[ubuntu/jammy-updates] linux-azure 5.15.0-1114.123 (Accepted)
Andy Whitcroft
apw at canonical.com
Mon Jun 8 12:31:44 UTC 2026
linux-azure (5.15.0-1114.123) jammy; urgency=medium
* jammy/linux-azure: 5.15.0-1114.123 -proposed tracker (LP: #2153630)
[ Ubuntu: 5.15.0-181.191 ]
* jammy/linux: 5.15.0-181.191 -proposed tracker (LP: #2153680)
* Packaging resync (LP: #1786013)
- [Packaging] update annotations scripts
- [Packaging] resync retpoline extraction
* CVE-2026-46300
- net: skbuff: preserve shared-frag marker during coalescing
- net: skbuff: propagate shared-frag marker through frag-transfer helpers
* net/rds: reset op_nents when zerocopy page pin fails (LP: #2153962)
- net/rds: reset op_nents when zerocopy page pin fails
* CVE-2026-46333
- ptrace: slightly saner 'get_dumpable()' logic
* CVE-2026-43500
- rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
* CVE-2026-43284
- xfrm: esp: avoid in-place decrypt on shared skb frags
- xfrm: esp: ipv4: fix up flags setting
linux-azure (5.15.0-1113.122) jammy; urgency=medium
* jammy/linux-azure: 5.15.0-1113.122 -proposed tracker (LP: #2150965)
[ Ubuntu: 5.15.0-179.189 ]
* jammy/linux: 5.15.0-179.189 -proposed tracker (LP: #2151014)
* CVE-2026-31419
- net: bonding: fix use-after-free in bond_xmit_broadcast()
* CVE-2026-31431
- crypto: scatterwalk - Backport memcpy_sglist()
- crypto: algif_aead - use memcpy_sglist() instead of null skcipher
- crypto: algif_aead - Revert to operating out-of-place
- crypto: algif_aead - snapshot IV for async AEAD requests
- crypto: authenc - use memcpy_sglist() instead of null skcipher
- crypto: authencesn - Do not place hiseq at end of dst for out-of-place
decryption
- crypto: authencesn - Fix src offset when decrypting in-place
- crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
- crypto: algif_aead - Fix minimum RX size check for decryption
* CVE-2026-31533
- net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
* CVE-2026-31504
- net: fix fanout UAF in packet_release() via NETDEV_UP race
linux-azure (5.15.0-1112.121) jammy; urgency=medium
* jammy/linux-azure: 5.15.0-1112.121 -proposed tracker (LP: #2148406)
[ Ubuntu: 5.15.0-178.188 ]
* jammy/linux: 5.15.0-178.188 -proposed tracker (LP: #2148097)
* Canonical Kmod 2025 key rotation (LP: #2147447)
- [Packaging] ubuntu-compatible-signing -- make Ubuntu-Compatible-Signing
extensible
- [Packaging] ubuntu-compatible-signing -- allow consumption of positive
certs
- [Packaging] ubuntu-compatible-signing -- report the livepatch:2025 key
- [Config] prepare for Canonical Kmod key rotation
- [Packaging] ubuntu-compatible-signing -- report the kmod:2025 key
* ADATA SU680 causes repeated SATA resets and I/O errors on Ubuntu unless
link power management is forced to max_performance (LP: #2144060)
- ata: libata-core: disable LPM on ADATA SU680 SSD
* CVE-2024-50060
- io_uring: check if we need to reschedule during overflow flush
* CVE-2024-35862
- smb: client: fix potential UAF in smb2_is_network_name_deleted()
* CVE-2026-23274
- netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
* CVE-2026-23351
- netfilter: nf_tables: de-constify set commit ops function argument
- netfilter: nft_set_pipapo: split gc into unlink and reclaim phase
* macvlan: observe an RCU grace period in macvlan_common_newlink() error
path (LP: #2144380) // CVE-2026-23209
- macvlan: observe an RCU grace period in macvlan_common_newlink() error
path
* CVE-2023-2640 // CVE-2023-32629
- SAUCE: overlayfs: default to userxattr when mounted from non initial
user namespace
* CVE-2023-2640 // CVE-2023-2640 and CVE-2023-32629. // CVE-2023-32629
- SAUCE: Revert "UBUNTU: SAUCE: overlayfs: Skip permission checking for
trusted.overlayfs.* xattrs"
* CVE-2026-23112
- nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
Date: 2026-05-26 14:24:19.578410+00:00
Changed-By: Alessio Faina <alessio.faina at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-azure/5.15.0-1114.123
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list