[ubuntu/jammy-security] linux-intel-iotg 5.15.0-1106.112 (Accepted)

Andy Whitcroft apw at canonical.com
Wed Jul 1 08:08:39 UTC 2026


linux-intel-iotg (5.15.0-1106.112) jammy; urgency=medium

  * jammy/linux-intel-iotg: 5.15.0-1106.112 -proposed tracker (LP: #2157235)

  [ Ubuntu: 5.15.0-185.195 ]

  * jammy/linux: 5.15.0-185.195 -proposed tracker (LP: #2157253)
  * Packaging resync (LP: #1786013)
    - [Packaging] update annotations scripts
    - [Packaging] resync retpoline extraction
  * CVE-2026-45988
    - rxrpc: Fix re-decryption of RESPONSE packets
  * CVE-2026-46195
    - smb: client: validate dacloffset before building DACL pointers
  * CVE-2026-46135
    - nvmet-tcp: fix race between ICReq handling and queue teardown
  * CVE-2026-31402
    - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
  * CVE-2026-43071
    - dcache: Limit the minimal number of bucket to two
  * CVE-2026-46119
    - libceph: Fix slab-out-of-bounds access in auth message processing
  * CVE-2026-43501
    - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
  * CVE-2026-46043
    - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
  * CVE-2026-43493
    - crypto: pcrypt - Fix handling of MAY_BACKLOG requests
  * CVE-2026-31637
    - rxrpc: reject undecryptable rxkad response tickets
  * CVE-2026-31657
    - batman-adv: hold claim backbone gateways by reference
  * CVE-2026-31685
    - netfilter: ip6t_eui64: reject invalid MAC header for all packets
  * CVE-2026-43117
    - btrfs: tracepoints: get correct superblock from dentry in event
      btrfs_sync_file()
  * CVE-2026-43114
    - netfilter: nft_set_pipapo_avx2: don't return non-matching entry on
      expiry
  * CVE-2026-31478
    - ksmbd: replace hardcoded hdr2_len with offsetof() in
      smb2_calc_max_out_buf_len()
  * CVE-2026-31668
    - seg6: separate dst_cache for input and output paths in seg6 lwtunnel
  * CVE-2026-31659
    - batman-adv: reject oversized global TT response buffers
  * CVE-2026-31649
    - net: stmmac: fix integer underflow in chain mode
  * CVE-2026-31669
    - mptcp: fix slab-use-after-free in __inet_lookup_established
  * CVE-2026-43011
    - net/x25: Fix potential double free of skb
  * CVE-2026-43037
    - ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
  * CVE-2026-43038
    - ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
  * CVE-2026-31682
    - bridge: br_nd_send: linearize skb before parsing ND options
  * CVE-2026-23450
    - net/smc: Only save the original clcsock callback functions
    - net/smc: Fix slab-out-of-bounds issue in fallback
    - net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
  * CVE-2026-23428
    - ksmbd: fix use-after-free of share_conf in compound request
  * CVE-2026-23455
    - netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
  * CVE-2026-43186
    - ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data()
  * CVE-2026-43185
    - ksmbd: fix signededness bug in smb_direct_prepare_negotiation()
  * CVE-2026-43341
    - net/ipv6: ioam6: prevent schema length wraparound in trace fill
  * CVE-2026-31607
    - usbip: validate number_of_packets in usbip_pack_ret_submit()
  * CVE-2026-43383
    - net/tcp-md5: Fix MAC comparison to be constant-time
  * CVE-2025-68263
    - ksmbd: ipc: fix use-after-free in ipc_msg_send_request
  * CVE-2026-46243
    - smb: client: reject userspace cifs.spnego descriptions
  * CVE-2026-43414
    - scsi: qla2xxx: Completely fix fcport double free
  * CVE-2026-43407
    - libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()
  * CVE-2026-43406
    - libceph: prevent potential out-of-bounds reads in
      process_message_header()
  * CVE-2026-43304
    - libceph: define and enforce CEPH_MAX_KEY_LEN
  * CVE-2025-37924
    - ksmbd: fix use-after-free in kerberos authentication
  * CVE-2025-37778
    - ksmbd: Fix dangling pointer in krb_authenticate

linux-intel-iotg (5.15.0-1105.111) jammy; urgency=medium

  * jammy/linux-intel-iotg: 5.15.0-1105.111 -proposed tracker (LP: #2151989)

