[ubuntu/bionic-updates] linux-azure-4.15 4.15.0-1162.177 (Accepted)
Andy Whitcroft
apw at canonical.com
Mon Mar 6 15:18:41 UTC 2023
linux-azure-4.15 (4.15.0-1162.177) bionic; urgency=medium
* bionic/linux-azure-4.15: 4.15.0-1162.177 -proposed tracker (LP: #2004396)
* Bionic update: upstream stable patchset 2023-01-20 (LP: #2003596)
- [Config] azure-4.15: updateconfigs for INET_TABLE_PERTURB_ORDER
[ Ubuntu: 4.15.0-207.218 ]
* bionic/linux: 4.15.0-207.218 -proposed tracker (LP: #2008419)
* rtcpie in timers from ubuntu_kernel_selftests randomly failing
(LP: #1814234)
- SAUCE: selftest: rtctest: Force passing unreliable subtest
* btrfs/154: rename fails with EOVERFLOW when calculating item size during
item key collision (LP: #2004132)
- btrfs: correctly calculate item size used when item key collision happens
* CVE-2021-3669
- ipc: replace costly bailout check in sysvipc_find_ipc()
* Bionic update: upstream stable patchset 2023-02-06 (LP: #2006403)
- libtraceevent: Fix build with binutils 2.35
- once: Fix panic when module unload
- once: add DO_ONCE_SLOW() for sleepable contexts
- mm/khugepaged: fix GUP-fast interaction by sending IPI
- mm/khugepaged: invoke MMU notifiers in shmem/file collapse paths
- block: unhash blkdev part inode when the part is deleted
- ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
- can: sja1000: fix size of OCR_MODE_MASK define
- can: mcba_usb: Fix termination command argument
- ASoC: ops: Correct bounds check for second channel on SX controls
- perf script python: Remove explicit shebang from tests/attr.c
- udf: Discard preallocation before extending file with a hole
- udf: Drop unused arguments of udf_delete_aext()
- udf: Fix preallocation discarding at indirect extent boundary
- udf: Do not bother looking for prealloc extents if i_lenExtents matches
i_size
- udf: Fix extending file within last block
- usb: gadget: uvc: Prevent buffer overflow in setup handler
- USB: serial: option: add Quectel EM05-G modem
- USB: serial: cp210x: add Kamstrup RF sniffer PIDs
- igb: Initialize mailbox message for VF reset
- net: loopback: use NET_NAME_PREDICTABLE for name_assign_type
- usb: musb: remove extra check in musb_gadget_vbus_draw
- ARM: dts: qcom: apq8064: fix coresight compatible
- drivers: soc: ti: knav_qmss_queue: Mark knav_acc_firmwares as static
- arm: dts: spear600: Fix clcd interrupt
- soc: ti: smartreflex: Fix PM disable depth imbalance in omap_sr_probe
- arm64: dts: mediatek: mt6797: Fix 26M oscillator unit name
- ARM: dts: dove: Fix assigned-addresses for every PCIe Root Port
- ARM: dts: armada-370: Fix assigned-addresses for every PCIe Root Port
- ARM: dts: armada-xp: Fix assigned-addresses for every PCIe Root Port
- ARM: dts: armada-375: Fix assigned-addresses for every PCIe Root Port
- ARM: dts: armada-38x: Fix assigned-addresses for every PCIe Root Port
- ARM: dts: armada-39x: Fix assigned-addresses for every PCIe Root Port
- ARM: dts: turris-omnia: Add ethernet aliases
- ARM: dts: turris-omnia: Add switch port 6 node
- pstore/ram: Fix error return code in ramoops_probe()
- ARM: mmp: fix timer_read delay
- pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
- tpm/tpm_crb: Fix error message in __crb_relinquish_locality()
- cpuidle: dt: Return the correct numbers of parsed idle states
- alpha: fix syscall entry in !AUDUT_SYSCALL case
- PM: hibernate: Fix mistake in kerneldoc comment
- fs: don't audit the capability check in simple_xattr_list()
- perf: Fix possible memleak in pmu_dev_alloc()
- timerqueue: Use rb_entry_safe() in timerqueue_getnext()
- ocfs2: fix memory leak in ocfs2_stack_glue_init()
- MIPS: vpe-mt: fix possible memory leak while module exiting
- MIPS: vpe-cmp: fix possible memory leak while module exiting
- PNP: fix name memory leak in pnp_alloc_dev()
- irqchip: gic-pm: Use pm_runtime_resume_and_get() in gic_probe()
- libfs: add DEFINE_SIMPLE_ATTRIBUTE_SIGNED for signed value
- lib/notifier-error-inject: fix error when writing -errno to debugfs file
- rapidio: fix possible name leaks when rio_add_device() fails
- rapidio: rio: fix possible name leak in rio_register_mport()
- ACPICA: Fix use-after-free in acpi_ut_copy_ipackage_to_ipackage()
- uprobes/x86: Allow to probe a NOP instruction with 0x66 prefix
- x86/xen: Fix memory leak in xen_init_lock_cpu()
- platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]()
- MIPS: BCM63xx: Add check for NULL for clk in clk_enable
- fs: sysv: Fix sysv_nblocks() returns wrong value
- rapidio: fix possible UAF when kfifo_alloc() fails
- eventfd: change int to __u64 in eventfd_signal() ifndef CONFIG_EVENTFD
- hfs: Fix OOB Write in hfs_asc2mac
- rapidio: devices: fix missing put_device in mport_cdev_open
- wifi: ath9k: hif_usb: fix memory leak of urbs in
ath9k_hif_usb_dealloc_tx_urbs()
- wifi: ath9k: hif_usb: Fix use-after-free in ath9k_hif_usb_reg_in_cb()
- media: i2c: ad5820: Fix error path
- spi: Update reference to struct spi_controller
- media: vivid: fix compose size exceed boundary
- mtd: Fix device name leak when register device failed in add_mtd_device()
- media: camss: Clean up received buffers on failed start of streaming
