UbuntuUpdates.org

Package "linux"

This package belongs to a PPA: Canonical Kernel Team

Name: linux

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Inspection and simple manipulation of BPF programs and maps
  • Headers for BPF development
  • Linux kernel buildinfo for version 6.14.0
  • Linux kernel buildinfo for version 6.14.0

Latest version: 6.14.0-30.30
Release: plucky (25.04)
Level: base
Repository: main

Links



Other versions of "linux" in Plucky

Repository Area Version
base main 7.6.0+6.14.0-15.15
security main 6.14.0-27.27
updates main 6.14.0-27.27
proposed main 6.14.0-28.28

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 6.14.0-30.30 2025-08-13 18:08:20 UTC

 linux (6.14.0-30.30) plucky; urgency=medium
 .
   * plucky/linux: 6.14.0-30.30 -proposed tracker (LP: #2120126)
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] debian.master/dkms-versions -- update from kernel-versions
       (main/2025.08.11)
 .
   * kernel panic when reloading apparmor 5.0.0 profiles (LP: #2120233)
     - SAUCE: apparmor5.0.0 [59/53]: apparmor: prevent profile->disconnected
       double free in aa_free_profile
 .
   * [SRU] Add support for ALC1708 codec on TRBL platform (LP: #2116247)
     - ASoC: Intel: soc-acpi-intel-lnl-match: add rt1320_l12_rt714_l0 support
 .
   * [SRU] Add waiting latency for USB port resume (LP: #2115478)
     - usb: hub: fix detection of high tier USB3 devices behind suspended hubs
     - usb: hub: Fix flushing and scheduling of delayed work that tunes runtime
       pm
     - usb: hub: Fix flushing of delayed work used for post resume purposes
 .
   * minimal kernel lacks modules for blk disk in arm64 openstack environments
     where config_drive is required (LP: #2118499)
     - [Config] Enable SYM53C8XX_2 on arm64
 .
   * Support xe2_hpg (LP: #2116175)
     - drm/xe/xe2_hpg: Add PCI IDs for xe2_hpg
     - drm/xe/xe2_hpg: Define additional Xe2_HPG GMD_ID
     - drm/xe/xe2_hpg: Add set of workarounds
     - drm/xe/xe2hpg: Add Wa_16025250150
 .
   * drm/xe: Lite restore breaks fdinfo drm-cycles-rcs reporting (LP: #2119526)
     - drm/xe: Add WA BB to capture active context utilization
     - drm/xe/lrc: Use a temporary buffer for WA BB
 .
   * No IP Address assigned after hot-plugging Ethernet cable on HP Platform
     (LP: #2115393)
     - Revert "e1000e: change k1 configuration on MTP and later platforms"
 .
   * I/O performance regression on NVMes under same bridge (dual port nvme)
     (LP: #2115738)
     - iommu/vt-d: Optimize iotlb_sync_map for non-caching/non-RWBF modes
     - iommu/vt-d: Split intel_iommu_domain_alloc_paging_flags()
     - iommu/vt-d: Create unique domain ops for each stage
     - iommu/vt-d: Split intel_iommu_enforce_cache_coherency()
     - iommu/vt-d: Split paging_domain_compatible()
     - iommu/vt-d: Make iotlb_sync_map a static property of dmar_domain
 .
   * BPF header file in wrong location (LP: #2118965)
     - [Packaging] Install bpf header to correct location
 .
   * Internal microphone not working on ASUS VivoBook with Realtek ALC256
     (Ubuntu 24.04 + kernel 6.15) (LP: #2112330)
     - ALSA: hda/realtek: Fix built-in mic on ASUS VivoBook X513EA
 .
   * Documentation update for [Ubuntu25.04] "virsh attach-interface" requires
     a reboot to reflect the attached interfaces on the guest (LP: #2111231)
     - powerpc/pseries/dlpar: Search DRC index from ibm, drc-indexes for IO add
 .
   * Plucky update: upstream stable patchset 2025-08-06 (LP: #2119603)
     - tools/x86/kcpuid: Fix error handling
     - x86/idle: Remove MFENCEs for X86_BUG_CLFLUSH_MONITOR in
       mwait_idle_with_hints() and prefer_mwait_c1_over_halt()
     - crypto: sun8i-ce-hash - fix error handling in sun8i_ce_hash_run()
     - sched: Fix trace_sched_switch(.prev_state)
     - perf/x86/amd/uncore: Remove unused 'struct amd_uncore_ctx::node' member
     - perf/x86/amd/uncore: Prevent UMC counters from saturating
     - gfs2: replace sd_aspace with sd_inode
     - gfs2: gfs2_create_inode error handling fix
     - perf/core: Fix broken throttling when max_samples_per_tick=1
     - crypto: sun8i-ss - do not use sg_dma_len before calling DMA functions
     - powerpc: do not build ppc_save_regs.o always
     - powerpc/crash: Fix non-smp kexec preparation
     - sched/core: Tweak wait_task_inactive() to force dequeue sched_delayed
       tasks
     - x86/microcode/AMD: Do not return error when microcode update is not
       necessary
     - crypto: sun8i-ce - undo runtime PM changes during driver removal
     - x86/cpu: Sanitize CPUID(0x80000000) output
     - x86/insn: Fix opcode map (!REX2) superscript tags
     - brd: fix aligned_sector from brd_do_discard()
     - brd: fix discard end sector
     - kselftest: cpufreq: Get rid of double suspend in rtcwake case
     - crypto: marvell/cesa - Avoid empty transfer descriptor
     - erofs: fix file handle encoding for 64-bit NIDs
     - powerpc/pseries/iommu: Fix kmemleak in TCE table userspace view
     - btrfs: scrub: update device stats when an error is detected
     - btrfs: scrub: fix a wrong error type when metadata bytenr mismatches
     - btrfs: fix invalid data space release when truncating block in NOCOW
       mode
     - rcu/cpu_stall_cputime: fix the hardirq count for x86 architecture
     - crypto: lrw - Only add ecb if it is not already there
     - crypto: xts - Only add ecb if it is not already there
     - crypto: sun8i-ce - move fallback ahash_request to the end of the struct
     - kunit: Fix wrong parameter to kunit_deactivate_static_stub()
     - crypto: api - Redo lookup on EEXIST
     - ACPICA: exserial: don't forget to handle FFixedHW opregions for reading
     - ASoC: tas2764: Enable main IRQs
     - EDAC/{skx_common,i10nm}: Fix the loss of saved RRL for HBM pseudo
       channel 0
     - spi: tegra210-quad: Fix X1_X2_X4 encoding and support x4 transfers
     - spi: tegra210-quad: remove redundant error handling code
     - spi: tegra210-quad: modify chip select (CS) deactivation
     - power: reset: at91-reset: Optimize at91_reset()
     - ASoC: SOF: ipc4-pcm: Adjust pipeline_list->pipelines allocation type
     - ASoC: SOF: amd: add missing acp descriptor field
     - PM: wakeup: Delete space in the end of string shown by
       pm_show_wakelocks()
     - ACPI: resource: fix a typo for MECHREVO in
       irq1_edge_low_force_override[]
     - x86/mtrr: Check if fixed-range MTRRs exist in mtrr_save_fixed_ranges()
     - PM: sleep: Print PM debug messages during hibernation
     - thermal/drivers/mediatek/lvts: Fix debugfs unregister on failure
     - ACPI: OSI: Stop advertising support for "3.0 _SCP Extensions"
     - spi: sh-msiof: Fix maximum DMA t

