[ubuntu/noble-updates] linux-oem-6.17 6.17.0-1028.28 (Accepted)
Andy Whitcroft
apw at canonical.com
Tue Jun 30 22:25:02 UTC 2026
linux-oem-6.17 (6.17.0-1028.28) noble; urgency=medium
* noble/linux-oem-6.17: 6.17.0-1028.28 -proposed tracker (LP: #2158224)
* [SRU]Enable Realtek ALC287 + Cirrus CS35L56 Audio for Lenovo Yoga Pro 7
(LP: #2156867)
- ALSA: hda/realtek: ALC269 fixup for Lenovo Yoga Pro 7 15ASH111 audio
- ALSA: hda/realtek:ALC269 fixup for Yoga Pro 7 15ASH11 mic mute LED
- ASoC: amd: acp: add DMI override for ACP70 flag
- ASoC: amd: acp: Add DMI quirk for Lenovo Yoga Pro 7 15ASH11
* Fix missing audio output device on Dell Slate HPT platform (LP: #2156830)
- ASoC: amd: acp: Add ACP6.3 match entries for Cirrus Logic parts
* MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260
renders upside-down (LP: #2155837)
- SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14
Premium PA14260
* Fix no audio from right built-in speaker on HP ZBook with TAS2781
amplifier (LP: #2156556)
- ALSA: hda/tas2781: Fix device-0 reset issue and handle -EXDEV in block
data processing
* Audio shows Dummy Output on systems with Cirrus Logic cs42l43 codec
(LP: #2156313)
- SAUCE: ASoC: sdw_utils: fix missing component_name for cs42l43 part_id
0x2A3B
* [SRU] Correct FIXED_VS Link Rate Toggle Condition (LP: #2155619)
- drm/amd/display: Correct FIXED_VS Link Rate Toggle Condition
* Internal display black screen on Intel Lunar Lake with eDP panel
(LP: #2156312)
- drm/i915/alpm: Allow LOBF only for platform that have Always on VRR TG
linux-oem-6.17 (6.17.0-1027.27) noble; urgency=medium
* noble/linux-oem-6.17: 6.17.0-1027.27 -proposed tracker (LP: #2157630)
[ Ubuntu: 6.17.0-40.40 ]
* questing/linux: 6.17.0-40.40 -proposed tracker (LP: #2157631)
* CVE-2026-43037
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
[ Ubuntu: 6.17.0-39.39 ]
* questing/linux: 6.17.0-39.39 -proposed tracker (LP: #2157145)
* Packaging resync (LP: #1786013)
- [Packaging] update annotations scripts
* CVE-2026-45988
- rxrpc: Fix re-decryption of RESPONSE packets
* CVE-2026-46135
- nvmet-tcp: fix race between ICReq handling and queue teardown
* CVE-2026-46195
- smb: client: validate dacloffset before building DACL pointers
* CVE-2026-31402
- nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
* CVE-2026-43378
- smb: server: fix use-after-free in smb2_open()
* CVE-2026-31657
- batman-adv: hold claim backbone gateways by reference
* CVE-2026-46266
- inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
* CVE-2026-46289
- lib/scatterlist: fix length calculations in extract_kvec_to_sg
* CVE-2026-31436
- dmaengine: idxd: fix possible wrong descriptor completion in
llist_abort_desc()
* CVE-2026-31649
- net: stmmac: fix integer underflow in chain mode
* CVE-2026-31659
- batman-adv: reject oversized global TT response buffers
* CVE-2026-31448
- ext4: avoid infinite loops caused by residual data
* CVE-2026-43071
- dcache: Limit the minimal number of bucket to two
* CVE-2026-31478
- ksmbd: replace hardcoded hdr2_len with offsetof() in
smb2_calc_max_out_buf_len()
* CVE-2026-31682
- bridge: br_nd_send: linearize skb before parsing ND options
* CVE-2026-43117
- btrfs: tracepoints: get correct superblock from dentry in event
btrfs_sync_file()
* CVE-2026-31669
- mptcp: fix slab-use-after-free in __inet_lookup_established
* CVE-2026-46115
- block: add pgmap check to biovec_phys_mergeable
* CVE-2026-45898
- RDMA/iwcm: Fix workqueue list corruption by removing work_list
* CVE-2026-46244
- netfilter: nft_inner: Fix IPv6 inner_thoff desync
* CVE-2026-43493
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests
* CVE-2026-43186
- ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data()
* CVE-2026-31685
- netfilter: ip6t_eui64: reject invalid MAC header for all packets
* CVE-2026-43114
- netfilter: nft_set_pipapo_avx2: don't return non-matching entry on