- drm/radeon: Add the missed acpi_put_table() to fix memory leak
- ASoC: pxa: fix null-pointer dereference in filter()
- regulator: core: fix unbalanced of node refcount in regulator_dev_lookup()
- ima: Fix misuse of dereference of pointer in template_desc_init_fields()
- wifi: ath10k: Fix return value in ath10k_pci_init()
- mtd: lpddr2_nvm: Fix possible null-ptr-deref
- Input: elants_i2c - properly handle the reset GPIO when power is off
- media: solo6x10: fix possible memory leak in solo_sysfs_init()
- media: platform: exynos4-is: Fix error handling in fimc_md_init()
- HID: hid-sensor-custom: set fixed size for custom attributes
- ALSA: seq: fix undefined behavior in bit shift for
SNDRV_SEQ_FILTER_USE_EVENT
- clk: rockchip: Fix memory leak in rockchip_clk_register_pll()
- mtd: maps: pxa2xx-flash: fix memory leak in probe
- media: imon: fix a race condition in send_packet()
- pinctrl: pinconf-generic: add missing of_node_put()
- media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()
- media: s5p-mfc: Add variant data for MFC v7 hardware for Exynos 3250 SoC
- NFSv4.2: Fix a memory stomp in decode_attr_security_label
- NFSv4: Fix a deadlock between nfs4_open_recover_helper() and delegreturn
- ALSA: asihpi: fix missing pci_disable_device()
- drm/radeon: Fix PCI device refcount leak in radeon_atrm_get_bios()
- drm/amdgpu: Fix PCI device refcount leak in amdgpu_atrm_get_bios()
- ASoC: pcm512x: Fix PM disable depth imbalance in pcm512x_probe
- bonding: uninitialized variable in bond_miimon_inspect()
- regulator: core: fix module refcount leak in set_supply()
- media: saa7164: fix missing pci_disable_device()
- ALSA: mts64: fix possible null-ptr-defer in snd_mts64_interrupt
- SUNRPC: Fix missing release socket in rpc_sockname()
- NFSv4.x: Fail client initialisation if state manager thread can't run
- mmc: moxart: fix return value check of mmc_add_host()
- mmc: mxcmmc: fix return value check of mmc_add_host()
- mmc: rtsx_usb_sdmmc: fix return value check of mmc_add_host()
- mmc: toshsd: fix return value check of mmc_add_host()
- mmc: vub300: fix return value check of mmc_add_host()
- mmc: wmt-sdmmc: fix return value check of mmc_add_host()
- mmc: via-sdmmc: fix return value check of mmc_add_host()
- mmc: wbsd: fix return value check of mmc_add_host()
- mmc: mmci: fix return value check of mmc_add_host()
- media: c8sectpfe: Add of_node_put() when breaking out of loop
- media: coda: Add check for dcoda_iram_alloc
- media: coda: Add check for kmalloc
- clk: samsung: Fix memory leak in _samsung_clk_register_pll()
- wifi: rtl8xxxu: Add __packed to struct rtl8723bu_c2h
- wifi: brcmfmac: Fix error return code in brcmf_sdio_download_firmware()
- blktrace: Fix output non-blktrace event when blk_classic option enabled
- net: vmw_vsock: vmci: Check memcpy_from_msg()
- net: defxx: Fix missing err handling in dfx_init()
- drivers: net: qlcnic: Fix potential memory leak in qlcnic_sriov_init()
- ethernet: s2io: don't call dev_kfree_skb() under spin_lock_irqsave()
- net: farsync: Fix kmemleak when rmmods farsync
- net/tunnel: wait until all sk_user_data reader finish before releasing the
sock
- net: apple: mace: don't call dev_kfree_skb() under spin_lock_irqsave()
- net: apple: bmac: don't call dev_kfree_skb() under spin_lock_irqsave()
- net: emaclite: don't call dev_kfree_skb() under spin_lock_irqsave()
- net: ethernet: dnet: don't call dev_kfree_skb() under spin_lock_irqsave()
- hamradio: don't call dev_kfree_skb() under spin_lock_irqsave()
- net: amd: lance: don't call dev_kfree_skb() under spin_lock_irqsave()
- net: amd-xgbe: Check only the minimum speed for active/passive cables
- net: lan9303: Fix read error execution path
- ntb_netdev: Use dev_kfree_skb_any() in interrupt context
- Bluetooth: btusb: don't call kfree_skb() under spin_lock_irqsave()
- Bluetooth: hci_qca: don't call kfree_skb() under spin_lock_irqsave()
- Bluetooth: hci_h5: don't call kfree_skb() under spin_lock_irqsave()
- Bluetooth: hci_bcsp: don't call kfree_skb() under spin_lock_irqsave()
- Bluetooth: hci_core: don't call kfree_skb() under spin_lock_irqsave()
- Bluetooth: RFCOMM: don't call kfree_skb() under spin_lock_irqsave()
- stmmac: fix potential division by 0
- apparmor: fix a memleak in multi_transaction_new()
- PCI: Check for alloc failure in pci_request_irq()
- RDMA/hfi: Decrease PCI device reference count in error path
- RDMA/rxe: Fix NULL-ptr-deref in rxe_qp_do_cleanup() when socket create
failed
- scsi: hpsa: Fix error handling in hpsa_add_sas_host()
- scsi: hpsa: Fix possible memory leak in hpsa_add_sas_device()
- scsi: fcoe: Fix possible name leak when device_register() fails
- scsi: ipr: Fix WARNING in ipr_init()
- scsi: fcoe: Fix transport not deattached when fcoe_if_init() fails
- scsi: snic: Fix possible UAF in snic_tgt_create()
- RDMA/hfi1: Fix error return code in parse_platform_config()
- orangefs: Fix sysfs not cleanup when dev init failed
- crypto: img-hash - Fix variable dereferenced before check 'hdev->req'
- hwrng: amd - Fix PCI device refcount leak
- hwrng: geode - Fix PCI device refcount leak
- IB/IPoIB: Fix queue count inconsistency for PKEY child interfaces
- drivers: dio: fix possible memory leak in dio_init()