Source diff to previous version
1786013 Packaging resync
2120233 kernel panic when reloading apparmor 5.0.0 profiles
2115478 [SRU] Add waiting latency for USB port resume
2118499 minimal kernel lacks modules for blk disk in arm64 openstack environments where config_drive is required
2116175 Support xe2_hpg
2119526 drm/xe: Lite restore breaks fdinfo drm-cycles-rcs reporting
2115738 I/O performance regression on NVMes under same bridge (dual port nvme)
2118965 BPF header file in wrong location
2112330 Internal microphone not working on ASUS VivoBook with Realtek ALC256 (Ubuntu 24.04 + kernel 6.15)
2111231 Documentation update for [Ubuntu25.04] \
2119603 Plucky update: upstream stable patchset 2025-08-06
2119039 Plucky update: v6.14.11 upstream stable release
2119010 Plucky update: v6.14.10 upstream stable release
2115678 Plucky update: v6.14.9 upstream stable release
CVE-2025-38105 In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Kill timer properly at removal The USB-audio MIDI code initial
CVE-2025-38114 In the Linux kernel, the following vulnerability has been resolved: e1000: Move cancel_work_sync to avoid deadlock Previously, e1000_down called ca
CVE-2025-38116 In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix uaf in ath12k_core_init() When the execution of ath12k_core_h
CVE-2025-38306 In the Linux kernel, the following vulnerability has been resolved: fs/fhandle.c: fix a race in call of has_locked_children() may_decode_fh() is ca
CVE-2025-38272 In the Linux kernel, the following vulnerability has been resolved: net: dsa: b53: do not enable EEE on bcm63xx BCM63xx internal switches do not su
CVE-2025-38311 In the Linux kernel, the following vulnerability has been resolved: iavf: get rid of the crit lock Get rid of the crit lock. That frees us from the
CVE-2025-38128 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: reject malformed HCI_CMD_SYNC commands In 'mgmt_hci_cmd_sync()
CVE-2025-38130 In the Linux kernel, the following vulnerability has been resolved: drm/connector: only call HDMI audio helper plugged cb if non-null On driver rem
CVE-2025-38132 In the Linux kernel, the following vulnerability has been resolved: coresight: holding cscfg_csdev_lock while removing cscfg from csdev There'll be
CVE-2025-38137 In the Linux kernel, the following vulnerability has been resolved: PCI/pwrctrl: Cancel outstanding rescan work when unregistering It's possible to
CVE-2025-38139 In the Linux kernel, the following vulnerability has been resolved: netfs: Fix oops in write-retry from mis-resetting the subreq iterator Fix the r
CVE-2025-38140 In the Linux kernel, the following vulnerability has been resolved: dm: limit swapping tables for devices with zone write plugs dm_revalidate_zones
CVE-2025-38279 In the Linux kernel, the following vulnerability has been resolved: bpf: Do not include stack ptr register in precision backtracking bookkeeping Yi
CVE-2025-38314 In the Linux kernel, the following vulnerability has been resolved: virtio-pci: Fix result size returned for the admin command completion The resul
CVE-2025-38316 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: avoid NULL pointer dereference in mt7996_set_monitor() The
CVE-2025-38281 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Add NULL check in mt7996_thermal_init devm_kasprintf() can
CVE-2025-38284 In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: configure manual DAC mode via PCI config API only To support
CVE-2025-38287 In the Linux kernel, the following vulnerability has been resolved: IB/cm: Drop lockdep assert and WARN when freeing old msg The send completion ha
CVE-2025-38289 In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Avoid potential ndlp use-after-free in dev_loss_tmo_callbk Smatch d
CVE-2025-38291 In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Prevent sending WMI commands to firmware during firmware crash Cu
CVE-2025-38294 In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix NULL access in assign channel context handler Currently, when
CVE-2025-38296 In the Linux kernel, the following vulnerability has been resolved: ACPI: platform_profile: Avoid initializing on non-ACPI platforms The platform p
CVE-2025-38100 In the Linux kernel, the following vulnerability has been resolved: x86/iopl: Cure TIF_IO_BITMAP inconsistencies io_bitmap_exit() is invoked from e
CVE-2025-38101 In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix buffer locking in ring_buffer_subbuf_order_set() Enlarge the c
CVE-2025-38267 In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Do not trigger WARN_ON() due to a commit_overrun When reading a me
CVE-2025-38268 In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: move tcpm_queue_vdm_unlocked to asynchronous work A state che
CVE-2025-38102 In the Linux kernel, the following vulnerability has been resolved: VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify During
CVE-2025-38301 In the Linux kernel, the following vulnerability has been resolved: nvmem: zynqmp_nvmem: unbreak driver after cleanup Commit 29be47fcd6a0 ("nvmem:
CVE-2025-38352 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer
CVE-2025-38103 In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse() Update str
CVE-2025-38302 In the Linux kernel, the following vulnerability has been resolved: block: don't use submit_bio_noacct_nocheck in blk_zone_wplug_bio_work Bios queu
CVE-2025-38106 In the Linux kernel, the following vulnerability has been resolved: io_uring: fix use-after-free of sq->thread in __io_uring_show_fdinfo() syzbot r
CVE-2025-38269 In the Linux kernel, the following vulnerability has been resolved: btrfs: exit after state insertion failure at btrfs_convert_extent_bit() If inse
CVE-2025-38270 In the Linux kernel, the following vulnerability has been resolved: net: drv: netdevsim: don't napi_complete() from netpoll netdevsim supports netp
CVE-2025-38107 In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: fix a race in ets_qdisc_change() Gerrard Tai reported a race co
CVE-2025-38108 In the Linux kernel, the following vulnerability has been resolved: net_sched: red: fix a race in __red_change() Gerrard Tai reported a race condit
CVE-2025-38109 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix ECVF vports unload on shutdown flow Fix shutdown flow UAF when a
CVE-2025-38303 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix possible crashes on eir_create_adv_data eir_create_adv_data
CVE-2025-38304 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix NULL pointer deference on eir_get_service_data The len parameter
CVE-2025-38110 In the Linux kernel, the following vulnerability has been resolved: net/mdiobus: Fix potential out-of-bounds clause 45 read/write access When using
CVE-2025-38111 In the Linux kernel, the following vulnerability has been resolved: net/mdiobus: Fix potential out-of-bounds read/write access When using publicly
CVE-2025-38112 In the Linux kernel, the following vulnerability has been resolved: net: Fix TOCTOU issue in sk_is_readable() sk->sk_prot->sock_is_readable is a va
CVE-2025-38113 In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Fix NULL pointer dereference when nosmp is used With nosmp in cmdli
CVE-2025-38088 In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap memtrace mma
CVE-2025-38115 In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: fix a potential crash on gso_skb handling SFQ has an assump
CVE-2025-38414 In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix GCC_GCC_PCIE_HOT_RST definition for WCN7850 GCC_GCC_PCIE_HOT_
CVE-2025-38305 In the Linux kernel, the following vulnerability has been resolved: ptp: remove ptp->n_vclocks check logic in ptp_vclock_in_use() There is no disag
CVE-2025-38117 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Protect mgmt_pending list with its own lock This uses a mutex
CVE-2025-38118 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete This reworks MGMT_
CVE-2025-38119 In the Linux kernel, the following vulnerability has been resolved: scsi: core: ufs: Fix a hang in the error handler ufshcd_err_handling_prepare()
CVE-2025-38307 In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Verify content returned by parse_int_array() The first elemen
CVE-2025-38310 In the Linux kernel, the following vulnerability has been resolved: seg6: Fix validation of nexthop addresses The kernel currently validates that t
CVE-2025-38120 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo_avx2: fix initial map fill If the first field doesn't
CVE-2025-38122 In the Linux kernel, the following vulnerability has been resolved: gve: add missing NULL check for gve_alloc_pending_packet() in TX DQO gve_alloc_
CVE-2025-38123 In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: Fix napi rx poll issue When driver handles the napi rx polling
CVE-2025-38124 In the Linux kernel, the following vulnerability has been resolved: net: fix udp gso skb_segment after pull from frag_list Commit a1e40ac5b5e9 ("ne
CVE-2025-38125 In the Linux kernel, the following vulnerability has been resolved: net: stmmac: make sure that ptp_rate is not 0 before configuring EST If the ptp
CVE-2025-38126 In the Linux kernel, the following vulnerability has been resolved: net: stmmac: make sure that ptp_rate is not 0 before configuring timestamping T
CVE-2025-38127 In the Linux kernel, the following vulnerability has been resolved: ice: fix Tx scheduler error handling in XDP callback When the XDP program is lo
CVE-2025-38129 In the Linux kernel, the following vulnerability has been resolved: page_pool: Fix use-after-free in page_pool_recycle_in_ring syzbot reported a ua
CVE-2025-38131 In the Linux kernel, the following vulnerability has been resolved: coresight: prevent deactivate active config while enabling the config While ena
CVE-2025-38274 In the Linux kernel, the following vulnerability has been resolved: fpga: fix potential null pointer deref in fpga_mgr_test_img_load_sgt() fpga_mgr
CVE-2025-38134 In the Linux kernel, the following vulnerability has been resolved: usb: acpi: Prevent null pointer dereference in usb_acpi_add_usb4_devlink() As d
CVE-2025-38135 In the Linux kernel, the following vulnerability has been resolved: serial: Fix potential null-ptr-deref in mlb_usio_probe() devm_ioremap() can ret
CVE-2025-38136 In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Reorder clock handling and power management in probe Reorde
CVE-2025-38138 In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: Add NULL check in udma_probe() devm_kasprintf() returns NULL whe
CVE-2025-38275 In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug The qmp_usb_iomap() helper funct
CVE-2025-38141 In the Linux kernel, the following vulnerability has been resolved: dm: fix dm_blk_report_zones If dm_get_live_table() returned NULL, dm_put_live_t
CVE-2025-38142 In the Linux kernel, the following vulnerability has been resolved: hwmon: (asus-ec-sensors) check sensor index in read_string() Prevent a potentia
CVE-2025-38277 In the Linux kernel, the following vulnerability has been resolved: mtd: nand: ecc-mxic: Fix use of uninitialized variable ret If ctx->steps is zer
CVE-2025-38143 In the Linux kernel, the following vulnerability has been resolved: backlight: pm8941: Add NULL check in wled_configure() devm_kasprintf() returns
CVE-2025-38312 In the Linux kernel, the following vulnerability has been resolved: fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod() In fb_find_mode_cvt
CVE-2025-38145 In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop() devm_kasprintf() retur
CVE-2025-38313 In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: fix double-free on mc_dev The blamed commit tried to simplify how
CVE-2025-38415 In the Linux kernel, the following vulnerability has been resolved: Squashfs: check return result of sb_min_blocksize Syzkaller reports an "UBSAN:
CVE-2025-38146 In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Fix the dead loop of MPLS parse The unexpected MPLS packet ma
CVE-2025-38147 In the Linux kernel, the following vulnerability has been resolved: calipso: Don't call calipso functions for AF_INET sk. syzkaller reported a null
CVE-2025-38278 In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: QOS: Refactor TC_HTB_LEAF_DEL_LAST callback This patch addresses
CVE-2025-38148 In the Linux kernel, the following vulnerability has been resolved: net: phy: mscc: Fix memory leak when using one step timestamping Fix memory lea
CVE-2025-38149 In the Linux kernel, the following vulnerability has been resolved: net: phy: clear phydev->devlink when the link is deleted There is a potential c
CVE-2025-38280 In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid __bpf_prog_ret0_warn when jit fails syzkaller reported an issue: WA
CVE-2025-38151 In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix hang when cma_netevent_callback fails to queue_work The cited com
CVE-2025-38153 In the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: fix error handling of usbnet read calls Syzkaller, courtesy o
CVE-2025-38154 In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Avoid using sk_socket after free when sending The sk->sk_socket i
CVE-2025-38315 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Check dsbr size from EFI variable Since the size of struct
CVE-2025-38155 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: Fix null-ptr-deref in mt7915_mmio_wed_init() devm_ioremap()
