[ubuntu/jammy-updates] linux-raspi 5.15.0-1105.108 (Accepted)
Andy Whitcroft
apw at canonical.com
Mon Jul 6 20:54:24 UTC 2026
linux-raspi (5.15.0-1105.108) jammy; urgency=medium
* jammy/linux-raspi: 5.15.0-1105.108 -proposed tracker (LP: #2157246)
[ Ubuntu: 5.15.0-185.195 ]
* jammy/linux: 5.15.0-185.195 -proposed tracker (LP: #2157253)
* Packaging resync (LP: #1786013)
- [Packaging] update annotations scripts
- [Packaging] resync retpoline extraction
* CVE-2026-45988
- rxrpc: Fix re-decryption of RESPONSE packets
* CVE-2026-46195
- smb: client: validate dacloffset before building DACL pointers
* CVE-2026-46135
- nvmet-tcp: fix race between ICReq handling and queue teardown
* CVE-2026-31402
- nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
* CVE-2026-43071
- dcache: Limit the minimal number of bucket to two
* CVE-2026-46119
- libceph: Fix slab-out-of-bounds access in auth message processing
* CVE-2026-43501
- ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
* CVE-2026-46043
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
* CVE-2026-43493
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests
* CVE-2026-31637
- rxrpc: reject undecryptable rxkad response tickets
* CVE-2026-31657
- batman-adv: hold claim backbone gateways by reference
* CVE-2026-31685
- netfilter: ip6t_eui64: reject invalid MAC header for all packets
* CVE-2026-43117
- btrfs: tracepoints: get correct superblock from dentry in event
btrfs_sync_file()
* CVE-2026-43114
- netfilter: nft_set_pipapo_avx2: don't return non-matching entry on
expiry
* CVE-2026-31478
- ksmbd: replace hardcoded hdr2_len with offsetof() in
smb2_calc_max_out_buf_len()
* CVE-2026-31668
- seg6: separate dst_cache for input and output paths in seg6 lwtunnel
* CVE-2026-31659
- batman-adv: reject oversized global TT response buffers
* CVE-2026-31649
- net: stmmac: fix integer underflow in chain mode
* CVE-2026-31669
- mptcp: fix slab-use-after-free in __inet_lookup_established
* CVE-2026-43011
- net/x25: Fix potential double free of skb
* CVE-2026-43037
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
* CVE-2026-43038
- ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
* CVE-2026-31682
- bridge: br_nd_send: linearize skb before parsing ND options
* CVE-2026-23450
- net/smc: Only save the original clcsock callback functions
- net/smc: Fix slab-out-of-bounds issue in fallback
- net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
* CVE-2026-23428
- ksmbd: fix use-after-free of share_conf in compound request
* CVE-2026-23455
- netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
* CVE-2026-43186
- ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data()
* CVE-2026-43185
- ksmbd: fix signededness bug in smb_direct_prepare_negotiation()
* CVE-2026-43341
- net/ipv6: ioam6: prevent schema length wraparound in trace fill
* CVE-2026-31607
- usbip: validate number_of_packets in usbip_pack_ret_submit()
* CVE-2026-43383
- net/tcp-md5: Fix MAC comparison to be constant-time
* CVE-2025-68263
- ksmbd: ipc: fix use-after-free in ipc_msg_send_request
* CVE-2026-46243
- smb: client: reject userspace cifs.spnego descriptions
* CVE-2026-43414
- scsi: qla2xxx: Completely fix fcport double free
* CVE-2026-43407
- libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()
* CVE-2026-43406
- libceph: prevent potential out-of-bounds reads in
process_message_header()
* CVE-2026-43304
- libceph: define and enforce CEPH_MAX_KEY_LEN
* CVE-2025-37924
- ksmbd: fix use-after-free in kerberos authentication
* CVE-2025-37778
- ksmbd: Fix dangling pointer in krb_authenticate
linux-raspi (5.15.0-1104.107) jammy; urgency=medium
* jammy/linux-raspi: 5.15.0-1104.107 -proposed tracker (LP: #2152000)
[ Ubuntu: 5.15.0-184.194 ]
* jammy/linux: 5.15.0-184.194 -proposed tracker (LP: #2154219)
* Kernel regression (6.8.0-117.generic) (LP: #2153556)
- net: bonding: update the slave array for broadcast mode
- bonding: do not set usable_slaves for broadcast mode
* kernel null pointer BUG in 5.15 when disconnecting from cifs share
(LP: #2150730)
- SAUCE: cifs: fix null pointer dereference in find_ipc_from_server_path
* SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
(LP: #2149767)
- SUNRPC: Check if the xprt is connected before handling sysfs reads
- SUNRPC: Do not dereference non-socket transports in sysfs
* SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
(LP: #2149767) // CVE-2022-48816
- SUNRPC: lock against ->sock changing during sysfs read
* iptables connlimit traffic loss (LP: #2149872)
- netfilter: nf_conncount: fix tracking of connections from localhost
* Some powerpc test from ubuntu_kernel_selftests timeout with 45 seconds
(LP: #2141536)
- selftests/powerpc: Lower run time of count_stcx_fail test
- selftests/powerpc: Give all tests 2 minutes timeout
* Jammy update: v5.15.200 upstream stable release (LP: #2147598)
- x86/kfence: fix booting on 32bit non-PAE systems
- platform/x86: intel_telemetry: Fix swapped arrays in PSS output
- rbd: check for EOD after exclusive lock is ensured to be held
- ARM: 9468/1: fix memset64() on big-endian
- mm/kfence: randomize the freelist on initialization
- Documentation: Remove bogus claim about del_timer_sync()
- timers: Get rid of del_singleshot_timer_sync()
- Documentation: Replace del_timer/del_timer_sync()
- timers: Update the documentation to reflect on the new timer_shutdown()
API
- Bluetooth: hci_qca: Fix the teardown problem for real
- binderfs: fix ida_alloc_max() upper bound
- net: usb: sr9700: support devices with virtual driver CD
- block,bfq: fix aux stat accumulation destination
- HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL
- HID: intel-ish-hid: Reset enum_devices_done before enumeration
- HID: playstation: Center initial joystick axes to prevent spurious
events
- ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk
- netfilter: replace -EEXIST with -EBUSY
- HID: quirks: Add another Chicony HP 5MP Cameras to hid_ignore_list
- HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30 (2d99:a101)
- ring-buffer: Avoid softlockup in ring_buffer_resize() during memory free
- wifi: mac80211: collect station statistics earlier when disconnect
- ASoC: davinci-evm: Fix reference leak in davinci_evm_probe
- ASoC: tlv320adcx140: Propagate error codes during probe
- wifi: cfg80211: Fix bitrate calculation overflow for HE rates
- wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt twice
- platform/x86: intel_telemetry: Fix PSS event register mask
- tipc: use kfree_sensitive() for session key material
- hwmon: (occ) Mark occ_init_attribute() as __printf
- nvmet-tcp: add an helper to free the cmd buffers
- nvmet-tcp: fix memory leak when performing a controller reset
- nvmet-tcp: fix regression in data_digest calculation
- nvmet-tcp: don't map pages which can't come from HIGHMEM
- tracing: Fix ftrace event field alignments
- gve: Correct ethtool rx_dropped calculation
- spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed
transfer
- spi: tegra210-quad: Move curr_xfer read inside spinlock
- spi: tegra210-quad: Protect curr_xfer assignment in
tegra_qspi_setup_transfer_one
- spi: tegra210-quad: Protect curr_xfer clearing in
tegra_qspi_non_combined_seq_xfer
- nvmet-tcp: pass iov_len instead of sg->length to bvec_set_page()
- riscv: Replace function-like macro by static inline function
- Linux 5.15.200
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23182
- spi: tegra: Fix a memory leak in tegra_slink_probe()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23202
- spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-71089
- iommu: disable SVA when CONFIG_X86 is set
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2023-53673
- Bluetooth: hci_event: call disconnect callback before deleting conn
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23262
- gve: Fix stats report corruption on queue count change
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-40082
- hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-37822
- riscv: uprobes: Add missing fence.i after building the XOL buffer
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23190
- ASoC: amd: fix memory leak in acp3x pdm dma ops
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23112
- nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23111
- netfilter: nf_tables: fix inverted genmask check in
nft_map_catchall_activate()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23180
- dpaa2-switch: add bounds check for if_id in IRQ handler
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23256
- net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23257
- net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23258
- net: liquidio: Initialize netdev pointer before queue setup
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23206
- dpaa2-switch: prevent ZERO_SIZE_PTR dereference when num_ifs is zero
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23176
- platform/x86: toshiba_haps: Fix memory leaks in add/remove routines
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23216
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23193
- scsi: target: iscsi: Fix use-after-free in
iscsit_dec_session_usage_count()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-71220
- smb/server: call ksmbd_session_rpc_close() on error path in
create_smb2_pipe()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-71222
- wifi: wlcore: ensure skb headroom before skb_push
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-71224
- wifi: mac80211: ocb: skip rx_no_sta when interface is not joined
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-68214
- timers: Fix NULL function pointer race in timer_shutdown_sync()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-38201
- netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23198
- KVM: Don't clobber irqfd routing type when deassigning irqfd
* CVE-2026-23272
- netfilter: nf_tables: always increment set element count
- netfilter: nf_tables: fix set size with rbtree backend
- netfilter: nf_tables: unconditionally bump set->nelems before insertion
* CVE-2026-31418
- netfilter: ipset: drop logically empty buckets in mtype_del
* CVE-2026-23278
- netfilter: nf_tables: always walk all pending catchall elements
* CVE-2026-46300
- net: skbuff: preserve shared-frag marker during coalescing
- net: skbuff: propagate shared-frag marker through frag-transfer helpers
* net/rds: reset op_nents when zerocopy page pin fails (LP: #2153962)
- net/rds: reset op_nents when zerocopy page pin fails
* CVE-2026-46333
- ptrace: slightly saner 'get_dumpable()' logic
* CVE-2026-43500
- rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
* CVE-2026-43284
- xfrm: esp: avoid in-place decrypt on shared skb frags
- xfrm: esp: ipv4: fix up flags setting
* CVE-2026-31419
- net: bonding: fix use-after-free in bond_xmit_broadcast()
* CVE-2026-31431
- crypto: scatterwalk - Backport memcpy_sglist()
- crypto: algif_aead - use memcpy_sglist() instead of null skcipher
- crypto: algif_aead - Revert to operating out-of-place
- crypto: algif_aead - snapshot IV for async AEAD requests
- crypto: authenc - use memcpy_sglist() instead of null skcipher
- crypto: authencesn - Do not place hiseq at end of dst for out-of-place
decryption
- crypto: authencesn - Fix src offset when decrypting in-place
- crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
- crypto: algif_aead - Fix minimum RX size check for decryption
* CVE-2026-31533
- net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
* CVE-2026-31504
- net: fix fanout UAF in packet_release() via NETDEV_UP race
Date: 2026-06-24 06:15:28.573468+00:00
Changed-By: Massimiliano Pellizzer <massimiliano.pellizzer at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-raspi/5.15.0-1105.108
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list