- class: fix possible memory leak in __class_register()
- vfio: platform: Do not pass return buffer to ACPI _RST method
- uio: uio_dmem_genirq: Fix missing unlock in irq configuration
- uio: uio_dmem_genirq: Fix deadlock between irq config and handling
- usb: fotg210-udc: Fix ages old endianness issues
- staging: vme_user: Fix possible UAF in tsi148_dma_list_add
- serial: amba-pl011: avoid SBSA UART accessing DMACR register
- serial: pch: Fix PCI device refcount leak in pch_request_dma()
- serial: sunsab: Fix error handling in sunsab_init()
- test_firmware: fix memory leak in test_firmware_init()
- misc: tifm: fix possible memory leak in tifm_7xx1_switch_media()
- misc: sgi-gru: fix use-after-free error in gru_set_context_option, gru_fault
and gru_handle_user_call_os
- cxl: fix possible null-ptr-deref in cxl_guest_init_afu|adapter()
- cxl: fix possible null-ptr-deref in cxl_pci_init_afu|adapter()
- drivers: mcb: fix resource leak in mcb_probe()
- mcb: mcb-parse: fix error handing in chameleon_parse_gdd()
- chardev: fix error handling in cdev_device_add()
- i2c: pxa-pci: fix missing pci_disable_device() on error in ce4100_i2c_probe
- staging: rtl8192u: Fix use after free in ieee80211_rx()
- staging: rtl8192e: Fix potential use-after-free in rtllib_rx_Monitor()
- vme: Fix error not catched in fake_init()
- i2c: ismt: Fix an out-of-bounds bug in ismt_access()
- usb: storage: Add check for kcalloc
- fbdev: ssd1307fb: Drop optional dependency
- fbdev: pm2fb: fix missing pci_disable_device()
- fbdev: via: Fix error in via_core_init()
- fbdev: vermilion: decrease reference count in error path
- fbdev: uvesafb: Fixes an error handling path in uvesafb_probe()
- HSI: omap_ssi_core: fix unbalanced pm_runtime_disable()
- HSI: omap_ssi_core: fix possible memory leak in ssi_probe()
- power: supply: fix residue sysfs file in error handle route of
__power_supply_register()
- HSI: omap_ssi_core: Fix error handling in ssi_init()
- include/uapi/linux/swab: Fix potentially missing __always_inline
- rtc: snvs: Allow a time difference on clock register read
- iommu/amd: Fix pci device refcount leak in ppr_notifier()
- iommu/fsl_pamu: Fix resource leak in fsl_pamu_probe()
- macintosh: fix possible memory leak in macio_add_one_device()
- macintosh/macio-adb: check the return value of ioremap()
- powerpc/52xx: Fix a resource leak in an error handling path
- cxl: Fix refcount leak in cxl_calc_capp_routing
- powerpc/xive: add missing iounmap() in error path in
xive_spapr_populate_irq_data()
- powerpc/perf: callchain validate kernel stack pointer bounds
- powerpc/83xx/mpc832x_rdb: call platform_device_put() in error case in
of_fsl_spi_probe()
- powerpc/hv-gpci: Fix hv_gpci event list
- selftests/powerpc: Fix resource leaks
- rtc: st-lpc: Add missing clk_disable_unprepare in st_rtc_probe()
- nfsd: under NFSv4.1, fix double svc_xprt_put on rpc_create failure
- mISDN: hfcsusb: don't call dev_kfree_skb/kfree_skb() under
spin_lock_irqsave()
- mISDN: hfcpci: don't call dev_kfree_skb/kfree_skb() under
spin_lock_irqsave()
- mISDN: hfcmulti: don't call dev_kfree_skb/kfree_skb() under
spin_lock_irqsave()
- nfc: pn533: Clear nfc_target before being used
- r6040: Fix kmemleak in probe and remove
- openvswitch: Fix flow lookup to use unmasked key
- skbuff: Account for tail adjustment during pull operations
- net_sched: reject TCF_EM_SIMPLE case for complex ematch module
- myri10ge: Fix an error handling path in myri10ge_probe()
- net: stream: purge sk_error_queue in sk_stream_kill_queues()
- binfmt_misc: fix shift-out-of-bounds in check_special_flags
- fs: jfs: fix shift-out-of-bounds in dbAllocAG
- udf: Avoid double brelse() in udf_rename()
- fs: jfs: fix shift-out-of-bounds in dbDiscardAG
- ACPICA: Fix error code path in acpi_ds_call_control_method()
- nilfs2: fix shift-out-of-bounds/overflow in nilfs_sb2_bad_offset()
- acct: fix potential integer overflow in encode_comp_t()
- hfs: fix OOB Read in __hfs_brec_find
- wifi: ath9k: verify the expected usb_endpoints are present
- wifi: ar5523: Fix use-after-free on ar5523_cmd() timed out
- ASoC: codecs: rt298: Add quirk for KBL-R RVP platform
- ipmi: fix memleak when unload ipmi driver
- bpf: make sure skb->len != 0 when redirecting to a tunneling device
- net: ethernet: ti: Fix return type of netcp_ndo_start_xmit()
- hamradio: baycom_epp: Fix return type of baycom_send_packet()
- wifi: brcmfmac: Fix potential shift-out-of-bounds in
brcmf_fw_alloc_request()
- igb: Do not free q_vector unless new one was allocated
- s390/ctcm: Fix return type of ctc{mp,}m_tx()
- s390/netiucv: Fix return type of netiucv_tx()
- s390/lcs: Fix return type of lcs_start_xmit()
- drm/sti: Use drm_mode_copy()
- md/raid1: stop mdx_raid1 thread when raid1 array run failed
- mrp: introduce active flags to prevent UAF when applicant uninit
- ppp: associate skb with a device at tx
- media: dvb-frontends: fix leak of memory fw
- media: dvbdev: adopts refcnt to avoid UAF
- media: dvb-usb: fix memory leak in dvb_usb_adapter_init()
- blk-mq: fix possible memleak when register 'hctx' failed
- mmc: f-sdh30: Add quirks for broken timeout clock capability
