel 6.14.0-17.17 or
     later (LP: #2115860)
     - drm/amd: Unify shutdown() callback behavior
     - drm/amd: Stop exporting amdgpu_device_ip_suspend() outside amdgpu_device
     - drm/amd: Remove comment about handling errors in
       amdgpu_device_ip_suspend_phase1()
     - drm/amd: Don't always set IP block HW status to false
     - drm/amd: Pass IP suspend errors up to callers
     - drm/amd: Avoid evicting resources at S5
   * kernel crash on bootup for some arm64 machines (LP: #2129770)
     - KVM: arm64: Guard PMSCR_EL1 initialization with SPE presence check
   * crash when reading from /sys/kernel/tracing/rv/enabled_monitors
     (LP: #2131136)
     - rv: Fully convert enabled_monitors to use list_head as iterator
   * i40e driver is triggering VF resets on every link state change
     (LP: #2130552)
     - i40e: avoid redundant VF link state updates
   * Re-enable INTEL_SKL_INT3472 for kernels >= 6.16 for Intel IPU camera
     (LP: #2128792)
     - Revert "UBUNTU: [Config] FTBFS: disable INTEL_SKL_INT3472"
     - Revert "UBUNTU: SAUCE: platform/x86: int3472: Add handshake GPIO
       function"
   * Support Samsung S5K3J1 sensor for Intel MIPI camera (LP: #2121852)
     - SAUCE: media: ipu-bridge: Support s5k3j1 sensor
   * Questing update: v6.17.4 upstream stable release (LP: #2131259)
     - fs: always return zero on success from replace_fd()
     - fscontext: do not consume log entries when returning -EMSGSIZE
     - btrfs: fix the incorrect max_bytes value for find_lock_delalloc_range()
     - arm64: map [_text, _stext) virtual address range non-executable+read-
       only
     - rseq: Protect event mask against membarrier IPI
     - statmount: don't call path_put() under namespace semaphore
     - listmount: don't call path_put() under namespace semaphore
     - clocksource/drivers/clps711x: Fix resource leaks in error paths
     - memcg: skip cgroup_file_notify if spinning is not allowed
     - page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches
     - PM: runtime: Update kerneldoc return codes
     - dma-mapping: fix direction in dma_alloc direction traces
     - cpufreq: Make drivers using CPUFREQ_ETERNAL specify transition latency
     - nfsd: unregister with rpcbind when deleting a transport
     - KVM: x86: Add helper to retrieve current value of user return MSR
     - KVM: SVM: Emulate PERF_CNTR_GLOBAL_STATUS_SET for PerfMonV2
     - iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE
     - media: v4l2-subdev: Fix alloc failure check in
       v4l2_subdev_call_state_try()
     - asm-generic/io.h: Skip trace helpers if rwmmio events are disabled
     - clk: npcm: select CONFIG_AUXILIARY_BUS
     - clk: thead: th1520-ap: describe gate clocks with clk_gate
     - clk: thead: th1520-ap: fix parent of padctrl0 clock
     - clk: thead: Correct parent for DPU pixel clocks
     - clk: renesas: r9a08g045: Add MSTOP for GPIO
     - perf disasm: Avoid undefined behavior in incrementing NULL
     - perf test trace_btf_enum: Skip if permissions are insufficient
     - perf evsel: Avoid container_of on a NULL leader
     - libperf event: Ensure tracing data is multiple of 8 sized
     - clk: qcom: common: Fix NULL vs IS_ERR() check in qcom_cc_icc_register()
     - clk: qcom: Select the intended config in QCS_DISPCC_615
     - perf parse-events: Handle fake PMUs in CPU terms
     - clk: at91: peripheral: fix return value
     - clk: renesas: cpg-mssr: Fix memory leak in cpg_mssr_reserved_init()
     - perf: Completely remove possibility to override MAX_NR_CPUS
     - perf drm_pmu: Fix fd_dir leaks in for_each_drm_fdinfo_in_dir()
     - perf util: Fix compression checks returning -1 as bool
     - rtc: x1205: Fix Xicor X1205 vendor prefix
     - rtc: optee: fix memory leak on driver removal
     - perf arm_spe: Correct setting remote access
     - perf arm_spe: Correct memory level for remote access
     - perf vendor events arm64 AmpereOneX: Fix typo - should be
       l1d_cache_access_prefetches
     - perf test: AMD IBS swfilt skip kernel tests if paranoia is >1
     - perf test shell lbr: Avoid failures with perf event paranoia
     - perf trace: Fix IS_ERR() vs NULL check bug
     - perf session: Fix handling when buffer exceeds 2 GiB
     - perf test: Don't leak workload gopipe in PERF_RECORD_*
     - perf evsel: Fix uniquification when PMU given without suffix
     - perf test: Avoid uncore_imc/clockticks in uniquification test
     - perf evsel: Ensure the fallback message is always written to
     - perf build-id: Ensure snprintf string is empty when size is 0
     - clk: mediatek: mt8195-infra_ao: Fix parent for infra_ao_hdmi_26m
     - clk: mediatek: clk-mux: Do not pass flags to
       clk_mux_determine_rate_flags()
     - clk: nxp: lpc18xx-cgu: convert from round_rate()

1786013 Packaging resync
2131154 kexec reports it cannot determine the file type of arm64 kernel images
2117147 linux-hwe-6.14-tools-6.14.0-24:amd64 == 6.14.0-24.24~24.04.3 is missing the perf and bpftool binaries
2132095 The machine didn\u2019t go into suspend and got stuck
2131046 CAP_PERFMON insufficient to get perf data
2129770 kernel crash on bootup for some arm64 machines
2131136 crash when reading from /sys/kernel/tracing/rv/enabled_monitors
2130552 i40e driver is triggering VF resets on every link state change
2128792 Re-enable INTEL_SKL_INT3472 for kernels \u003e= 6.16 for Intel IPU camera
2131259 Questing update: v6.17.4 upstream stable release
2131702 Race condition in perf build causes build failure due to missing unistd_64.h header on arm64
2129610 Questing update: v6.17.3 upstream stable release
CVE-2025-40019 In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-place encryption Move the ssi
CVE-2025-40018 In the Linux kernel, the following vulnerability has been resolved: ipvs: Defer ip_vs_ftp unregister during netns cleanup On the netns cleanup path



About   -   Send Feedback to @ubuntu_updates