  * Packaging resync (LP: #1786013)
    - [Packaging] resync retpoline extraction

  [ Ubuntu: 5.15.0-184.194 ]

  * jammy/linux: 5.15.0-184.194 -proposed tracker (LP: #2154219)
  * Kernel regression (6.8.0-117.generic) (LP: #2153556)
    - net: bonding: update the slave array for broadcast mode
    - bonding: do not set usable_slaves for broadcast mode
  * kernel null pointer BUG in 5.15 when disconnecting from cifs share
    (LP: #2150730)
    - SAUCE: cifs: fix null pointer dereference in find_ipc_from_server_path
  * SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
    (LP: #2149767)
    - SUNRPC: Check if the xprt is connected before handling sysfs reads
    - SUNRPC: Do not dereference non-socket transports in sysfs
  * SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
    (LP: #2149767) // CVE-2022-48816
    - SUNRPC: lock against ->sock changing during sysfs read
  * iptables connlimit traffic loss (LP: #2149872)
    - netfilter: nf_conncount: fix tracking of connections from localhost
  * Some powerpc test from ubuntu_kernel_selftests timeout with 45 seconds
    (LP: #2141536)
    - selftests/powerpc: Lower run time of count_stcx_fail test
    - selftests/powerpc: Give all tests 2 minutes timeout
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598)
    - x86/kfence: fix booting on 32bit non-PAE systems
    - platform/x86: intel_telemetry: Fix swapped arrays in PSS output
    - rbd: check for EOD after exclusive lock is ensured to be held
    - ARM: 9468/1: fix memset64() on big-endian
    - mm/kfence: randomize the freelist on initialization
    - Documentation: Remove bogus claim about del_timer_sync()
    - timers: Get rid of del_singleshot_timer_sync()
    - Documentation: Replace del_timer/del_timer_sync()
    - timers: Update the documentation to reflect on the new timer_shutdown()
      API
    - Bluetooth: hci_qca: Fix the teardown problem for real
    - binderfs: fix ida_alloc_max() upper bound
    - net: usb: sr9700: support devices with virtual driver CD
    - block,bfq: fix aux stat accumulation destination
    - HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL
    - HID: intel-ish-hid: Reset enum_devices_done before enumeration
    - HID: playstation: Center initial joystick axes to prevent spurious
      events
    - ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk
    - netfilter: replace -EEXIST with -EBUSY
    - HID: quirks: Add another Chicony HP 5MP Cameras to hid_ignore_list
    - HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30 (2d99:a101)
    - ring-buffer: Avoid softlockup in ring_buffer_resize() during memory free
    - wifi: mac80211: collect station statistics earlier when disconnect
    - ASoC: davinci-evm: Fix reference leak in davinci_evm_probe
    - ASoC: tlv320adcx140: Propagate error codes during probe
    - wifi: cfg80211: Fix bitrate calculation overflow for HE rates
    - wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt twice
    - platform/x86: intel_telemetry: Fix PSS event register mask
    - tipc: use kfree_sensitive() for session key material
    - hwmon: (occ) Mark occ_init_attribute() as __printf
    - nvmet-tcp: add an helper to free the cmd buffers
    - nvmet-tcp: fix memory leak when performing a controller reset
    - nvmet-tcp: fix regression in data_digest calculation
    - nvmet-tcp: don't map pages which can't come from HIGHMEM
    - tracing: Fix ftrace event field alignments
    - gve: Correct ethtool rx_dropped calculation
    - spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed
      transfer
    - spi: tegra210-quad: Move curr_xfer read inside spinlock
    - spi: tegra210-quad: Protect curr_xfer assignment in
      tegra_qspi_setup_transfer_one
    - spi: tegra210-quad: Protect curr_xfer clearing in
      tegra_qspi_non_combined_seq_xfer
    - nvmet-tcp: pass iov_len instead of sg->length to bvec_set_page()
    - riscv: Replace function-like macro by static inline function
    - Linux 5.15.200
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23182
    - spi: tegra: Fix a memory leak in tegra_slink_probe()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23202
    - spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-71089
    - iommu: disable SVA when CONFIG_X86 is set
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2023-53673
