UbuntuUpdates.org

Package "linux-modules-6.8.0-136-generic"

Name: linux-modules-6.8.0-136-generic

Description:

Linux kernel extra modules for version 6.8.0 on 64 bit x86 SMP

Latest version: 6.8.0-136.136~22.04.1
Release: jammy (22.04)
Level: updates
Repository: main
Head package: linux-hwe-6.8

Links


Download "linux-modules-6.8.0-136-generic"


Other versions of "linux-modules-6.8.0-136-generic" in Jammy

Repository Area Version
proposed main 6.8.0-136.136~22.04.1
PPA: Canonical Kernel Team 6.8.0-136.136~22.04.1

Changelog

Version: 6.8.0-136.136~22.04.1 2026-07-23 21:08:25 UTC
No changelog available yet.
Source diff to previous version

Version: 6.8.0-134.134~22.04.1 2026-07-10 01:08:58 UTC

  linux-hwe-6.8 (6.8.0-134.134~22.04.1) jammy; urgency=medium

  * jammy/linux-hwe-6.8: 6.8.0-134.134~22.04.1 -proposed tracker (LP: #2158430)

  [ Ubuntu: 6.8.0-134.134 ]

  * noble/linux: 6.8.0-134.134 -proposed tracker (LP: #2158432)
  * ext4: writeback causes kernel oops when low on space (LP: #2158377)
    - ext4: get rid of ppath in get_ext_path()

Source diff to previous version
2158377 ext4: writeback causes kernel oops when low on space

Version: 6.8.0-124.124~22.04.1 2026-05-29 00:07:36 UTC

  linux-hwe-6.8 (6.8.0-124.124~22.04.1) jammy; urgency=medium

  [ Ubuntu: 6.8.0-124.124 ]

  * GRO managed-frag use-after-free leading to local privilege escalation
    (LP: #2154172)
    - net: gro: don't merge zcopy skbs

  [ Ubuntu: 6.8.0-121.121 ]

  * apparmor (LP: #2151747)
    - apparmor: Fix incorrect profile->signal range check
    - SAUCE: apparmor: pass big_resp to handler
    - SAUCE: apparmor: remove redundant kref_init for listener->count
    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb
  * apparmor (LP: #2151747) // CVE-2026-47337
    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr
  * apparmor (LP: #2151747) // CVE-2026-47336
    - SAUCE: apparmor: fix use of unintialized variable in net opt level
  * apparmor (LP: #2151747) // CVE-2026-47335
    - SAUCE: apparmor: fix possible NULL pointer dereference by adding a NULL
      check
  * apparmor (LP: #2151747) // CVE-2026-47334
    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock
  * apparmor (LP: #2151747) // CVE-2026-47333
    - SAUCE: apparmor: fix dfa unpacking size of the notification filter
  * apparmor (LP: #2151747) // CVE-2026-47332
    - SAUCE: apparmor: fix size check against type instead of pointer
  * apparmor (LP: #2151747) // CVE-2026-47331
    - SAUCE: apparmor: fix changing rules list without a lock
  * apparmor: LLVM/clang build failure due to uninitialized variable in
    notify.c (LP: #2148809) // CVE-2026-47330
    - SAUCE: apparmor: initialize variable used in uninitialized context
  * apparmor (LP: #2151747) // CVE-2026-47329
    - SAUCE: apparmor: fix name validation bypass on notification
  * apparmor (LP: #2151747) // CVE-2026-47327 // CVE-2026-47328
    - SAUCE: apparmor: fix glob memory leak after kstrdup
  * apparmor (LP: #2151747) // CVE-2026-47326
    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer

  [ Ubuntu: 6.8.0-120.120 ]

  * noble/linux: 6.8.0-120.120 -proposed tracker (LP: #2153733)
  * Packaging resync (LP: #1786013)
    - [Packaging] update annotations scripts
  * CVE-2026-46300
    - net: skbuff: preserve shared-frag marker during coalescing
    - net: skbuff: propagate shared-frag marker through frag-transfer helpers
  * net/rds: reset op_nents when zerocopy page pin fails (LP: #2153962)
    - net/rds: reset op_nents when zerocopy page pin fails
  * CVE-2026-46333
    - ptrace: slightly saner 'get_dumpable()' logic
  * CVE-2026-43500
    - rxrpc: Fix conn-level packet handling to unshare RESPONSE packets
    - rxrpc: Parse received packets before dealing with timeouts
    - rxrpc: Fix potential UAF after skb_unshare() failure
    - rxrpc: Fix rxrpc_input_call_event() to only unshare DATA packets
    - rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
  * CVE-2026-31676 // CVE-2026-43500
    - rxrpc: only handle RESPONSE during service challenge
  * CVE-2026-43284
    - xfrm: esp: avoid in-place decrypt on shared skb frags