CVE-2025-38156 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Fix null-ptr-deref in mt7996_mmio_wed_init() devm_ioremap()
CVE-2025-38282 In the Linux kernel, the following vulnerability has been resolved: kernfs: Relax constraint in draining guard The active reference lifecycle provi
CVE-2025-38157 In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k_htc: Abort software beacon handling if disabled A malicious USB dev
CVE-2025-38283 In the Linux kernel, the following vulnerability has been resolved: hisi_acc_vfio_pci: bugfix live migration function without VF device driver If t
CVE-2025-38158 In the Linux kernel, the following vulnerability has been resolved: hisi_acc_vfio_pci: fix XQE dma address error The dma addresses of EQE and AEQE
CVE-2025-38159 In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds Set the
CVE-2025-38285 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARN() in get_bpf_raw_tp_regs syzkaller reported an issue: WARNING: C
CVE-2025-38286 In the Linux kernel, the following vulnerability has been resolved: pinctrl: at91: Fix possible out-of-boundary access at91_gpio_probe() doesn't ch
CVE-2025-38160 In the Linux kernel, the following vulnerability has been resolved: clk: bcm: rpi: Add NULL check in raspberrypi_clk_register() devm_kasprintf() re
CVE-2025-38161 In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix error flow upon firmware failure for RQ destruction Upon RQ dest
CVE-2025-38162 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: prevent overflow in lookup table allocation When cal
CVE-2025-38288 In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Fix smp_processor_id() call trace for preemptible kernels Corre
CVE-2025-38290 In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix node corruption in ar->arvifs list In current WLAN recovery c
CVE-2025-38292 In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix invalid access to memory In ath12k_dp_rx_msdu_coalesce(), rxc
CVE-2025-38163 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on sbi->total_valid_block_count syzbot reported a
CVE-2025-38317 In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix buffer overflow in debugfs If the user tries to write more th
CVE-2025-38164 In the Linux kernel, the following vulnerability has been resolved: f2fs: zone: fix to avoid inconsistence in between SIT and SSA w/ below testcase
CVE-2025-38165 In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix panic when calling skb_linearize The panic can be reproduced
CVE-2025-38166 In the Linux kernel, the following vulnerability has been resolved: bpf: fix ktls panic with sockmap [ 2172.936997] ------------[ cut here ]-------
CVE-2025-38293 In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix node corruption in ar->arvifs list In current WLAN recovery c
CVE-2025-38295 In the Linux kernel, the following vulnerability has been resolved: perf/amlogic: Replace smp_processor_id() with raw_smp_processor_id() in meson_dd
CVE-2025-38167 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: handle hdr_first_de() return value The hdr_first_de() function return
CVE-2025-38318 In the Linux kernel, the following vulnerability has been resolved: perf: arm-ni: Fix missing platform_set_drvdata() Add missing platform_set_drvda
CVE-2025-38168 In the Linux kernel, the following vulnerability has been resolved: perf: arm-ni: Unregister PMUs on probe failure When a resource allocation fails
CVE-2025-38169 In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: Avoid clobbering kernel FPSIMD state with SMSTOP On system with S
CVE-2025-38170 In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: Discard stale CPU state when handling SME traps The logic for han
CVE-2025-38319 In the Linux kernel, the following vulnerability has been resolved: drm/amd/pp: Fix potential NULL pointer dereference in atomctrl_initialize_mc_reg
CVE-2025-38297 In the Linux kernel, the following vulnerability has been resolved: PM: EM: Fix potential division-by-zero error in em_compute_costs() When the dev
CVE-2025-38298 In the Linux kernel, the following vulnerability has been resolved: EDAC/skx_common: Fix general protection fault After loading i10nm_edac (which a
CVE-2025-38299 In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY() ETDM2_IN_BE and ETDM
CVE-2025-38172 In the Linux kernel, the following vulnerability has been resolved: erofs: avoid using multiple devices with different type For multiple devices, b
CVE-2025-38173 In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/cesa - Handle zero-length skcipher requests Do not access rando
CVE-2025-38300 In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ce-cipher - fix error handling in sun8i_ce_cipher_prepare() Fix t
CVE-2025-38174 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Do not double dequeue a configuration request Some of our devices
CVE-2025-38175 In the Linux kernel, the following vulnerability has been resolved: binder: fix yet another UAF in binder_devices Commit e77aff5528a18 ("binderfs:
CVE-2025-38176 In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in binderfs_evict_inode() Running 'stress-ng --binde
CVE-2025-38265 In the Linux kernel, the following vulnerability has been resolved: serial: jsm: fix NPE during jsm_uart_port_init No device was set which caused s
CVE-2025-38092 In the Linux kernel, the following vulnerability has been resolved: ksmbd: use list_first_entry_or_null for opinfo_get_list() The list_first_entry(
CVE-2025-38091 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check stream id dml21 wrapper to get plane_id [Why & How] Fix
CVE-2025-38082 In the Linux kernel, the following vulnerability has been resolved: gpio: virtuser: fix potential out-of-bound write If the caller wrote more chara
CVE-2025-38050 In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix kernel NULL pointer dereference when replacing free hugetlb foli
CVE-2025-38029 In the Linux kernel, the following vulnerability has been resolved: kasan: avoid sleepable page allocation from atomic context apply_to_pte_range()
CVE-2025-38076 In the Linux kernel, the following vulnerability has been resolved: alloc_tag: allocate percpu counters for module tags dynamically When a module g
CVE-2025-38051 In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_fill_dirent There is a race condition i
CVE-2025-38077 In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Avoid buffer overflow in current_password_store()
CVE-2025-38078 In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix race of buffer access at PCM OSS layer The PCM OSS layer tries t
CVE-2025-38003 In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procfs content When the procfs co
CVE-2025-38004 In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates The CAN broadcast manager (CAN
CVE-2025-38031 In the Linux kernel, the following vulnerability has been resolved: padata: do not leak refcount in reorder_work A recent patch that addressed a UA
CVE-2025-38079 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - fix double free in hash_accept If accept(2) is called on s
CVE-2025-38052 In the Linux kernel, the following vulnerability has been resolved: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done Syzbot reporte
CVE-2025-38053 In the Linux kernel, the following vulnerability has been resolved: idpf: fix null-ptr-deref in idpf_features_check idpf_features_check is used to
CVE-2025-38032 In the Linux kernel, the following vulnerability has been resolved: mr: consolidate the ipmr_can_free_table() checks. Guoyu Yin reported a splat in
CVE-2025-38054 In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Limit signal/freq counts in summary output functions The debugfs summ
CVE-2025-38055 In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix segfault with PEBS-via-PT with sample_freq Currently, using
CVE-2025-38057 In the Linux kernel, the following vulnerability has been resolved: espintcp: fix skb leaks A few error paths are missing a kfree_skb.
CVE-2025-38058 In the Linux kernel, the following vulnerability has been resolved: __legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under mount_lock ... or
CVE-2025-38033 In the Linux kernel, the following vulnerability has been resolved: x86/Kconfig: make CFI_AUTO_DEFAULT depend on !RUST or Rust >= 1.88 Calling core
CVE-2025-38059 In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid NULL pointer dereference if no valid csum tree [BUG] When trying r
CVE-2025-38034 In the Linux kernel, the following vulnerability has been resolved: btrfs: correct the order of prelim_ref arguments in btrfs__prelim_ref btrfs_pre
CVE-2025-38035 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: don't restore null sk_state_change queue->state_change is set as par
CVE-2025-38036 In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Perform early GT MMIO initialization to read GMDID VFs need to commu
CVE-2025-38037 In the Linux kernel, the following vulnerability has been resolved: vxlan: Annotate FDB data races The 'used' and 'updated' fields in the FDB entry
CVE-2025-38038 In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate: Remove unnecessary driver_lock in set_boost set_boost is a
CVE-2025-38039 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Avoid WARN_ON when configuring MQPRIO with HTB offload enabled When
CVE-2025-38080 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Increase block_sequence array size [Why] It's possible to gene
CVE-2025-38060 In the Linux kernel, the following vulnerability has been resolved: bpf: copy_verifier_state() should copy 'loop_entry' field The bpf_verifier_stat
CVE-2025-38040 In the Linux kernel, the following vulnerability has been resolved: serial: mctrl_gpio: split disable_ms into sync and no_sync APIs The following s
CVE-2025-38061 In the Linux kernel, the following vulnerability has been resolved: net: pktgen: fix access outside of user given buffer in pktgen_thread_write() H
CVE-2025-38062 In the Linux kernel, the following vulnerability has been resolved: genirq/msi: Store the IOMMU IOVA directly in msi_desc instead of iommu_cookie T
CVE-2025-38041 In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: h616: Reparent GPU clock during frequency changes The H616 manua
CVE-2025-38063 In the Linux kernel, the following vulnerability has been resolved: dm: fix unconditional IO throttle caused by REQ_PREFLUSH When a bio with REQ_PR
CVE-2025-38064 In the Linux kernel, the following vulnerability has been resolved: virtio: break and reset virtio devices on device_shutdown() Hongyu reported a h
CVE-2025-38042 In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: k3-udma-glue: Drop skip_fdq argument from k3_udma_glue_reset_rx_c
CVE-2025-38043 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Set dma_mask for ffa devices Set dma_mask for FFA devices, o
CVE-2025-38044 In the Linux kernel, the following vulnerability has been resolved: media: cx231xx: set device_caps for 417 The video_device for the MPEG encoder d
CVE-2025-38065 In the Linux kernel, the following vulnerability has been resolved: orangefs: Do not truncate file size 'len' is used to store the result of i_size
CVE-2025-38066 In the Linux kernel, the following vulnerability has been resolved: dm cache: prevent BUG_ON by blocking retries on failed device resumes A cache d
CVE-2025-38067 In the Linux kernel, the following vulnerability has been resolved: rseq: Fix segfault on registration when rseq_cs is non-zero The rseq_cs field i
CVE-2025-38068 In the Linux kernel, the following vulnerability has been resolved: crypto: lzo - Fix compression buffer overrun Unlike the decompression code, the
CVE-2025-38069 In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: pci-epf-test: Fix double free that causes kernel to oops Fix a k
CVE-2025-38045 In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix debug actions order The order of actions taken for debug was
CVE-2025-38070 In the Linux kernel, the following vulnerability has been resolved: ASoC: sma1307: Add NULL check in sma1307_setting_loaded() All varibale allocate
CVE-2025-38071 In the Linux kernel, the following vulnerability has been resolved: x86/mm: Check return value from memblock_phys_alloc_range() At least with CONFI
CVE-2025-38072 In the Linux kernel, the following vulnerability has been resolved: libnvdimm/labels: Fix divide error in nd_label_data_init() If a faulty CXL memo
CVE-2025-38081 In the Linux kernel, the following vulnerability has been resolved: spi-rockchip: Fix register out of bounds access Do not write native chip select
CVE-2025-38047 In the Linux kernel, the following vulnerability has been resolved: x86/fred: Fix system hang during S4 resume with FRED enabled Upon a wakeup from
CVE-2025-38073 In the Linux kernel, the following vulnerability has been resolved: block: fix race between set_blocksize and read paths With the new large sector
CVE-2025-38074 In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: protect vq->log_used with vq->mutex The vhost-scsi completion path
CVE-2025-38048 In the Linux kernel, the following vulnerability has been resolved: virtio_ring: Fix data race by tagging event_triggered as racy for KCSAN syzbot
CVE-2025-38075 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix timeout on deleted connection NOPIN response timer may
CVE-2025-38350 In the Linux kernel, the following vulnerability has been resolved: net/sched: Always pass notifications when child class becomes empty Certain cla