- media: si470x: Fix use-after-free in si470x_int_in_callback()
- clk: st: Fix memory leak in st_of_quadfs_setup()
- drm/fsl-dcu: Fix return type of fsl_dcu_drm_connector_mode_valid()
- drm/sti: Fix return type of sti_{dvo,hda,hdmi}_connector_mode_valid()
- orangefs: Fix kmemleak in orangefs_prepare_debugfs_help_string()
- ASoC: mediatek: mt8173-rt5650-rt5514: fix refcount leak in
mt8173_rt5650_rt5514_dev_probe()
- ASoC: rockchip: pdm: Add missing clk_disable_unprepare() in
rockchip_pdm_runtime_resume()
- ASoC: wm8994: Fix potential deadlock
- ASoC: rockchip: spdif: Add missing clk_disable_unprepare() in
rk_spdif_runtime_resume()
- ASoC: rt5670: Remove unbalanced pm_runtime_put()
- pstore: Switch pmsg_lock to an rt_mutex to avoid priority inversion
- pstore: Make sure CONFIG_PSTORE_PMSG selects CONFIG_RT_MUTEXES
- usb: dwc3: core: defer probe on ulpi_read_id timeout
- HID: wacom: Ensure bootloader PID is usable in hidraw mode
- reiserfs: Add missing calls to reiserfs_security_free()
- iio: adc: ad_sigma_delta: do not use internal iio_dev lock
- gcov: add support for checksum field
- media: dvbdev: fix refcnt bug
- powerpc/rtas: avoid device tree lookups in rtas_os_term()
- powerpc/rtas: avoid scheduling in rtas_os_term()
- HID: plantronics: Additional PIDs for double volume key presses quirk
- hfsplus: fix bug causing custom uid and gid being unable to be assigned with
mount
- ALSA: line6: correct midi status byte when receiving data from podxt
- ALSA: line6: fix stack overflow in line6_midi_transmit
- pnode: terminate at peers of source
- md: fix a crash in mempool_free
- mmc: vub300: fix warning - do not call blocking ops when !TASK_RUNNING
- tpm: tpm_crb: Add the missed acpi_put_table() to fix memory leak
- tpm: tpm_tis: Add the missed acpi_put_table() to fix memory leak
- media: stv0288: use explicitly signed char
- ktest.pl minconfig: Unset configs instead of just removing them
- ARM: ux500: do not directly dereference __iomem
- selftests: Use optional USERCFLAGS and USERLDFLAGS
- dm cache: Fix ABBA deadlock between shrink_slab and dm_cache_metadata_abort
- dm thin: Use last transaction's pmd->root when commit failed
- dm thin: Fix UAF in run_timer_softirq()
- dm cache: Fix UAF in destroy()
- dm cache: set needs_check flag after aborting metadata
- x86/microcode/intel: Do not retry microcode reloading on the APs
- tracing: Fix infinite loop in tracing_read_pipe on overflowed
print_trace_line
- ARM: 9256/1: NWFPE: avoid compiler-generated __aeabi_uldivmod
- media: dvb-core: Fix double free in dvb_register_device()
- cifs: fix confusing debug message
- ima: Fix a potential NULL pointer access in ima_restore_measurement_list
- PCI: Fix pci_device_is_present() for VFs by checking PF
- PCI/sysfs: Fix double free in error path
- crypto: n2 - add missing hash statesize
- iommu/amd: Fix ivrs_acpihid cmdline parsing code
- parisc: led: Fix potential null-ptr-deref in start_task()
- device_cgroup: Roll back to original exceptions after copy failure
- drm/connector: send hotplug uevent on connector cleanup
- drm/vmwgfx: Validate the box size for the snooped cursor
- ext4: add inode table check in __ext4_get_inode_loc to aovid possible
infinite loop
- ext4: fix undefined behavior in bit shift for ext4_check_flag_values
- ext4: fix bug_on in __es_tree_search caused by bad boot loader inode
- ext4: init quota for 'old.inode' in 'ext4_rename'
- ext4: fix error code return to user-space in ext4_get_branch()
- ext4: avoid BUG_ON when creating xattrs
- ext4: fix inode leak in ext4_xattr_inode_create() on an error path
- ext4: initialize quota before expanding inode in setproject ioctl
- ext4: avoid unaccounted block allocation when expanding inode
- ext4: allocate extended attribute value in vmalloc area
- SUNRPC: ensure the matching upcall is in-flight upon downcall
- bpf: pull before calling skb_postpull_rcsum()
- qlcnic: prevent ->dcb use-after-free on qlcnic_dcb_enable() failure
- nfc: Fix potential resource leaks
- net: amd-xgbe: add missed tasklet_kill
- net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
- net: sched: atm: dont intepret cls results when asked to drop
- usb: rndis_host: Secure rndis_query check against int overflow
- caif: fix memory leak in cfctrl_linkup_request()
- udf: Fix extension of the last extent in the file
- nfsd: fix handling of readdir in v4root vs. mount upcall timeout
- hfs/hfsplus: use WARN_ON for sanity check
- hfs/hfsplus: avoid WARN_ON() for sanity check, use proper error handling
- parisc: Align parisc MADV_XXX constants with all other architectures
- driver core: Fix bus_type.match() error handling in __driver_attach()
- ravb: Fix "failed to switch device to config mode" message during unbind
- net: sched: disallow noqueue for qdisc classes
- docs: Fix the docs build with Sphinx 6.0
- perf auxtrace: Fix address filter duplicate symbol selection
- s390/percpu: add READ_ONCE() to arch_this_cpu_to_op_simple()
- platform/x86: sony-laptop: Don't turn off 0x153 keyboard backlight during
probe
- ipv6: raw: Deduct extension header length in rawv6_push_pending_frames
- netfilter: ipset: Fix overflow before widen in the bitmap_ip_create()
function.