 -- Manuel Diewald <email address hidden> Tue, 26 May 2026 14:15:46 +0200

Source diff to previous version
2154172 GRO managed-frag use-after-free leading to local privilege escalation
2151747 AppArmor Vulnerabilities
2148809 apparmor: LLVM/clang build failure due to uninitialized variable in notify.c
1786013 Packaging resync
2153962 net/rds: reset op_nents when zerocopy page pin fails
CVE-2026-47337 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible N ...
CVE-2026-47336 Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an unin ...
CVE-2026-47335 Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer d ...
CVE-2026-47334 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which in ...
CVE-2026-47333 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which ca ...
CVE-2026-47332 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which in ...
CVE-2026-47331 Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire ...
CVE-2026-47330 Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which ca ...
CVE-2026-47329 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to val ...
CVE-2026-47327 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible N ...
CVE-2026-47328 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which in ...
CVE-2026-47326 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory lea ...
CVE-2026-46300 In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() c
CVE-2026-46333 In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fu
CVE-2026-43500 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA
CVE-2026-31676 In the Linux kernel, the following vulnerability has been resolved: rxrpc: only handle RESPONSE during service challenge Only process RESPONSE pack
CVE-2026-43284 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can atta

Version: 6.8.0-117.117~22.04.1 2026-05-14 21:07:30 UTC

  linux-hwe-6.8 (6.8.0-117.117~22.04.1) jammy; urgency=medium

  * jammy/linux-hwe-6.8: 6.8.0-117.117~22.04.1 -proposed tracker (LP: #2151068)

  [ Ubuntu: 6.8.0-117.117 ]

  * noble/linux: 6.8.0-117.117 -proposed tracker (LP: #2151070)
  * CVE-2026-31419
    - net: bonding: fix use-after-free in bond_xmit_broadcast()
  * CVE-2026-31431
    - crypto: scatterwalk - Backport memcpy_sglist()
    - crypto: algif_aead - use memcpy_sglist() instead of null skcipher
    - crypto: algif_aead - Revert to operating out-of-place
    - crypto: algif_aead - snapshot IV for async AEAD requests
    - crypto: authenc - use memcpy_sglist() instead of null skcipher
    - crypto: authencesn - Do not place hiseq at end of dst for out-of-place
      decryption
    - crypto: authencesn - Fix src offset when decrypting in-place
    - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
    - crypto: algif_aead - Fix minimum RX size check for decryption
  * CVE-2026-31533
    - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
  * CVE-2026-31504
    - net: fix fanout UAF in packet_release() via NETDEV_UP race

 -- Manuel Diewald <email address hidden> Wed, 06 May 2026 15:19:52 +0200

Source diff to previous version
CVE-2026-31419 In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broadcast() bond_xmit_broadcast()
CVE-2026-31431 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commi
CVE-2026-31533 In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUS
CVE-2026-31504 In the Linux kernel, the following vulnerability has been resolved: net: fix fanout UAF in packet_release() via NETDEV_UP race `packet_release()` h

Version: 6.8.0-111.111~22.04.1 2026-04-30 18:08:30 UTC

  linux-hwe-6.8 (6.8.0-111.111~22.04.1) jammy; urgency=medium

  * jammy/linux-hwe-6.8: 6.8.0-111.111~22.04.1 -proposed tracker (LP: #2147888)

  [ Ubuntu: 6.8.0-111.111 ]

  * noble/linux: 6.8.0-111.111 -proposed tracker (LP: #2147890)
  * CVE-2026-23231
    - netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
  * macvlan: observe an RCU grace period in macvlan_common_newlink() error
    path (LP: #2144380) // CVE-2026-23209
    - macvlan: observe an RCU grace period in macvlan_common_newlink() error
      path
  * CVE-2026-23112
    - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec

 -- Stefan Bader <email address hidden> Tue, 14 Apr 2026 17:37:42 +0200

2144380 macvlan: observe an RCU grace period in macvlan_common_newlink() error path
CVE-2026-23231 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addc
CVE-2026-23209 In the Linux kernel, the following vulnerability has been resolved: macvlan: fix error recovery in macvlan_common_newlink() valis provided a nice r
CVE-2026-23112 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_i



About   -   Send Feedback to @ubuntu_updates