Version: 6.14.0-28.28 2025-07-23 14:08:03 UTC

 linux (6.14.0-28.28) plucky; urgency=medium
 .
   * plucky/linux: 6.14.0-28.28 -proposed tracker (LP: #2117649)
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] update annotations scripts
     - [Packaging] debian.master/dkms-versions -- update from kernel-versions
       (main/2025.07.14)
 .
   * Dell AIO backlight is not working, dell_uart_backlight module is missing
     (LP: #2083800)
     - [Config] enable CONFIG_DELL_UART_BACKLIGHT
 .
   * integrated I219-LM network adapter appears to be running too fast, causing
     synchronization issues when using the I219-LM PTP feature (LP: #2116072)
     - e1000e: set fixed clock frequency indication for Nahum 11 and Nahum 13
 .
   * Audio broken on ThinkPad X13s (LP: #2115898)
     - SAUCE: Revert "UBUNTU: SAUCE: Change: cracking sound fix"
 .
   * Ubuntu 24.04+ arm64: screen resolution fixed to 1024x768 with last kernel
     update (LP: #2115068)
     - [Config] Replace FB_HYPERV with DRM_HYPERV
 .
   * [SRU][HPE 24.04] Patch Request for HPE iLO7 VGA device for Gen12 Servers
     (LP: #2114516)
     - drm/mgag200: Added support for the new device G200eH5
 .
   * A process exiting with an open /dev/snapshot fd causes a NULL pointer
     dereference caught by ubuntu_stress_smoke_test:sut-scan (LP: #2113990)
     - libfs: export find_next_child()
     - efivarfs: support freeze/thaw
 .
   * [SRU] Add support for new hotkey of F9 on Thinkpad X9 (LP: #2115022)
     - platform/x86: thinkpad-acpi: Add support for new hotkey for camera
       shutter switch
 .
   * [SRU] Fix GT0: Engine reset when suspend on Intel LNL (LP: #2114697)
     - drm/xe/sched: stop re-submitting signalled jobs
 .
   * CVE-2025-38056
     - devres: Introduce devm_kmemdup_array()
     - ASoC: SOF: Intel: hda: Fix UAF when reloading module
 .
   * Handle IOMMU IVRS entries with mismatched UID on AMD Strix or newer
     platforms (LP: #2115174)
     - iommu/amd: Allow matching ACPI HID devices without matching UIDs
 .
   * [UBUNTU 22.04] kernel: Fix z17 elf platform recognition (LP: #2114450)
     - s390: Add z17 elf platform
 .
   * [UBUNTU 24.04] Kernel: Add CPUMF extended counter set for z17
     (LP: #2114258)
     - s390/cpumf: Update CPU Measurement facility extended counter set support
 .
   * Plucky update: v6.14.8 upstream stable release (LP: #2115266)
     - arm64: dts: rockchip: Assign RT5616 MCLK rate on rk3588-friendlyelec-
       cm3588
     - fs/xattr.c: fix simple_xattr_list to always include security.* xattrs
     - drivers/platform/x86/amd: pmf: Check for invalid sideloaded Smart PC
       Policies
     - drivers/platform/x86/amd: pmf: Check for invalid Smart PC Policies
     - x86/amd_node, platform/x86/amd/hsmp: Have HSMP use SMN through AMD_NODE
     - platform/x86/amd/hsmp: Make amd_hsmp and hsmp_acpi as mutually exclusive
       drivers
     - arm64: dts: rockchip: fix Sige5 RTC interrupt pin
     - riscv: dts: sophgo: fix DMA data-width configuration for CV18xx
     - binfmt_elf: Move brk for static PIE even if ASLR disabled
     - platform/x86/amd/pmc: Declare quirk_spurious_8042 for MECHREVO Wujie
       14XA (GX4HRXL)
     - platform/x86: asus-wmi: Fix wlan_ctrl_by_user detection
     - arm64: dts: imx8mp-var-som: Fix LDO5 shutdown causing SD card timeout
     - cgroup/cpuset: Extend kthread_is_per_cpu() check to all
       PF_NO_SETAFFINITY tasks
     - tracing: fprobe: Fix RCU warning message in list traversal
     - tracing: probes: Fix a possible race in trace_probe_log APIs
     - tpm: tis: Double the timeout B to 4s
     - iio: adc: ad7606: move the software mode configuration
     - iio: adc: ad7606: move software functions into common file
     - HID: thrustmaster: fix memory leak in thrustmaster_interrupts()
     - spi: loopback-test: Do not split 1024-byte hexdumps
     - Bluetooth: MGMT: Fix MGMT_OP_ADD_DEVICE invalid device flags
     - drm/meson: Use 1000ULL when operating with mode->clock
     - tools/net/ynl: ethtool: fix crash when Hardware Clock info is missing
     - tests/ncdevmem: Fix double-free of queue array
     - net: mctp: Ensure keys maintain only one ref to corresponding dev
     - ALSA: seq: Fix delivery of UMP events to group ports
     - ALSA: ump: Fix a typo of snd_ump_stream_msg_device_info
     - net: cadence: macb: Fix a possible deadlock in macb_halt_tx.
     - net: dsa: sja1105: discard incoming frames in BR_STATE_LISTENING
     - nvme-pci: make nvme_pci_npages_prp() __always_inline
     - nvme-pci: acquire cq_poll_lock in nvme_poll_irqdisable
     - ALSA: sh: SND_AICA should depend on SH_DMA_API
     - net: dsa: b53: prevent standalone from trying to forward to other ports
     - vsock/test: Fix occasional failure in SIOCOUTQ tests
     - qlcnic: fix memory leak in qlcnic_sriov_channel_cfg_cmd()
     - octeontx2-pf: Fix ethtool support for SDP representors
     - drm/xe: Save CTX_TIMESTAMP mmio value instead of LRC value
     - netlink: specs: tc: fix a couple of attribute names
     - netlink: specs: tc: all actions are indexed arrays
     - octeontx2-pf: macsec: Fix incorrect max transmit size in TX secy
     - net: ethernet: mtk_eth_soc: fix typo for declaration MT7988 ESW
       capability
     - octeontx2-af: Fix CGX Receive counters
     - octeontx2-pf: Do not reallocate all ntuple filters
     - tsnep: fix timestamping with a stacked DSA driver
     - ublk: fix dead loop when canceling io command
     - NFSv4/pnfs: Reset the layout state after a layoutreturn
     - dmaengine: Revert "dmaengine: dmatest: Fix dmatest waiting less when
       interrupted"
     - Revert "kbuild, rust: use -fremap-path-prefix to make paths relative"
     - udf: Make sure i_lenExtents is uptodate on inode eviction
     - HID: amd_sfh: Fix SRA sensor when it's the only sensor
     - LoongArch: Prevent cond_resched() occurring within kernel-fpu
     - LoongArch: Move __arch_cpu_idle() to .cpuidle.text section
     - LoongArch: Save and restore CSR.CNTC for hibernation
     - LoongArch: Fix MAX_REG_OFFSET calculatio