- x86/boot: Avoid using Intel mnemonics in AT&T syntax asm
- EDAC/device: Fix period calculation in edac_device_reset_delay_period()
- regulator: da9211: Use irq handler when ready
- hvc/xen: lock console list traversal
- nfc: pn533: Wait for out_urb's completion in pn533_usb_send_frame()
- Revert "usb: ulpi: defer ulpi_register on ulpi_read_id timeout"
- selftests/ftrace: event_triggers: wait longer for test_event_enable
- debugfs: fix error when writing negative value to atomic_t debugfs file
- x86/xen: Fix memory leak in xen_smp_intr_init{_pv}()
- relay: fix type mismatch when allocating memory in relay_create_buf()
- wifi: rtl8xxxu: Fix reading the vendor of combo chips
- media: dvb-core: Fix ignored return value in dvb_register_frontend()
- wifi: cfg80211: Fix not unregister reg_pdev when load_builtin_regdb_keys()
fails
- mmc: atmel-mci: fix return value check of mmc_add_host()
- mmc: meson-gx: fix return value check of mmc_add_host()
- net: amd-xgbe: Fix logic around active and passive cables
- apparmor: fix lockdep warning when removing a namespace
- scsi: hpsa: Fix possible memory leak in hpsa_init_one()
- serial: pl011: Do not clear RX FIFO & RX interrupt in unthrottle.
- serial: altera_uart: fix locking in polling mode
- usb: gadget: f_hid: fix refcount leak on error path
- perf symbol: correction while adjusting symbol
- rxrpc: Fix missing unlock in rxrpc_do_sendmsg()
- media: dvbdev: fix build warning due to comments
- ata: ahci: Fix PCS quirk application for suspend
- SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
- binfmt: Fix error return code in load_elf_fdpic_binary()
- ext4: fix corruption when online resizing a 1K bigalloc fs
- media: s5p-mfc: Fix to handle reference queue during finishing
- media: s5p-mfc: Clear workbit to handle error condition
- media: s5p-mfc: Fix in register read and write for H264
- dm thin: resume even if in FAIL mode
- mbcache: don't reclaim used entries
- ext4: remove EA inode entry from mbcache on inode eviction
- usb: ulpi: defer ulpi_register on ulpi_read_id timeout
- net/mlx5: Fix ptp max frequency adjustment range
- drm/virtio: Fix GEM handle creation UAF
- arm64: cmpxchg_double*: hazard against entire exchange variable
* Bionic update: upstream stable patchset 2023-02-06 (LP: #2006403) //
CVE-2023-0266 was assigned for this issue.
- ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF
* Bionic update: upstream stable patchset 2023-02-06 (LP: #2006403) //
CVE-2022-41218 is assigned to those bugs above.
- media: dvb-core: Fix UAF due to refcount races at releasing
* CVE-2023-23559
- wifi: rndis_wlan: Prevent buffer overflow in rndis_query_oid
* CVE-2023-0045
- x86/bugs: Flush IBP in ib_prctl_set()
[ Ubuntu: 4.15.0-206.217 ]
* bionic/linux: 4.15.0-206.217 -proposed tracker (LP: #2004655)
* CVE-2023-0461
- SAUCE: Fix inet_csk_listen_start after CVE-2023-0461
[ Ubuntu: 4.15.0-205.216 ]
* bionic/linux: 4.15.0-205.216 -proposed tracker (LP: #2004414)
* Bionic update: upstream stable patchset 2023-01-20 (LP: #2003596)
- NFSv4.1: Handle RECLAIM_COMPLETE trunking errors
- NFSv4.1: We must always send RECLAIM_COMPLETE after a reboot
- nfs4: Fix kmemleak when allocate slot failed
- net: dsa: Fix possible memory leaks in dsa_loop_init()
- nfc: s3fwrn5: Fix potential memory leak in s3fwrn5_nci_send()
- nfc: nfcmrvl: Fix potential memory leak in nfcmrvl_i2c_nci_send()
- net: fec: fix improper use of NETDEV_TX_BUSY
- ata: pata_legacy: fix pdc20230_set_piomode()
- net: sched: Fix use after free in red_enqueue()
- ipvs: use explicitly signed chars
- rose: Fix NULL pointer dereference in rose_send_frame()
- mISDN: fix possible memory leak in mISDN_register_device()
- isdn: mISDN: netjet: fix wrong check of device registration
- btrfs: fix inode list leak during backref walking at resolve_indirect_refs()
- btrfs: fix ulist leaks in error paths of qgroup self tests
- Bluetooth: L2CAP: fix use-after-free in l2cap_conn_del()
- net: mdio: fix undefined behavior in bit shift for __mdiobus_register
- net, neigh: Fix null-ptr-deref in neigh_table_clear()
- media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE
- media: dvb-frontends/drxk: initialize err to 0
- i2c: xiic: Add platform module alias
- Bluetooth: L2CAP: Fix attempting to access uninitialized memory
- block, bfq: protect 'bfqd->queued' by 'bfqd->lock'
- btrfs: fix type of parameter generation in btrfs_get_dentry
- tcp/udp: Make early_demux back namespacified.
