[ubuntu/jammy-proposed] linux 5.15.0-189.199 (Accepted)

Timo Aaltonen tjaalton at ubuntu.com
Mon Aug 3 15:10:44 UTC 2026


linux (5.15.0-189.199) jammy; urgency=medium

  * jammy/linux: 5.15.0-189.199 -proposed tracker (LP: #2162537)

  * Drop DEP-8 tests from kernel packages (LP: #2160302)
    - [Packaging] Drop DEP-8 tests from kernel source

  * CVE-2026-53131
    - netfilter: require Ethernet MAC header before using eth_hdr()

  * CVE-2026-64531
    - net: openvswitch: reject oversized nested action attrs

  * CVE-2026-53224
    - sctp: validate embedded INIT chunk and address list lengths in cookie

  * CVE-2026-53246
    - sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing

  * CVE-2026-53086
    - net: bcmgenet: fix racing timeout handler

  * CVE-2026-53225
    - sctp: fix uninit-value in __sctp_rcv_asconf_lookup()

  * CVE-2026-53228
    - ipv6: sit: reload inner IPv6 header after GSO offloads

  * CVE-2026-43499
    - rtmutex: Use waiter::task instead of current in remove_waiter()

  * CVE-2026-46331
    - net/sched: fix pedit partial COW leading to page cache corruption

  * CVE-2026-53212
    - netfilter: nft_tunnel: fix use-after-free on object destroy

  * CVE-2026-53359
    - KVM: x86: Fix shadow paging use-after-free due to unexpected role

  * CVE-2026-52989
    - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers

  * CVE-2026-52924
    - sctp: purge outqueue on stale COOKIE-ECHO handling

  * CVE-2026-43378
    - smb: server: fix use-after-free in smb2_open()

  * CVE-2025-27558
    - wifi: prevent A-MSDU attacks in mesh networks

  * CVE-2026-53215
    - net: mvpp2: refill RX buffers before XDP or skb use

  * CVE-2026-53176
    - IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN

  * CVE-2026-46266
    - inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP

  * CVE-2026-43198
    - tcp: fix potential race in tcp_v6_syn_recv_sock()

  * CVE-2026-31705
    - ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment

  * CVE-2026-31448
    - ext4: avoid infinite loops caused by residual data

  * CVE-2026-31414
    - netfilter: nf_conntrack_expect: use expect->helper

  * Packaging resync (LP: #1786013)
    - [Packaging] update annotations scripts
    - [Packaging] resync retpoline extraction

  * Miscellaneous Ubuntu changes
    - SAUCE: Skip srv6_end_dt46_l3vpn_test::host_vpn_tests if iproute2 too old

Date: 2026-08-01 03:01:11.693576+00:00
Changed-By: Edoardo Canepa <edoardo.canepa at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux/5.15.0-189.199
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list