Source diff to previous version
1786013 Packaging resync
2083800 Dell AIO backlight is not working, dell_uart_backlight module is missing
2116072 integrated I219-LM network adapter appears to be running too fast, causing synchronization issues when using the I219-LM PTP feature
2115898 Audio broken on ThinkPad X13s
2115068 Ubuntu 24.04+ arm64: screen resolution fixed to 1024x768 with last kernel update
2114516 [SRU][HPE 24.04] Patch Request for HPE iLO7 VGA device for Gen12 Servers
2113990 A process exiting with an open /dev/snapshot fd causes a NULL pointer dereference caught by ubuntu_stress_smoke_test:sut-scan
2114450 [UBUNTU 22.04] kernel: Fix z17 elf platform recognition
2114258 [UBUNTU 24.04] Kernel: Add CPUMF extended counter set for z17
2115266 Plucky update: v6.14.8 upstream stable release
2115252 Plucky update: v6.14.7 upstream stable release
2113992 Creating a VXLAN interface with a Fan mapping causes a NULL pointer dereference caught by ubuntu_fan_smoke_test:sut-scan
2117494 [Regression Updates] \
2116061 [UBUNTU 25.04] lszcrypt output shows no cards because ap module has to be loaded manually
CVE-2025-38056 In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: Fix UAF when reloading module hda_generic_machine_select
CVE-2025-38008 In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix race condition in unaccepted memory handling The page alloca
CVE-2025-38014 In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Refactor remove call with idxd_cleanup() helper The idxd_clean
CVE-2025-38015 In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc Memory al
CVE-2025-38005 In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: k3-udma: Add missing locking Recent kernels complain about a mis
CVE-2025-38009 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: disable napi on driver removal A warning on driver removal started
CVE-2025-38010 In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Use a bitmask for UTMI pad power state tracking The current i
CVE-2025-38011 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: csa unmap use uninterruptible lock After process exit to unmap csa
CVE-2025-38016 In the Linux kernel, the following vulnerability has been resolved: HID: bpf: abort dispatch if device destroyed The current HID bpf implementation
CVE-2025-38012 In the Linux kernel, the following vulnerability has been resolved: sched_ext: bpf_iter_scx_dsq_new() should always initialize iterator BPF program
CVE-2025-38018 In the Linux kernel, the following vulnerability has been resolved: net/tls: fix kernel panic when alloc_page failed We cannot set frag_list to NUL
CVE-2025-38019 In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_router: Fix use-after-free when deleting GRE net devices The dr
CVE-2025-38013 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Set n_channels after allocating struct cfg80211_scan_request Ma
CVE-2025-38002 In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: grab ctx->uring_lock around io_uring_show_fdinfo() Not everyth
CVE-2025-38027 In the Linux kernel, the following vulnerability has been resolved: regulator: max20086: fix invalid memory access max20086_parse_regulators_dt() c
CVE-2025-38020 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Disable MACsec offload for uplink representor profile MACsec offload
CVE-2025-38021 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix null check of pipe_ctx->plane_state for update_dchubp_dpp
CVE-2025-38006 In the Linux kernel, the following vulnerability has been resolved: net: mctp: Don't access ifa_index when missing In mctp_dump_addrinfo, ifa_index
CVE-2025-37992 In the Linux kernel, the following vulnerability has been resolved: net_sched: Flush gso_skb list too during ->change() Previously, when reducing a
CVE-2025-38022 In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem
CVE-2025-38028 In the Linux kernel, the following vulnerability has been resolved: NFS/localio: Fix a race in nfs_local_open_fh() Once the clp->cl_uuid.lock has b
CVE-2025-38023 In the Linux kernel, the following vulnerability has been resolved: nfs: handle failure of nfs_get_lock_context in unlock path When memory is insuf
CVE-2025-38007 In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Add NULL check in uclogic_input_configured() devm_kasprintf() ret
CVE-2025-38024 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug Call Trace: <T
CVE-2025-38025 In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7606: check for NULL before calling sw_mode_config() Check that the
CVE-2025-37963 In the Linux kernel, the following vulnerability has been resolved: arm64: bpf: Only mitigate cBPF programs loaded by unprivileged users Support fo
CVE-2025-37948 In the Linux kernel, the following vulnerability has been resolved: arm64: bpf: Add BHB mitigation to the epilogue for cBPF programs A malicious BP
CVE-2025-37994 In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix NULL pointer access This patch ensures that
CVE-2025-37967 In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix deadlock This patch introduces the ucsi_con_
CVE-2025-37950 In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix panic in failed foilio allocation commit 7e119cff9d0a ("ocfs2: conve
CVE-2025-37995 In the Linux kernel, the following vulnerability has been resolved: module: ensure that kobject_put() is safe for module type kobjects In 'lookup_o
CVE-2025-37960 In the Linux kernel, the following vulnerability has been resolved: memblock: Accept allocated memory before use in memblock_double_array() When in
CVE-2025-37996 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix uninitialized memcache pointer in user_mem_abort() Commit fce88
CVE-2025-37949 In the Linux kernel, the following vulnerability has been resolved: xenbus: Use kref to track req lifetime Marek reported seeing a NULL pointer fau
CVE-2025-37954 In the Linux kernel, the following vulnerability has been resolved: smb: client: Avoid race in open_cached_dir with lease breaks A pre-existing val
CVE-2025-37965 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix invalid context error in dml helper [Why] "BUG: sleeping f
CVE-2025-37951 In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Add job to pending list if the reset was skipped When a CL/CSD job tim
CVE-2025-37968 In the Linux kernel, the following vulnerability has been resolved: iio: light: opt3001: fix deadlock due to concurrent flag access The threaded IR
CVE-2025-37969 In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_tagged_fifo Preven
CVE-2025-37970 In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo Prevent st_ls
CVE-2025-37966 In the Linux kernel, the following vulnerability has been resolved: riscv: Fix kernel crash due to PR_SET_TAGGED_ADDR_CTRL When userspace does PR_S
CVE-2025-37957 In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception Previously, commit e
CVE-2025-37958 In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix dereferencing invalid pmd migration entry When migrating a
CVE-2025-37964 In the Linux kernel, the following vulnerability has been resolved: x86/mm: Eliminate window where TLB flushes may be inadvertently skipped tl;dr:
CVE-2025-37971 In the Linux kernel, the following vulnerability has been resolved: staging: bcm2835-camera: Initialise dev in v4l2_dev Commit 42a2f6664e18 ("stagi
CVE-2025-37972 In the Linux kernel, the following vulnerability has been resolved: Input: mtk-pmic-keys - fix possible null pointer dereference In mtk_pmic_keys_p
CVE-2025-37959 In the Linux kernel, the following vulnerability has been resolved: bpf: Scrub packet on bpf_redirect_peer When bpf_redirect_peer is used to redire
CVE-2025-37961 In the Linux kernel, the following vulnerability has been resolved: ipvs: fix uninit-value for saddr in do_output_route4 syzbot reports for uninit-
CVE-2025-37993 In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_class_allocate_dev(): initialize spin lock on device probe Th
CVE-2025-37955 In the Linux kernel, the following vulnerability has been resolved: virtio-net: free xsk_buffs on error in virtnet_xsk_pool_enable() The selftests
CVE-2025-37962 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leak in parse_lease_state() The previous patch that added bou
CVE-2025-37998 In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output_userspace() This patch repl
CVE-2025-37952 In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix UAF in __close_file_table_ids A use-after-free is possible if one th
CVE-2025-37947 In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds stream writes by validating *pos ksmbd_vfs_stream_
CVE-2025-37956 In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent rename with empty string Client can send empty newname string to
CVE-2025-37973 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentati
CVE-2025-37999 In the Linux kernel, the following vulnerability has been resolved: fs/erofs/fileio: call erofs_onlinefolio_split() after bio_add_folio() If bio_ad
CVE-2025-38083 In the Linux kernel, the following vulnerability has been resolved: net_sched: prio: fix a race in prio_tune() Gerrard Tai reported a race conditio