- capabilities: fix potential memleak on error path from vfs_getxattr_alloc()
- ALSA: usb-audio: Add quirks for MacroSilicon MS2100/MS2106 devices
- efi: random: reduce seed size to 32 bytes
- parisc: Make 8250_gsc driver dependend on CONFIG_PARISC
- parisc: Export iosapic_serial_irq() symbol for serial port driver
- ext4: fix warning in 'ext4_da_release_space'
- KVM: x86: Mask off reserved bits in CPUID.80000008H
- KVM: x86: emulator: em_sysexit should update ctxt->mode
- KVM: x86: emulator: introduce emulator_recalc_and_set_mode
- KVM: x86: emulator: update the emulation mode after CR0 write
- linux/const.h: prefix include guard of uapi/linux/const.h with _UAPI
- linux/const.h: move UL() macro to include/linux/const.h
- linux/bits.h: make BIT(), GENMASK(), and friends available in assembly
- RDMA/qedr: clean up work queue on failure in qedr_alloc_resources()
- net: tun: fix bugs for oversize packet when napi frags enabled
- ipvs: fix WARNING in __ip_vs_cleanup_batch()
- ipvs: fix WARNING in ip_vs_app_net_cleanup()
- ipv6: fix WARNING in ip6_route_net_exit_late()
- parisc: Avoid printing the hardware path twice
- HID: hyperv: fix possible memory leak in mousevsc_probe()
- net: gso: fix panic on frag_list with mixed head alloc types
- bnxt_en: fix potentially incorrect return value for ndo_rx_flow_steer
- net: fman: Unregister ethernet device on removal
- capabilities: fix undefined behavior in bit shift for CAP_TO_MASK
- net: lapbether: fix issue of dev reference count leakage in
lapbeth_device_event()
- hamradio: fix issue of dev reference count leakage in bpq_device_event()
- drm/vc4: Fix missing platform_unregister_drivers() call in
vc4_drm_register()
- ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network
- tipc: fix the msg->req tlv len check in
tipc_nl_compat_name_table_dump_header
- dmaengine: mv_xor_v2: Fix a resource leak in mv_xor_v2_remove()
- drivers: net: xgene: disable napi when register irq failed in
xgene_enet_open()
- net: cxgb3_main: disable napi when bind qsets failed in cxgb_up()
- ethernet: s2io: disable napi when start nic failed in s2io_card_up()
- net: mv643xx_eth: disable napi when init rxq or txq failed in
mv643xx_eth_open()
- net: macvlan: fix memory leaks of macvlan_common_newlink
- arm64: efi: Fix handling of misaligned runtime regions and drop warning
- ALSA: hda: fix potential memleak in 'add_widget_node'
- ALSA: usb-audio: Add quirk entry for M-Audio Micro
- nilfs2: fix deadlock in nilfs_count_free_blocks()
- drm/i915/dmabuf: fix sg_table handling in map_dma_buf
- platform/x86: hp_wmi: Fix rfkill causing soft blocked wifi
- btrfs: selftests: fix wrong error check in btrfs_free_dummy_root()
- udf: Fix a slab-out-of-bounds write bug in udf_find_entry()
- cert host tools: Stop complaining about deprecated OpenSSL functions
- dmaengine: at_hdmac: Fix at_lli struct definition
- dmaengine: at_hdmac: Don't start transactions at tx_submit level
- dmaengine: at_hdmac: Fix completion of unissued descriptor in case of errors
- dmaengine: at_hdmac: Don't allow CPU to reorder channel enable
- dmaengine: at_hdmac: Fix impossible condition
- dmaengine: at_hdmac: Check return code of dma_async_device_register
- x86/cpu: Restore AMD's DE_CFG MSR after resume
- selftests/futex: fix build for clang
- drm/imx: imx-tve: Fix return type of imx_tve_connector_mode_valid
- ASoC: core: Fix use-after-free in snd_soc_exit()
- serial: 8250_omap: remove wait loop from Errata i202 workaround
- serial: 8250: omap: Flush PM QOS work on remove
- tty: n_gsm: fix sleep-in-atomic-context bug in gsm_control_send
- ASoC: soc-utils: Remove __exit for snd_soc_util_exit()
- block: sed-opal: kmalloc the cmd/resp buffers
- parport_pc: Avoid FIFO port location truncation
- pinctrl: devicetree: fix null pointer dereferencing in pinctrl_dt_to_map
- net: bgmac: Drop free_netdev() from bgmac_enet_remove()
- mISDN: fix possible memory leak in mISDN_dsp_element_register()
- mISDN: fix misuse of put_device() in mISDN_register_device()
- net: caif: fix double disconnect client in chnl_net_open()
- xen/pcpu: fix possible memory leak in register_pcpu()
- drbd: use after free in drbd_create_device()
- net/x25: Fix skb leak in x25_lapb_receive_frame()
- cifs: Fix wrong return value checking when GETFLAGS
- ftrace: Fix the possible incorrect kernel message
- ftrace: Optimize the allocation for mcount entries
- ftrace: Fix null pointer dereference in ftrace_add_mod()
- ring_buffer: Do not deactivate non-existant pages
- ALSA: usb-audio: Drop snd_BUG_ON() from snd_usbmidi_output_open()
- USB: serial: option: add Sierra Wireless EM9191
- USB: serial: option: remove old LARA-R6 PID
- USB: serial: option: add u-blox LARA-R6 00B modem
- USB: serial: option: add u-blox LARA-L6 modem
- USB: serial: option: add Fibocom FM160 0x0111 composition
- usb: add NO_LPM quirk for Realforce 87U Keyboard
- usb: chipidea: fix deadlock in ci_otg_del_timer
- iio: adc: at91_adc: fix possible memory leak in at91_adc_allocate_trigger()
- iio: trigger: sysfs: fix possible memory leak in iio_sysfs_trig_init()
- iio: pressure: ms5611: changed hardcoded SPI speed to value limited
