[ubuntu/jammy-security] linux-nvidia-6.8 6.8.0-1063.66~22.04.1 (Accepted)

Andy Whitcroft apw at canonical.com
Mon Sep 28 13:20:00 UTC 2026


linux-nvidia-6.8 (6.8.0-1063.66~22.04.1) jammy; urgency=medium

  * jammy/linux-nvidia-6.8: 6.8.0-1063.66~22.04.1 -proposed tracker (LP: #2165696)

  * Packaging resync (LP: #1786013)
    - [Packaging] debian.nvidia-6.8/dkms-versions -- update from kernel-
      versions (main/s2026.08.03)

  [ Ubuntu-nvidia: 6.8.0-1063.66 ]

  * noble/linux-nvidia: 6.8.0-1063.66 -proposed tracker (LP: #2165697)
  * Packaging resync (LP: #1786013)
    - [Packaging] debian.nvidia/dkms-versions -- update from kernel-versions
      (main/s2026.08.03)
  [ Ubuntu: 6.8.0-142.142 ]
  * noble/linux: 6.8.0-142.142 -proposed tracker (LP: #2165997)
  * Packaging resync (LP: #1786013)
    - [Packaging] debian.master/dkms-versions -- update from kernel-versions
      (main/s2026.08.03)
  [ Ubuntu: 6.8.0-140.140 ]
  * noble/linux: 6.8.0-140.140 -proposed tracker (LP: #2165716)
  * CVE-2025-10263 // CVE-2026-53354
    - arm64: errata: Mitigate TLBI errata on various Arm CPUs
    - [Config] Enable CONFIG_ARM64_ERRATUM_4118414
  * CVE-2025-10263
    - arm64: cputype: Add C1-Ultra definitions
    - arm64: cputype: Add C1-Premium definitions
  * CVE-2026-53355
    - net: rds: clear i_sends on setup unwind
  * CVE-2026-53186
    - RDMA/srp: bound SRP_RSP sense copy by the received length
  * CVE-2026-53216
    - net: mvpp2: limit XDP frame size to the RX buffer
  * CVE-2026-63888
    - scsi: target: iscsi: Fix CRC overread and double-free in
      iscsit_handle_text_cmd()
  * CVE-2026-63886
    - scsi: target: iscsi: Validate CHAP_R length before base64 decode
  * CVE-2026-63887
    - scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
  * CVE-2026-63912
    - xfrm: esp: restore combined single-frag length gate
  * CVE-2026-63922
    - ipv6: exthdrs: refresh nh after handling HAO option
  * CVE-2026-63924
    - ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
  * CVE-2026-64091
    - batman-adv: tt: fix TOCTOU race for reported vlans
  * CVE-2026-63984
    - ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
  * CVE-2026-63992
    - tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
  * CVE-2026-63993
    - vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
  * CVE-2026-63994
    - tunnels: load network headers after skb_cow() in
      iptunnel_pmtud_build_icmp[v6]()
  * CVE-2026-64000
    - net: hsr: fix potential OOB access in supervision frame handling
  * CVE-2026-64007
    - netfilter: synproxy: refresh tcphdr after skb_ensure_writable
  * CVE-2026-53221
    - ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
  * CVE-2026-53131
    - netfilter: require Ethernet MAC header before using eth_hdr()

Date: 2026-09-09 21:03:17.741145+00:00
Changed-By: Jacob Martin <jacob.martin at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-nvidia-6.8/6.8.0-1063.66~22.04.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list