Version: 6.14.0-26.26 2025-07-11 17:08:51 UTC

 linux (6.14.0-26.26) plucky; urgency=medium
 .
   * plucky/linux: 6.14.0-26.26 -proposed tracker (LP: #2116604)
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] update annotations scripts
     - [Packaging] debian.master/dkms-versions -- update from kernel-versions
       (main/2025.07.14)
 .
   * Dell AIO backlight is not working, dell_uart_backlight module is missing
     (LP: #2083800)
     - [Config] enable CONFIG_DELL_UART_BACKLIGHT
 .
   * integrated I219-LM network adapter appears to be running too fast, causing
     synchronization issues when using the I219-LM PTP feature (LP: #2116072)
     - e1000e: set fixed clock frequency indication for Nahum 11 and Nahum 13
 .
   * Audio broken on ThinkPad X13s (LP: #2115898)
     - SAUCE: Revert "UBUNTU: SAUCE: Change: cracking sound fix"
 .
   * Ubuntu 24.04+ arm64: screen resolution fixed to 1024x768 with last kernel
     update (LP: #2115068)
     - [Config] Replace FB_HYPERV with DRM_HYPERV
 .
   * [SRU][HPE 24.04] Patch Request for HPE iLO7 VGA device for Gen12 Servers
     (LP: #2114516)
     - drm/mgag200: Added support for the new device G200eH5
 .
   * A process exiting with an open /dev/snapshot fd causes a NULL pointer
     dereference caught by ubuntu_stress_smoke_test:sut-scan (LP: #2113990)
     - libfs: export find_next_child()
     - efivarfs: support freeze/thaw
 .
   * [SRU] Add support for new hotkey of F9 on Thinkpad X9 (LP: #2115022)
     - platform/x86: thinkpad-acpi: Add support for new hotkey for camera
       shutter switch
 .
   * [SRU] Fix GT0: Engine reset when suspend on Intel LNL (LP: #2114697)
     - drm/xe/sched: stop re-submitting signalled jobs
 .
   * CVE-2025-38056
     - devres: Introduce devm_kmemdup_array()
     - ASoC: SOF: Intel: hda: Fix UAF when reloading module
 .
   * Handle IOMMU IVRS entries with mismatched UID on AMD Strix or newer
     platforms (LP: #2115174)
     - iommu/amd: Allow matching ACPI HID devices without matching UIDs
 .
   * [UBUNTU 22.04] kernel: Fix z17 elf platform recognition (LP: #2114450)
     - s390: Add z17 elf platform
 .
   * [UBUNTU 24.04] Kernel: Add CPUMF extended counter set for z17
     (LP: #2114258)
     - s390/cpumf: Update CPU Measurement facility extended counter set support
 .
   * Plucky update: v6.14.8 upstream stable release (LP: #2115266)
     - arm64: dts: rockchip: Assign RT5616 MCLK rate on rk3588-friendlyelec-
       cm3588
     - fs/xattr.c: fix simple_xattr_list to always include security.* xattrs
     - drivers/platform/x86/amd: pmf: Check for invalid sideloaded Smart PC
       Policies
     - drivers/platform/x86/amd: pmf: Check for invalid Smart PC Policies
     - x86/amd_node, platform/x86/amd/hsmp: Have HSMP use SMN through AMD_NODE
     - platform/x86/amd/hsmp: Make amd_hsmp and hsmp_acpi as mutually exclusive
       drivers
     - arm64: dts: rockchip: fix Sige5 RTC interrupt pin
     - riscv: dts: sophgo: fix DMA data-width configuration for CV18xx
     - binfmt_elf: Move brk for static PIE even if ASLR disabled
     - platform/x86/amd/pmc: Declare quirk_spurious_8042 for MECHREVO Wujie
       14XA (GX4HRXL)
     - platform/x86: asus-wmi: Fix wlan_ctrl_by_user detection
     - arm64: dts: imx8mp-var-som: Fix LDO5 shutdown causing SD card timeout
     - cgroup/cpuset: Extend kthread_is_per_cpu() check to all
       PF_NO_SETAFFINITY tasks
     - tracing: fprobe: Fix RCU warning message in list traversal
     - tracing: probes: Fix a possible race in trace_probe_log APIs
     - tpm: tis: Double the timeout B to 4s
     - iio: adc: ad7606: move the software mode configuration
     - iio: adc: ad7606: move software functions into common file
     - HID: thrustmaster: fix memory leak in thrustmaster_interrupts()
     - spi: loopback-test: Do not split 1024-byte hexdumps
     - Bluetooth: MGMT: Fix MGMT_OP_ADD_DEVICE invalid device flags
     - drm/meson: Use 1000ULL when operating with mode->clock
     - tools/net/ynl: ethtool: fix crash when Hardware Clock info is missing
     - tests/ncdevmem: Fix double-free of queue array
     - net: mctp: Ensure keys maintain only one ref to corresponding dev
     - ALSA: seq: Fix delivery of UMP events to group ports
     - ALSA: ump: Fix a typo of snd_ump_stream_msg_device_info
     - net: cadence: macb: Fix a possible deadlock in macb_halt_tx.
     - net: dsa: sja1105: discard incoming frames in BR_STATE_LISTENING
     - nvme-pci: make nvme_pci_npages_prp() __always_inline
     - nvme-pci: acquire cq_poll_lock in nvme_poll_irqdisable
     - ALSA: sh: SND_AICA should depend on SH_DMA_API
     - net: dsa: b53: prevent standalone from trying to forward to other ports
     - vsock/test: Fix occasional failure in SIOCOUTQ tests
     - qlcnic: fix memory leak in qlcnic_sriov_channel_cfg_cmd()
     - octeontx2-pf: Fix ethtool support for SDP representors
     - drm/xe: Save CTX_TIMESTAMP mmio value instead of LRC value
     - netlink: specs: tc: fix a couple of attribute names
     - netlink: specs: tc: all actions are indexed arrays
     - octeontx2-pf: macsec: Fix incorrect max transmit size in TX secy
     - net: ethernet: mtk_eth_soc: fix typo for declaration MT7988 ESW
       capability
     - octeontx2-af: Fix CGX Receive counters
     - octeontx2-pf: Do not reallocate all ntuple filters
     - tsnep: fix timestamping with a stacked DSA driver
     - ublk: fix dead loop when canceling io command
     - NFSv4/pnfs: Reset the layout state after a layoutreturn
     - dmaengine: Revert "dmaengine: dmatest: Fix dmatest waiting less when
       interrupted"
     - Revert "kbuild, rust: use -fremap-path-prefix to make paths relative"
     - udf: Make sure i_lenExtents is uptodate on inode eviction
     - HID: amd_sfh: Fix SRA sensor when it's the only sensor
     - LoongArch: Prevent cond_resched() occurring within kernel-fpu
     - LoongArch: Move __arch_cpu_idle() to .cpuidle.text section
     - LoongArch: Save and restore CSR.CNTC for hibernation
     - LoongArch: Fix MAX_REG_OFFSET calculatio

