[ubuntu/noble-security] linux-azure-6.17 6.17.0-1022.22 (Accepted)

Andy Whitcroft apw at canonical.com
Thu Aug 6 08:58:34 UTC 2026


linux-azure-6.17 (6.17.0-1022.22) noble; urgency=medium

  * noble/linux-azure-6.17: 6.17.0-1022.22 -proposed tracker (LP: #2161414)

  * Packaging resync (LP: #1786013)
    - [Packaging] debian.azure-6.17/dkms-versions -- update from kernel-
      versions (main/s2026.06.22)

  * CVE-2026-53359
    - KVM: x86: Fix shadow paging use-after-free due to unexpected role

  * CVE-2026-46113
    - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN

  * CVE-2026-53212
    - netfilter: nft_tunnel: fix use-after-free on object destroy

  * CVE-2026-46331
    - net/sched: fix pedit partial COW leading to page cache corruption

  * CVE-2026-46242
    - eventpoll: fix ep_remove struct eventpoll / struct file UAF

  * CVE-2026-43499
    - rtmutex: Use waiter::task instead of current in remove_waiter()

  * CVE-2026-53131
    - netfilter: require Ethernet MAC header before using eth_hdr()

  * CVE-2026-53086
    - net: bcmgenet: fix racing timeout handler

  * CVE-2026-53225
    - sctp: fix uninit-value in __sctp_rcv_asconf_lookup()

  * CVE-2026-53228
    - ipv6: sit: reload inner IPv6 header after GSO offloads

  * CVE-2026-52924
    - sctp: purge outqueue on stale COOKIE-ECHO handling

  * CVE-2026-52989
    - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers

  * CVE-2026-53176
    - IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN

  * CVE-2026-46137
    - mptcp: pm: ADD_ADDR rtx: fix potential data-race

  * CVE-2026-43465
    - net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ

  * CVE-2026-43379
    - ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()

  * CVE-2026-43198
    - tcp: fix potential race in tcp_v6_syn_recv_sock()

  * CVE-2026-31705
    - ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment

  * CVE-2026-31636
    - rxrpc: fix RESPONSE authenticator parser OOB read

  * CVE-2026-31633
    - rxrpc: Fix integer overflow in rxgk_verify_response()

  * CVE-2026-31589
    - mm: call ->free_folio() directly in folio_unmap_invalidate()

  * CVE-2026-31501
    - net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path

  * CVE-2026-31414
    - netfilter: nf_conntrack_expect: use expect->helper

  * CVE-2026-31405
    - media: dvb-net: fix OOB access in ULE extension header tables

Date: 2026-07-27 16:11:12.390333+00:00
Changed-By: Benjamin Wheeler <benjamin.wheeler at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-azure-6.17/6.17.0-1022.22
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list