[ubuntu/noble-updates] linux 6.8.0-137.137 (Accepted)
Andy Whitcroft
apw at canonical.com
Tue Aug 4 08:12:05 UTC 2026
linux (6.8.0-137.137) noble; urgency=medium
* noble/linux: 6.8.0-137.137 -proposed tracker (LP: #2160836)
* Packaging resync (LP: #1786013)
- [Packaging] update annotations scripts
- [Packaging] debian.master/dkms-versions -- update from kernel-versions
(main/s2026.06.22)
* CVE-2026-53225
- sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
* CVE-2026-53228
- ipv6: sit: reload inner IPv6 header after GSO offloads
* CVE-2026-46242
- eventpoll: fix ep_remove struct eventpoll / struct file UAF
* CVE-2026-46331
- net/sched: fix pedit partial COW leading to page cache corruption
* CVE-2026-53212
- netfilter: nft_tunnel: fix use-after-free on object destroy
* CVE-2026-53359
- KVM: x86: Fix shadow paging use-after-free due to unexpected role
* CVE-2026-53151
- rxrpc: Fix the ACK parser to extract the SACK table for parsing
* CVE-2026-52924
- sctp: purge outqueue on stale COOKIE-ECHO handling
* CVE-2026-53215
- net: mvpp2: refill RX buffers before XDP or skb use
* CVE-2026-53176
- IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
* CVE-2026-52931
- batman-adv: tp_meter: avoid use of uninit sender vars
* CVE-2026-52914
- batman-adv: fix fragment reassembly length accounting
* CVE-2026-46325
- RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE
* CVE-2026-43465
- net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ
* CVE-2026-43198
- tcp: fix potential race in tcp_v6_syn_recv_sock()
* CVE-2026-43197
- netconsole: avoid OOB reads, msg is not nul-terminated
* CVE-2026-43083
- net: ioam6: fix OOB and missing lock
Date: 2026-07-17 18:15:17.407105+00:00
Changed-By: Manuel Diewald <manuel.diewald at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux/6.8.0-137.137
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list