Source diff to previous version
1786013 Packaging resync
2083800 Dell AIO backlight is not working, dell_uart_backlight module is missing
2116072 integrated I219-LM network adapter appears to be running too fast, causing synchronization issues when using the I219-LM PTP feature
2115898 Audio broken on ThinkPad X13s
2115068 Ubuntu 24.04+ arm64: screen resolution fixed to 1024x768 with last kernel update
2114516 [SRU][HPE 24.04] Patch Request for HPE iLO7 VGA device for Gen12 Servers
2113990 A process exiting with an open /dev/snapshot fd causes a NULL pointer dereference caught by ubuntu_stress_smoke_test:sut-scan
2114450 [UBUNTU 22.04] kernel: Fix z17 elf platform recognition
2114258 [UBUNTU 24.04] Kernel: Add CPUMF extended counter set for z17
2115266 Plucky update: v6.14.8 upstream stable release
2115252 Plucky update: v6.14.7 upstream stable release
2113992 Creating a VXLAN interface with a Fan mapping causes a NULL pointer dereference caught by ubuntu_fan_smoke_test:sut-scan
2116061 [UBUNTU 25.04] lszcrypt output shows no cards because ap module has to be loaded manually
CVE-2025-38056 In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: Fix UAF when reloading module hda_generic_machine_select
CVE-2025-38008 In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix race condition in unaccepted memory handling The page alloca
CVE-2025-38014 In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Refactor remove call with idxd_cleanup() helper The idxd_clean
CVE-2025-38015 In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc Memory al
CVE-2025-38005 In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: k3-udma: Add missing locking Recent kernels complain about a mis
CVE-2025-38009 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: disable napi on driver removal A warning on driver removal started
CVE-2025-38010 In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Use a bitmask for UTMI pad power state tracking The current i
CVE-2025-38011 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: csa unmap use uninterruptible lock After process exit to unmap csa
CVE-2025-38016 In the Linux kernel, the following vulnerability has been resolved: HID: bpf: abort dispatch if device destroyed The current HID bpf implementation
CVE-2025-38012 In the Linux kernel, the following vulnerability has been resolved: sched_ext: bpf_iter_scx_dsq_new() should always initialize iterator BPF program
CVE-2025-38018 In the Linux kernel, the following vulnerability has been resolved: net/tls: fix kernel panic when alloc_page failed We cannot set frag_list to NUL
CVE-2025-38019 In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_router: Fix use-after-free when deleting GRE net devices The dr
CVE-2025-38013 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Set n_channels after allocating struct cfg80211_scan_request Ma
CVE-2025-38002 In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: grab ctx->uring_lock around io_uring_show_fdinfo() Not everyth
CVE-2025-38027 In the Linux kernel, the following vulnerability has been resolved: regulator: max20086: fix invalid memory access max20086_parse_regulators_dt() c
CVE-2025-38020 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Disable MACsec offload for uplink representor profile MACsec offload
CVE-2025-38021 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix null check of pipe_ctx->plane_state for update_dchubp_dpp
CVE-2025-38006 In the Linux kernel, the following vulnerability has been resolved: net: mctp: Don't access ifa_index when missing In mctp_dump_addrinfo, ifa_index
CVE-2025-37992 In the Linux kernel, the following vulnerability has been resolved: net_sched: Flush gso_skb list too during ->change() Previously, when reducing a
CVE-2025-38022 In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem
CVE-2025-38028 In the Linux kernel, the following vulnerability has been resolved: NFS/localio: Fix a race in nfs_local_open_fh() Once the clp->cl_uuid.lock has b
CVE-2025-38023 In the Linux kernel, the following vulnerability has been resolved: nfs: handle failure of nfs_get_lock_context in unlock path When memory is insuf
CVE-2025-38007 In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Add NULL check in uclogic_input_configured() devm_kasprintf() ret
CVE-2025-38024 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug Call Trace: <T
CVE-2025-38025 In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7606: check for NULL before calling sw_mode_config() Check that the
CVE-2025-37963 In the Linux kernel, the following vulnerability has been resolved: arm64: bpf: Only mitigate cBPF programs loaded by unprivileged users Support fo
CVE-2025-37948 In the Linux kernel, the following vulnerability has been resolved: arm64: bpf: Add BHB mitigation to the epilogue for cBPF programs A malicious BP
CVE-2025-37994 In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix NULL pointer access This patch ensures that
CVE-2025-37967 In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix deadlock This patch introduces the ucsi_con_
CVE-2025-37950 In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix panic in failed foilio allocation commit 7e119cff9d0a ("ocfs2: conve
CVE-2025-37995 In the Linux kernel, the following vulnerability has been resolved: module: ensure that kobject_put() is safe for module type kobjects In 'lookup_o
CVE-2025-37960 In the Linux kernel, the following vulnerability has been resolved: memblock: Accept allocated memory before use in memblock_double_array() When in
CVE-2025-37996 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix uninitialized memcache pointer in user_mem_abort() Commit fce88
CVE-2025-37949 In the Linux kernel, the following vulnerability has been resolved: xenbus: Use kref to track req lifetime Marek reported seeing a NULL pointer fau
CVE-2025-37954 In the Linux kernel, the following vulnerability has been resolved: smb: client: Avoid race in open_cached_dir with lease breaks A pre-existing val
CVE-2025-37965 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix invalid context error in dml helper [Why] "BUG: sleeping f
CVE-2025-37951 In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Add job to pending list if the reset was skipped When a CL/CSD job tim
CVE-2025-37968 In the Linux kernel, the following vulnerability has been resolved: iio: light: opt3001: fix deadlock due to concurrent flag access The threaded IR
CVE-2025-37969 In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_tagged_fifo Preven
CVE-2025-37970 In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo Prevent st_ls
CVE-2025-37966 In the Linux kernel, the following vulnerability has been resolved: riscv: Fix kernel crash due to PR_SET_TAGGED_ADDR_CTRL When userspace does PR_S
CVE-2025-37957 In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception Previously, commit e
CVE-2025-37958 In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix dereferencing invalid pmd migration entry When migrating a
CVE-2025-37964 In the Linux kernel, the following vulnerability has been resolved: x86/mm: Eliminate window where TLB flushes may be inadvertently skipped tl;dr:
CVE-2025-37971 In the Linux kernel, the following vulnerability has been resolved: staging: bcm2835-camera: Initialise dev in v4l2_dev Commit 42a2f6664e18 ("stagi
CVE-2025-37972 In the Linux kernel, the following vulnerability has been resolved: Input: mtk-pmic-keys - fix possible null pointer dereference In mtk_pmic_keys_p
CVE-2025-37959 In the Linux kernel, the following vulnerability has been resolved: bpf: Scrub packet on bpf_redirect_peer When bpf_redirect_peer is used to redire
CVE-2025-37961 In the Linux kernel, the following vulnerability has been resolved: ipvs: fix uninit-value for saddr in do_output_route4 syzbot reports for uninit-
CVE-2025-37993 In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_class_allocate_dev(): initialize spin lock on device probe Th
CVE-2025-37955 In the Linux kernel, the following vulnerability has been resolved: virtio-net: free xsk_buffs on error in virtnet_xsk_pool_enable() The selftests
CVE-2025-37962 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leak in parse_lease_state() The previous patch that added bou
CVE-2025-37998 In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output_userspace() This patch repl
CVE-2025-37952 In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix UAF in __close_file_table_ids A use-after-free is possible if one th
CVE-2025-37947 In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds stream writes by validating *pos ksmbd_vfs_stream_
CVE-2025-37956 In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent rename with empty string Client can send empty newname string to
CVE-2025-37973 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentati
CVE-2025-37999 In the Linux kernel, the following vulnerability has been resolved: fs/erofs/fileio: call erofs_onlinefolio_split() after bio_add_folio() If bio_ad
CVE-2025-38083 In the Linux kernel, the following vulnerability has been resolved: net_sched: prio: fix a race in prio_tune() Gerrard Tai reported a race conditio

Version: 6.14.0-24.24 2025-06-15 14:08:44 UTC

 linux (6.14.0-24.24) plucky; urgency=medium
 .
   * plucky/linux: 6.14.0-24.24 -proposed tracker (LP: #2114501)
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] update variants
     - [Packaging] update annotations scripts
     - [Packaging] debian.master/dkms-versions -- update from kernel-versions
       (main/2025.06.16)
 .
   * Apple spi keyboard/trackpad not working 25.04 (LP: #2107976)
     - iommu/vt-d: Restore context entry setup order for aliased devices
 .
   * Unexpected system reboot at loading GUI session on some AMD platforms
     (LP: #2112462)
     - drm/amdgpu/hdp4: use memcfg register to post the write for HDP flush
     - drm/amdgpu/hdp5: use memcfg register to post the write for HDP flush
     - drm/amdgpu/hdp5.2: use memcfg register to post the write for HDP flush
     - drm/amdgpu/hdp6: use memcfg register to post the write for HDP flush
     - drm/amdgpu/hdp7: use memcfg register to post the write for HDP flush
 .
   * Fix ARL-U/H suspend issues (LP: #2112469)
     - platform/x86/intel/pmc: Remove duplicate enum
     - platform/x86:intel/pmc: Make tgl_core_generic_init() static
     - platform/x86:intel/pmc: Create generic_core_init() for all platforms
     - platform/x86/intel/pmc: Remove simple init functions
     - platform/x86/intel/pmc: Add Arrow Lake U/H support to intel_pmc_core
       driver
     - platform/x86/intel/pmc: Fix Arrow Lake U/H NPU PCI ID
 .
   * [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
     (LP: #2114174)
     - s390/pci: Remove redundant bus removal and disable from
       zpci_release_device()
     - s390/pci: Prevent self deletion in disable_slot()
     - s390/pci: Allow re-add of a reserved but not yet removed device
     - s390/pci: Serialize device addition and removal
 .
   * [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
     (LP: #2114174) // CVE-2025-37946
     - s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has
       child VFs
 .
   * [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
     (LP: #2114174) // CVE-2025-37974
     - s390/pci: Fix missing check for zpci_create_device() error return
 .
   * HW accelerated video playback causes VCN timeout on VCN 4.0.5 (AMD Strix)
     (LP: #2112582)
     - drm/amdgpu: read back register after written for VCN v4.0.5
 .
   * kvmppc_set_passthru_irq_hv: Could not assign IRQ map traces are seen when
     pci device is attached to kvm guest when "xive=off" is set (LP: #2109951)
     - KVM: PPC: Book3S HV: Fix IRQ map warnings with XICS on pSeries KVM Guest
 .
   * System will restart while resuming with SATA HDD or nvme installed with
     password set (LP: #2110090)
     - PCI: Explicitly put devices into D0 when initializing
 .
   * VM boots slowly with large-BAR GPU Passthrough (Root Cause Fix SRU)
     (LP: #2111861)
     - mm: Provide address mask in struct follow_pfnmap_args
     - vfio/type1: Convert all vaddr_get_pfns() callers to use vfio_batch
     - vfio/type1: Catch zero from pin_user_pages_remote()
     - vfio/type1: Use vfio_batch for vaddr_get_pfns()
     - vfio/type1: Use consistent types for page counts
     - vfio/type1: Use mapping page mask for pfnmaps
 .
   * Plucky update: v6.14.6 upstream stable release (LP: #2113881)
     - Revert "rndis_host: Flag RNDIS modems as WWAN devices"
     - ALSA: hda/realtek - Add more HP laptops which need mute led fixup
     - ALSA: usb-audio: Add retry on -EPROTO from usb_set_interface()
     - ALSA: usb-audio: Add second USB ID for Jabra Evolve 65 headset
     - ASoC: renesas: rz-ssi: Use NOIRQ_SYSTEM_SLEEP_PM_OPS()
     - btrfs: fix COW handling in run_delalloc_nocow()
     - cpufreq: intel_pstate: Unchecked MSR aceess in legacy mode
     - drm/fdinfo: Protect against driver unbind
     - EDAC/altera: Test the correct error reg offset
     - EDAC/altera: Set DDR and SDMMC interrupt mask before registration
     - i2c: imx-lpi2c: Fix clock count when probe defers
     - pinctrl: airoha: fix wrong PHY LED mapping and PHY2 LED defines
     - perf/x86/intel: Only check the group flag for X86 leader
     - amd-xgbe: Fix to ensure dependent features are toggled with RX checksum
       offload
     - mm/memblock: pass size instead of end to memblock_set_node()
     - mm/memblock: repeat setting reserved region nid if array is doubled
     - mmc: renesas_sdhi: Fix error handling in renesas_sdhi_probe
     - spi: tegra114: Don't fail set_cs_timing when delays are zero
     - tracing: Do not take trace_event_sem in print_event_fields()
     - x86/boot/sev: Support memory acceptance in the EFI stub under SVSM
     - dm-integrity: fix a warning on invalid table line
     - dm: always update the array size in realloc_argv on success
     - drm/amdgpu: Fix offset for HDP remap in nbio v7.11
     - drm: Select DRM_KMS_HELPER from DRM_DEBUG_DP_MST_TOPOLOGY_REFS
     - iommu/arm-smmu-v3: Fix iommu_device_probe bug due to duplicated stream
       ids
     - iommu/arm-smmu-v3: Fix pgsize_bit for sva domains
     - iommu/vt-d: Apply quirk_iommu_igfx for 8086:0044 (QM57/QS57)
     - platform/x86/amd: pmc: Require at least 2.5 seconds between HW sleep
       cycles
     - platform/x86/intel-uncore-freq: Fix missing uncore sysfs during CPU
       hotplug
     - smb: client: fix zero length for mkdir POSIX create context
     - cpufreq: Avoid using inconsistent policy->min and policy->max
     - cpufreq: Fix setting policy limits when frequency tables are used
     - bcachefs: Remove incorrect __counted_by annotation
     - drm/amd/display: Default IPS to RCG_IN_ACTIVE_IPS2_IN_OFF
     - ASoC: soc-core: Stop using of_property_read_bool() for non-boolean
       properties
     - ASoC: cs-amp-lib-test: Don't select SND_SOC_CS_AMP_LIB
     - firmware: cs_dsp: tests: Depend on FW_CS_DSP rather then enabling it
     - ASoC: soc-pcm: Fix hw_params() and DAPM widget sequence
     - Revert "UBUNTU: SAUCE: powerpc64/ftrace: fix module loading without