- dm ioctl: fix misbehavior if list_versions races with module loading
- serial: 8250: Fall back to non-DMA Rx if IIR_RDI occurs
- serial: 8250_lpss: Configure DMA also w/o DMA filter
- mmc: core: properly select voltage range without power cycle
- mmc: sdhci-pci: Fix possible memory leak caused by missing pci_dev_put()
- misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram()
- nilfs2: fix use-after-free bug of ns_writer on remount
- serial: 8250: Flush DMA Rx on RLSI
- macvlan: enforce a consistent minimal mtu
- tcp: cdg: allow tcp_cdg_release() to be called multiple times
- kcm: avoid potential race in kcm_tx_work
- bpf, test_run: Fix alignment problem in bpf_prog_test_run_skb()
- kcm: close race conditions on sk_receive_queue
- 9p: trans_fd/p9_conn_cancel: drop client lock earlier
- gfs2: Check sb_bsize_shift after reading superblock
- gfs2: Switch from strlcpy to strscpy
- 9p/trans_fd: always use O_NONBLOCK read/write
- mm: fs: initialize fsdata passed to write_begin/write_end interface
- ntfs: fix use-after-free in ntfs_attr_find()
- ntfs: fix out-of-bounds read in ntfs_attr_find()
- ntfs: check overflow when iterating ATTR_RECORDs
- wifi: cfg80211: fix memory leak in query_regdb_file()
- net: tun: Fix memory leaks of napi_get_frags
- riscv: process: fix kernel info leakage
- vmlinux.lds.h: Fix placement of '.data..decrypted' section
- net: thunderbolt: Fix error handling in tbnet_init()
- scsi: target: tcm_loop: Fix possible name leak in tcm_loop_setup_hba_bus()
- Input: i8042 - fix leaking of platform device on module removal
- wifi: mac80211_hwsim: fix debugfs attribute ps with rc table support
- audit: fix undefined behavior in bit shift for AUDIT_BIT
- wifi: mac80211: Fix ack frame idr leak when mesh has no route
- spi: stm32: fix stm32_spi_prepare_mbr() that halves spi clk for every run
- MIPS: pic32: treat port as signed integer
- af_key: Fix send_acquire race with pfkey_register
- ARM: dts: am335x-pcm-953: Define fixed regulators in root node
- bus: sunxi-rsb: Support atomic transfers
- ARM: dts: at91: sam9g20ek: enable udc vbus gpio pinctrl
- nfc/nci: fix race with opening and closing
- net: pch_gbe: fix potential memleak in pch_gbe_tx_queue()
- 9p/fd: fix issue of list_del corruption in p9_fd_cancel()
- ARM: mxs: fix memory leak in mxs_machine_init()
- net/mlx4: Check retval of mlx4_bitmap_init
- net/qla3xxx: fix potential memleak in ql3xxx_send()
- xfrm: Fix ignored return value in xfrm6_init()
- NFC: nci: fix memory leak in nci_rx_data_packet()
- dccp/tcp: Reset saddr on failure after inet6?_hash_connect().
- s390/dasd: fix no record found for raw_track_access
- nfc: st-nci: fix incorrect validating logic in EVT_TRANSACTION
- nfc: st-nci: fix memory leaks in EVT_TRANSACTION
- net: thunderx: Fix the ACPI memory leak
- s390/crashdump: fix TOD programmable field size
- nios2: add FORCE for vmlinuz.gz
- arm64: dts: rockchip: lower rk3399-puma-haikou SD controller clock frequency
- iio: light: apds9960: fix wrong register for gesture gain
- iio: core: Fix entry not deleted when iio_register_sw_trigger_type() fails
- kconfig: display recursive dependency resolution hint just once
- nilfs2: fix nilfs_sufile_mark_dirty() not set segment usage as dirty
- Input: synaptics - switch touchpad on HP Laptop 15-da3001TU to RMI mode
- serial: 8250: 8250_omap: Avoid RS485 RTS glitch on ->set_termios()
- xen/platform-pci: add missing free_irq() in error path
- platform/x86: asus-wmi: add missing pci_dev_put() in asus_wmi_set_xusb2pr()
- platform/x86: acer-wmi: Enable SW_TABLET_MODE on Switch V 10 (SW5-017)
- platform/x86: hp-wmi: Ignore Smart Experience App event
- [Config] updateconfigs for INET_TABLE_PERTURB_ORDER
- tcp: configurable source port perturb table size
- net: usb: qmi_wwan: add Telit 0x103a composition
- drm/amdgpu: always register an MMU notifier for userptr
- iio: health: afe4403: Fix oob read in afe4403_read_raw
- iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw
- iio: light: rpr0521: add missing Kconfig dependencies
- hwmon: (i5500_temp) fix missing pci_disable_device()
- hwmon: (ibmpex) Fix possible UAF when ibmpex_register_bmc() fails
- of: property: decrement node refcount in of_fwnode_get_reference_args()
- net/mlx5: Fix uninitialized variable bug in outlen_write()
- can: sja1000_isa: sja1000_isa_probe(): add missing free_sja1000dev()
- can: cc770: cc770_isa_probe(): add missing free_cc770dev()
- qlcnic: fix sleep-in-atomic-context bugs caused by msleep
- net: phy: fix null-ptr-deref while probe() failed
- net: net_netdev: Fix error handling in ntb_netdev_init_module()
- net/9p: Fix a potential socket leak in p9_socket_open
- dsa: lan9303: Correct stat name
- net: hsr: Fix potential use-after-free
- packet: do not set TP_STATUS_CSUM_VALID on CHECKSUM_COMPLETE
- net: ethernet: renesas: ravb: Fix promiscuous mode after system resumed
- hwmon: (coretemp) Check for null before removing sysfs attrs
- hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new()
- perf: Add sample_flags to indicate the PMU-filled sample data
- btrfs: qgroup: fix sleep from invalid context bug in btrfs_qgroup_inherit()
