[ubuntu/jammy-proposed] linux-ibm 5.15.0-1104.108 (Accepted)

Timo Aaltonen tjaalton at ubuntu.com
Wed Jun 24 22:15:36 UTC 2026


linux-ibm (5.15.0-1104.108) jammy; urgency=medium

  * jammy/linux-ibm: 5.15.0-1104.108 -proposed tracker (LP: #2151971)

  * Packaging resync (LP: #1786013)
    - [Packaging] resync retpoline extraction

  [ Ubuntu: 5.15.0-184.194 ]

  * jammy/linux: 5.15.0-184.194 -proposed tracker (LP: #2154219)
  * Kernel regression (6.8.0-117.generic) (LP: #2153556)
    - net: bonding: update the slave array for broadcast mode
    - bonding: do not set usable_slaves for broadcast mode
  * kernel null pointer BUG in 5.15 when disconnecting from cifs share
    (LP: #2150730)
    - SAUCE: cifs: fix null pointer dereference in find_ipc_from_server_path
  * SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
    (LP: #2149767)
    - SUNRPC: Check if the xprt is connected before handling sysfs reads
    - SUNRPC: Do not dereference non-socket transports in sysfs
  * SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
    (LP: #2149767) // CVE-2022-48816
    - SUNRPC: lock against ->sock changing during sysfs read
  * iptables connlimit traffic loss (LP: #2149872)
    - netfilter: nf_conncount: fix tracking of connections from localhost
  * Some powerpc test from ubuntu_kernel_selftests timeout with 45 seconds
    (LP: #2141536)
    - selftests/powerpc: Lower run time of count_stcx_fail test
    - selftests/powerpc: Give all tests 2 minutes timeout
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598)
    - x86/kfence: fix booting on 32bit non-PAE systems
    - platform/x86: intel_telemetry: Fix swapped arrays in PSS output
    - rbd: check for EOD after exclusive lock is ensured to be held
    - ARM: 9468/1: fix memset64() on big-endian
    - mm/kfence: randomize the freelist on initialization
    - Documentation: Remove bogus claim about del_timer_sync()
    - timers: Get rid of del_singleshot_timer_sync()
    - Documentation: Replace del_timer/del_timer_sync()
    - timers: Update the documentation to reflect on the new timer_shutdown()
      API
    - Bluetooth: hci_qca: Fix the teardown problem for real
    - binderfs: fix ida_alloc_max() upper bound
    - net: usb: sr9700: support devices with virtual driver CD
    - block,bfq: fix aux stat accumulation destination
    - HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL
    - HID: intel-ish-hid: Reset enum_devices_done before enumeration
    - HID: playstation: Center initial joystick axes to prevent spurious
      events
    - ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk
    - netfilter: replace -EEXIST with -EBUSY
    - HID: quirks: Add another Chicony HP 5MP Cameras to hid_ignore_list
    - HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30 (2d99:a101)
    - ring-buffer: Avoid softlockup in ring_buffer_resize() during memory free
    - wifi: mac80211: collect station statistics earlier when disconnect
    - ASoC: davinci-evm: Fix reference leak in davinci_evm_probe
    - ASoC: tlv320adcx140: Propagate error codes during probe
    - wifi: cfg80211: Fix bitrate calculation overflow for HE rates
    - wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt twice
    - platform/x86: intel_telemetry: Fix PSS event register mask
    - tipc: use kfree_sensitive() for session key material
    - hwmon: (occ) Mark occ_init_attribute() as __printf
    - nvmet-tcp: add an helper to free the cmd buffers
    - nvmet-tcp: fix memory leak when performing a controller reset
    - nvmet-tcp: fix regression in data_digest calculation
    - nvmet-tcp: don't map pages which can't come from HIGHMEM
    - tracing: Fix ftrace event field alignments
    - gve: Correct ethtool rx_dropped calculation
    - spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed
      transfer
    - spi: tegra210-quad: Move curr_xfer read inside spinlock
    - spi: tegra210-quad: Protect curr_xfer assignment in
      tegra_qspi_setup_transfer_one
    - spi: tegra210-quad: Protect curr_xfer clearing in
      tegra_qspi_non_combined_seq_xfer
    - nvmet-tcp: pass iov_len instead of sg->length to bvec_set_page()
    - riscv: Replace function-like macro by static inline function
    - Linux 5.15.200
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23182
    - spi: tegra: Fix a memory leak in tegra_slink_probe()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23202
    - spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-71089