Source diff to previous version
1786013 Packaging resync
2107976 Apple spi keyboard/trackpad not working 25.04
2112469 Fix ARL-U/H suspend issues
2114174 [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
2109951 kvmppc_set_passthru_irq_hv: Could not assign IRQ map traces are seen when pci device is attached to kvm guest when \
2110090 System will restart while resuming with SATA HDD or nvme installed with password set
2111861 VM boots slowly with large-BAR GPU Passthrough (Root Cause Fix SRU)
2113881 Plucky update: v6.14.6 upstream stable release
2109543 deadlock on cpu_hotplug_lock in __accept_page()
2105402 Plucky fails to boot on (older) Macs
CVE-2025-37946 In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has child VFs W
CVE-2025-37974 In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix missing check for zpci_create_device() error return The zpci_crea
CVE-2025-37903 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix slab-use-after-free in hdcp The HDCP code in amdgpu_dm_hdc
CVE-2025-37904 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix the inode leak in btrfs_iget() [BUG] There is a bug report that a sy
CVE-2025-37905 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Balance device refcount when destroying devices Using devic
CVE-2025-37906 In the Linux kernel, the following vulnerability has been resolved: ublk: fix race between io_uring_cmd_complete_in_task and ublk_cancel_cmd ublk_c
CVE-2025-37907 In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix locking order in ivpu_job_submit Fix deadlock in job submission
CVE-2025-37908 In the Linux kernel, the following vulnerability has been resolved: mm, slab: clean up slab->obj_exts always When memory allocation profiling is di
CVE-2025-37933 In the Linux kernel, the following vulnerability has been resolved: octeon_ep: Fix host hang issue during device reboot When the host loses heartbe
CVE-2025-37909 In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Fix memleak issue when GSO enabled Always map the `skb` to the LS
CVE-2025-37910 In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Fix NULL dereference in Adva board SMA sysfs operations On Adva board
CVE-2025-37894 In the Linux kernel, the following vulnerability has been resolved: net: use sock_gen_put() when sk_state is TCP_TIME_WAIT It is possible for a poi
CVE-2025-37934 In the Linux kernel, the following vulnerability has been resolved: ASoC: simple-card-utils: Fix pointer check in graph_util_parse_link_direction A
CVE-2025-37911 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix out-of-bound memcpy() during ethtool -w When retrieving the FW cor
CVE-2025-37895 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix error handling path in bnxt_init_chip() WARN_ON() is triggered in
CVE-2025-37935 In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix SER panic with 4GB+ RAM If the mtk_poll_rx() fu
CVE-2025-37891 In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: Fix buffer overflow at UMP SysEx message conversion The conversion f
CVE-2025-37912 In the Linux kernel, the following vulnerability has been resolved: ice: Check VF VSI Pointer Value in ice_vc_add_fdir_fltr() As mentioned in the c
CVE-2025-37913 In the Linux kernel, the following vulnerability has been resolved: net_sched: qfq: Fix double list add in class with netem as child qdisc As descr
CVE-2025-37914 In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: Fix double list add in class with netem as child qdisc As descr
CVE-2025-37915 In the Linux kernel, the following vulnerability has been resolved: net_sched: drr: Fix double list add in class with netem as child qdisc As descr
CVE-2025-37916 In the Linux kernel, the following vulnerability has been resolved: pds_core: remove write-after-free of client_id A use-after-free error popped up
CVE-2025-37917 In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk-star-emac: fix spinlock recursion issues on rx/tx poll Use s
CVE-2025-37918 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: avoid NULL pointer dereference in skb_dequeue() A NULL pointe
CVE-2025-37919 In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp: Fix NULL pointer deref in acp_i2s_set_tdm_slot Update chip data
CVE-2025-37896 In the Linux kernel, the following vulnerability has been resolved: spi: spi-mem: Add fix to avoid divide error For some SPI flash memory operation
CVE-2025-37920 In the Linux kernel, the following vulnerability has been resolved: xsk: Fix race condition in AF_XDP generic RX path Move rx_lock from xsk_socket
CVE-2025-37921 In the Linux kernel, the following vulnerability has been resolved: vxlan: vnifilter: Fix unlocked deletion of default FDB entry When a VNI is dele
CVE-2025-37897 In the Linux kernel, the following vulnerability has been resolved: wifi: plfxlc: Remove erroneous assert in plfxlc_mac_release plfxlc_mac_release(
CVE-2025-37898 In the Linux kernel, the following vulnerability has been resolved: powerpc64/ftrace: fix module loading without patchable function entries get_stu
CVE-2025-37922 In the Linux kernel, the following vulnerability has been resolved: book3s64/radix : Align section vmemmap start address to PAGE_SIZE A vmemmap alt
CVE-2025-37923 In the Linux kernel, the following vulnerability has been resolved: tracing: Fix oob write in trace_seq_to_buffer() syzbot reported this bug: =====
CVE-2025-37899 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in session logoff The sess->user object can currently
CVE-2025-37924 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL
CVE-2025-37926 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_session_rpc_open A UAF issue can occur due t
CVE-2025-37900 In the Linux kernel, the following vulnerability has been resolved: iommu: Fix two issues in iommu_copy_struct_from_user() In the review for iommu_
CVE-2025-37927 In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid There is a strin
CVE-2025-37928 In the Linux kernel, the following vulnerability has been resolved: dm-bufio: don't schedule in atomic context A BUG was reported as below when CON
CVE-2025-37990 In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage() The fun
CVE-2025-37901 In the Linux kernel, the following vulnerability has been resolved: irqchip/qcom-mpm: Prevent crash when trying to handle non-wake GPIOs On Qualcom
CVE-2025-37936 In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: KVM: Mask PEBS_ENABLE loaded for guest with vCPU's value. When
CVE-2025-37991 In the Linux kernel, the following vulnerability has been resolved: parisc: Fix double SIGFPE crash Camm noticed that on parisc a SIGFPE exception
CVE-2025-37929 In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Add missing sentinels to Spectre-BHB MIDR arrays Commit a5951389
CVE-2025-37930 In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: Fix WARN_ON in nouveau_fence_context_kill() Nouveau is mostly desi
CVE-2025-37931 In the Linux kernel, the following vulnerability has been resolved: btrfs: adjust subpage bit start based on sectorsize When running machines with
CVE-2025-37798 In the Linux kernel, the following vulnerability has been resolved: codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog() After making
CVE-2025-37997 In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types Region locking introduced in
CVE-2025-37890 In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc As

Version: 6.14.0-22.22 2025-05-21 18:09:17 UTC

 linux (6.14.0-22.22) plucky; urgency=medium
 .
   * plucky/linux: 6.14.0-22.22 -proposed tracker (LP: #2111404)
 .
   * snapd has high CPU usage for exactly 150 seconds every 5, 7.5 or 10 minutes
     (LP: #2110289)
     - fs/eventpoll: fix endless busy loop after timeout has expired
 .

2110289 snapd has high CPU usage for exactly 150 seconds every 5, 7.5 or 10 minutes



About   -   Send Feedback to @ubuntu_updates