    - Bluetooth: hci_event: call disconnect callback before deleting conn
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23262
    - gve: Fix stats report corruption on queue count change
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-40082
    - hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-37822
    - riscv: uprobes: Add missing fence.i after building the XOL buffer
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23190
    - ASoC: amd: fix memory leak in acp3x pdm dma ops
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23112
    - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23111
    - netfilter: nf_tables: fix inverted genmask check in
      nft_map_catchall_activate()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23180
    - dpaa2-switch: add bounds check for if_id in IRQ handler
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23256
    - net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23257
    - net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23258
    - net: liquidio: Initialize netdev pointer before queue setup
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23206
    - dpaa2-switch: prevent ZERO_SIZE_PTR dereference when num_ifs is zero
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23176
    - platform/x86: toshiba_haps: Fix memory leaks in add/remove routines
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23216
    - scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23193
    - scsi: target: iscsi: Fix use-after-free in
      iscsit_dec_session_usage_count()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-71220
    - smb/server: call ksmbd_session_rpc_close() on error path in
      create_smb2_pipe()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-71222
    - wifi: wlcore: ensure skb headroom before skb_push
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-71224
    - wifi: mac80211: ocb: skip rx_no_sta when interface is not joined
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-68214
    - timers: Fix NULL function pointer race in timer_shutdown_sync()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-38201
    - netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23198
    - KVM: Don't clobber irqfd routing type when deassigning irqfd
  * CVE-2026-23272
    - netfilter: nf_tables: always increment set element count
    - netfilter: nf_tables: fix set size with rbtree backend
    - netfilter: nf_tables: unconditionally bump set->nelems before insertion
  * CVE-2026-31418
    - netfilter: ipset: drop logically empty buckets in mtype_del
  * CVE-2026-23278
    - netfilter: nf_tables: always walk all pending catchall elements
  * CVE-2026-46300
    - net: skbuff: preserve shared-frag marker during coalescing
    - net: skbuff: propagate shared-frag marker through frag-transfer helpers
  * net/rds: reset op_nents when zerocopy page pin fails (LP: #2153962)
    - net/rds: reset op_nents when zerocopy page pin fails
  * CVE-2026-46333
    - ptrace: slightly saner 'get_dumpable()' logic
  * CVE-2026-43500
    - rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
  * CVE-2026-43284
    - xfrm: esp: avoid in-place decrypt on shared skb frags
    - xfrm: esp: ipv4: fix up flags setting
  * CVE-2026-31419
    - net: bonding: fix use-after-free in bond_xmit_broadcast()
  * CVE-2026-31431
    - crypto: scatterwalk - Backport memcpy_sglist()
    - crypto: algif_aead - use memcpy_sglist() instead of null skcipher
    - crypto: algif_aead - Revert to operating out-of-place
    - crypto: algif_aead - snapshot IV for async AEAD requests
    - crypto: authenc - use memcpy_sglist() instead of null skcipher
    - crypto: authencesn - Do not place hiseq at end of dst for out-of-place
      decryption
    - crypto: authencesn - Fix src offset when decrypting in-place
    - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
    - crypto: algif_aead - Fix minimum RX size check for decryption
  * CVE-2026-31533
    - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
  * CVE-2026-31504
    - net: fix fanout UAF in packet_release() via NETDEV_UP race

Date: 2026-06-22 20:50:11.137378+00:00
Changed-By: Bethany Jamison <bethany.jamison at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1106.112
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list