- tools/vm/slabinfo-gnuplot: use "grep -E" instead of "egrep"
- nilfs2: fix NULL pointer dereference in nilfs_palloc_commit_free_entry()
- x86/bugs: Make sure MSR_SPEC_CTRL is updated properly upon resume from S3
- arm64: Fix panic() when Spectre-v2 causes Spectre-BHB to re-allocate KVM
vectors
- arm64: errata: Fix KVM Spectre-v2 mitigation selection for Cortex-A57/A72
- efi: random: Properly limit the size of the random seed
- ASoC: ops: Fix bounds check for _sx controls
- pinctrl: single: Fix potential division by zero
- iommu/vt-d: Fix PCI device refcount leak in dmar_dev_scope_init()
- nvme: restrict management ioctls to admin
- x86/tsx: Add a feature bit for TSX control MSR support
- x86/pm: Add enumeration check before spec MSRs save/restore setup
- x86/ioremap: Fix page aligned size calculation in __ioremap_caller()
- mmc: sdhci: use FIELD_GET for preset value bit masks
- mmc: sdhci: Fix voltage switch delay
- proc: avoid integer type confusion in get_proc_long
- proc: proc_skip_spaces() shouldn't think it is working on C strings
- v4l2: don't fall back to follow_pfn() if pin_user_pages_fast() fails
- ipc/sem: Fix dangling sem_array access in semtimedop race
- x86/nospec: Fix i386 RSB stuffing
- Revert "x86/speculation: Change FILL_RETURN_BUFFER to work with objtool"
- ASoC: sgtl5000: Reset the CHIP_CLK_CTRL reg on remove
- net: pch_gbe: fix pci device refcount leak while module exiting
- Drivers: hv: vmbus: fix double free in the error path of
vmbus_add_channel_work()
- Drivers: hv: vmbus: fix possible memory leak in vmbus_device_register()
- bnx2x: fix pci device refcount leak in bnx2x_vf_is_pcie_pending()
- iio: pressure: ms5611: fixed value compensation bug
- arm: dts: rockchip: fix node name for hym8563 rtc
- ARM: dts: rockchip: fix ir-receiver node names
- ARM: 9251/1: perf: Fix stacktraces for tracepoint events in THUMB2 kernels
- ARM: 9266/1: mm: fix no-MMU ZERO_PAGE() implementation
- ARM: dts: rockchip: disable arm_global_timer on rk3066 and rk3188
- ALSA: seq: Fix function prototype mismatch in snd_seq_expand_var_event
- ASoC: soc-pcm: Add NULL check in BE reparenting
- regulator: twl6030: fix get status of twl6032 regulators
- net: usb: qmi_wwan: add u-blox 0x1342 composition
- xen/netback: do some code cleanup
- xen/netback: don't call kfree_skb() with interrupts disabled
- rcutorture: Automatically create initrd directory
- media: v4l2-dv-timings.c: fix too strict blanking sanity checks
- memcg: fix possible use-after-free in memcg_write_event_control()
- KVM: s390: vsie: Fix the initialization of the epoch extension (epdx) field
- HID: hid-lg4ff: Add check for empty lbuf
- HID: core: fix shift-out-of-bounds in hid_report_raw_event
- ieee802154: cc2520: Fix error return code in cc2520_hw_init()
- ca8210: Fix crash by zero initializing data
- gpio: amd8111: Fix PCI device reference count leak
- e1000e: Fix TX dispatch condition
- igb: Allocate MSI-X vector when testing
- Bluetooth: 6LoWPAN: add missing hci_dev_put() in get_l2cap_conn()
- mac802154: fix missing INIT_LIST_HEAD in ieee802154_if_add()
- net: encx24j600: Add parentheses to fix precedence
- net: encx24j600: Fix invalid logic in reading of MISTAT register
- net: mvneta: Prevent out of bounds read in mvneta_config_rss()
- NFC: nci: Bounds check struct nfc_target arrays
- net: stmmac: fix "snps,axi-config" node property parsing
- net: hisilicon: Fix potential use-after-free in hisi_femac_rx()
- net: hisilicon: Fix potential use-after-free in hix5hd2_rx()
- tipc: Fix potential OOB in tipc_link_proto_rcv()
- ethernet: aeroflex: fix potential skb leak in greth_init_rings()
- net: plip: don't call kfree_skb/dev_kfree_skb() under spin_lock_irq()
- ipv6: avoid use-after-free in ip6_fragment()
- net: mvneta: Fix an out of bounds check
- net: mvneta: Prevent out of bounds read in mvneta_config_rss()
- i40e: Fix not setting default xps_cpus after reset
- i40e: Fix for VF MAC address 0
- i40e: Disallow ip4 and ip6 l4_4_bytes
- nvme initialize core quirks before calling nvme_init_subsystem
- can: esd_usb: Allow REC and TEC to return to zero
* CVE-2022-3628
- wifi: brcmfmac: Fix potential buffer overflow in brcmf_fweh_event_worker()
* rdpru in ubuntu_kvm_unit_tests failed on B-4.15 node riccioli with FAIL:
RDPRU raises #UD (LP: #1968681)
- x86/cpufeatures: Add feature bit RDPRU on AMD
- kvm: svm: Intercept RDPRU
* NFS: client permission error after adding user to permissible group
(LP: #2003053)
- cred: add cred_fscmp() for comparing creds.
- NFS: Clear the file access cache upon login
- NFS: Judge the file access cache's timestamp in rcu path
- NFS: Fix up a sparse warning
* 5.15.0-58.64 breaks xen bridge networking (pvh domU) (LP: #2002889)
- xen/netback: fix build warning
* CVE-2023-0461
- net/ulp: prevent ULP without clone op from entering the LISTEN status
* CVE-2022-3545
- nfp: fix use-after-free in area_cache_get()
Date: 2023-02-24 19:51:09.016492+00:00
Changed-By: Tim Gardner <tim.gardner at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-azure-4.15/4.15.0-1162.177
-------------- next part --------------
Sorry, changesfile not available.
More information about the Bionic-changes
mailing list