[ubuntu/noble-proposed] linux-hwe-6.17 6.17.0-44.44 (Accepted)
Timo Aaltonen
tjaalton at ubuntu.com
Fri Aug 7 08:25:39 UTC 2026
linux-hwe-6.17 (6.17.0-44.44) noble; urgency=medium
* noble/linux-hwe-6.17: 6.17.0-44.44 -proposed tracker (LP: #2162477)
* CVE-2026-52982
- net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
* CVE-2026-52999
- netfilter: nfnetlink_osf: fix out-of-bounds read on option matching
* CVE-2026-64531
- net: openvswitch: reject oversized nested action attrs
* CVE-2026-53216
- net: mvpp2: limit XDP frame size to the RX buffer
* CVE-2026-53049
- gfs2: add some missing log locking
* CVE-2026-53175
- inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
* CVE-2026-53006
- ipv6: fix possible UAF in icmpv6_rcv()
* CVE-2026-52993
- tipc: fix double-free in tipc_buf_append()
* CVE-2026-52986
- netfilter: nf_conntrack_sip: don't use simple_strtoul
* CVE-2026-52914
- batman-adv: fix fragment reassembly length accounting
* CVE-2026-52955
- libceph: Fix potential out-of-bounds access in crush_decode()
* CVE-2026-53260
- tcp: Add preempt_{disable, enable}_nested() in reqsk_queue_hash_req().
* CVE-2026-53247
- net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
* CVE-2026-53215
- net: mvpp2: refill RX buffers before XDP or skb use
* CVE-2026-53055
- crypto: hisilicon/sec2 - prevent req used-after-free for sec
* CVE-2026-53045
- memory: tegra124-emc: Fix dll_change check
* CVE-2026-53046
- ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine
* CVE-2026-53043
- ocfs2/dlm: validate qr_numregions in dlm_match_regions()
* CVE-2026-52958
- libceph: Fix potential out-of-bounds access in osdmap_decode()
* CVE-2026-52931
- batman-adv: tp_meter: avoid use of uninit sender vars
* CVE-2026-53224
- sctp: validate embedded INIT chunk and address list lengths in cookie
* CVE-2026-53246
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
* CVE-2026-53309
- ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
* CVE-2026-53151
- rxrpc: Fix the ACK parser to extract the SACK table for parsing
* CVE-2026-53088
- net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
* CVE-2026-53010
- ksmbd: fix use-after-free in smb2_open during durable reconnect
* CVE-2026-53002
- netfilter: conntrack: remove sprintf usage
* Clean up packaging bits (LP: #2081030)
- [Packaging] Remove obsolete packaging scripts
* Don't produce linux-*-cloud-tools-common, linux-*-tools-common and
linux-*-tools-host binary packages (LP: #2048183)
- [Packaging] Remove invalid/unused do_* build flags
* CVE-2026-53359
- KVM: x86: Fix shadow paging use-after-free due to unexpected role
* CVE-2026-46113
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN
* CVE-2026-53212
- netfilter: nft_tunnel: fix use-after-free on object destroy
* CVE-2026-46331
- net/sched: fix pedit partial COW leading to page cache corruption
* CVE-2026-46242
- eventpoll: fix ep_remove struct eventpoll / struct file UAF
* CVE-2026-43499
- rtmutex: Use waiter::task instead of current in remove_waiter()
* CVE-2026-53131
- netfilter: require Ethernet MAC header before using eth_hdr()
* CVE-2026-53086
- net: bcmgenet: fix racing timeout handler
* CVE-2026-53225
- sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
* CVE-2026-53228
- ipv6: sit: reload inner IPv6 header after GSO offloads
* CVE-2026-52924
- sctp: purge outqueue on stale COOKIE-ECHO handling
* CVE-2026-52989
- nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
* CVE-2026-53176
- IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
* CVE-2026-46137
- mptcp: pm: ADD_ADDR rtx: fix potential data-race
* CVE-2026-43465
- net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ
* CVE-2026-43379
- ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()
* CVE-2026-43198
- tcp: fix potential race in tcp_v6_syn_recv_sock()
* CVE-2026-31705
- ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment
* CVE-2026-31636
- rxrpc: fix RESPONSE authenticator parser OOB read
* CVE-2026-31633
- rxrpc: Fix integer overflow in rxgk_verify_response()
* CVE-2026-31589
- mm: call ->free_folio() directly in folio_unmap_invalidate()
* CVE-2026-31501
- net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path
* CVE-2026-31414
- netfilter: nf_conntrack_expect: use expect->helper
* CVE-2026-31405
- media: dvb-net: fix OOB access in ULE extension header tables
* Packaging resync (LP: #1786013)
- [Packaging] update variants
- [Packaging] update update.conf
- [Packaging] update annotations scripts
Date: 2026-08-01 02:21:11.597180+00:00
Changed-By: Edoardo Canepa <edoardo.canepa at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-hwe-6.17/6.17.0-44.44
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list