    - iommu: disable SVA when CONFIG_X86 is set
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2023-53673
    - Bluetooth: hci_event: call disconnect callback before deleting conn
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23262
    - gve: Fix stats report corruption on queue count change
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-40082
    - hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-37822
    - riscv: uprobes: Add missing fence.i after building the XOL buffer
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23190
    - ASoC: amd: fix memory leak in acp3x pdm dma ops
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23112
    - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23111
    - netfilter: nf_tables: fix inverted genmask check in
      nft_map_catchall_activate()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23180
    - dpaa2-switch: add bounds check for if_id in IRQ handler
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23256
    - net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23257
    - net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23258
    - net: liquidio: Initialize netdev pointer before queue setup
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23206
    - dpaa2-switch: prevent ZERO_SIZE_PTR dereference when num_ifs is zero
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23176
    - platform/x86: toshiba_haps: Fix memory leaks in add/remove routines
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23216
    - scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23193
    - scsi: target: iscsi: Fix use-after-free in
      iscsit_dec_session_usage_count()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-71220
    - smb/server: call ksmbd_session_rpc_close() on error path in
      create_smb2_pipe()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-71222
    - wifi: wlcore: ensure skb headroom before skb_push
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-71224
    - wifi: mac80211: ocb: skip rx_no_sta when interface is not joined
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-68214
    - timers: Fix NULL function pointer race in timer_shutdown_sync()
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-38201
    - netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX
  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23198
    - KVM: Don't clobber irqfd routing type when deassigning irqfd
  * CVE-2026-23272
    - netfilter: nf_tables: always increment set element count
    - netfilter: nf_tables: fix set size with rbtree backend
    - netfilter: nf_tables: unconditionally bump set->nelems before insertion
  * CVE-2026-31418
    - netfilter: ipset: drop logically empty buckets in mtype_del
  * CVE-2026-23278
    - netfilter: nf_tables: always walk all pending catchall elements
  * CVE-2026-46300
    - net: skbuff: preserve shared-frag marker during coalescing
    - net: skbuff: propagate shared-frag marker through frag-transfer helpers
  * net/rds: reset op_nents when zerocopy page pin fails (LP: #2153962)
    - net/rds: reset op_nents when zerocopy page pin fails
  * CVE-2026-46333
    - ptrace: slightly saner 'get_dumpable()' logic
  * CVE-2026-43500
    - rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
  * CVE-2026-43284
    - xfrm: esp: avoid in-place decrypt on shared skb frags
    - xfrm: esp: ipv4: fix up flags setting
  * CVE-2026-31419
    - net: bonding: fix use-after-free in bond_xmit_broadcast()
  * CVE-2026-31431
    - crypto: scatterwalk - Backport memcpy_sglist()
    - crypto: algif_aead - use memcpy_sglist() instead of null skcipher
    - crypto: algif_aead - Revert to operating out-of-place
    - crypto: algif_aead - snapshot IV for async AEAD requests
    - crypto: authenc - use memcpy_sglist() instead of null skcipher
    - crypto: authencesn - Do not place hiseq at end of dst for out-of-place
      decryption
    - crypto: authencesn - Fix src offset when decrypting in-place
    - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
    - crypto: algif_aead - Fix minimum RX size check for decryption
  * CVE-2026-31533
    - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
  * CVE-2026-31504
    - net: fix fanout UAF in packet_release() via NETDEV_UP race

Date: 2026-06-11 19:32:11.693387+00:00
Changed-By: Ross Porter <ross.porter at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-ibm/5.15.0-1104.108
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list