expiry
* CVE-2026-46325
- RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE
* CVE-2026-31668
- seg6: separate dst_cache for input and output paths in seg6 lwtunnel
* CVE-2026-43197
- netconsole: avoid OOB reads, msg is not nul-terminated
* CVE-2026-43083
- net: ioam6: fix OOB and missing lock
* CVE-2026-46043
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
* CVE-2026-23428
- ksmbd: fix use-after-free of share_conf in compound request
* CVE-2026-23450
- net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
* CVE-2026-46185
- smb/client: fix out-of-bounds read in symlink_data()
* CVE-2026-23455
- netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
* CVE-2026-46119
- libceph: Fix slab-out-of-bounds access in auth message processing
* CVE-2026-46039
- rxgk: Fix potential integer overflow in length check
* CVE-2026-23427
- ksmbd: fix use-after-free in durable v2 replay of active file handles
* CVE-2026-31718
- ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger
* CVE-2026-31637
- rxrpc: reject undecryptable rxkad response tickets
* CVE-2026-43011
- net/x25: Fix potential double free of skb
* CVE-2026-43038
- ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
* CVE-2026-31635
- rxrpc: fix oversized RESPONSE authenticator length check
* CVE-2026-43501
- ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
* CVE-2026-43125
- dlm: validate length in dlm_search_rsb_tree
* CVE-2026-46316
- KVM: arm64: vgic-its: Drop the translation cache reference only for the
erased entry
* CVE-2026-43185
- ksmbd: fix signededness bug in smb_direct_prepare_negotiation()
* CVE-2026-43341
- net/ipv6: ioam6: prevent schema length wraparound in trace fill
* CVE-2026-31607
- usbip: validate number_of_packets in usbip_pack_ret_submit()
* CVE-2026-43402
- kthread: consolidate kthread exit paths to prevent use-after-free
* CVE-2026-43384
- net/tcp-ao: Fix MAC comparison to be constant-time
* CVE-2026-43383
- net/tcp-md5: Fix MAC comparison to be constant-time
* CVE-2026-43376
- ksmbd: fix use-after-free by using call_rcu() for oplock_info
* CVE-2026-46243
- smb: client: reject userspace cifs.spnego descriptions
* CVE-2026-43414
- scsi: qla2xxx: Completely fix fcport double free
* CVE-2026-43407
- libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()
* CVE-2026-43406
- libceph: prevent potential out-of-bounds reads in
process_message_header()
* CVE-2026-43304
- libceph: define and enforce CEPH_MAX_KEY_LEN
* CVE-2026-22984
- libceph: prevent potential out-of-bounds reads in handle_auth_done()
linux-oem-6.17 (6.17.0-1026.26) noble; urgency=medium
* noble/linux-oem-6.17: 6.17.0-1026.26 -proposed tracker (LP: #2151894)
* Fix audio mute function not working on new Dell platforms (LP: #2155120)
- platform/x86: dell-wmi: Add audio/mic mute key codes
* Thunderbolt DP tunnel torn down during boot with LUKS Full Disk Encryption
(LP: #2155096)
- SAUCE: thunderbolt: Defer DP tunnel teardown until display driver is
ready
* Backport ASoC SDCA, AMD SoundWire, and RT722 audio fixes (LP: #2154418)
- ASoC: SDCA: Add companion amp Function
- ASoC: amd: acp: Add ACP7.0 match entries for Realtek parts
- ASoC: amd: amd_sdw: add machine driver quirk for Lenovo models
- ASoC: soc-component: re-add pcm_new()/pcm_free()
- ASoC: amd: name back to pcm_new()/pcm_free()
- ASoC: amd: acp: update dmic_num logic for acp pdm dmic
- ASoC: amd: acp-sdw-legacy: rename the dmic component name
- ASoC: amd: ps: fix the pcm device numbering for acp pdm dmic
- ASoC: amd: acp: add Lenovo P16s G5 AMD quirk for legacy SDW machine
- ASoC: amd: acp: update DMI quirk and add ACP DMIC for Lenovo platforms
- ASoC: sdw_utils: cs42l43: allow spk component names to be combined
- SAUCE: ASoC: rt722-sdca: add FU06 Playback Switch for speaker mute
control
* Fix graceful fault handling after FPU softirq changes causes hard freeze
on EFI runtime calls (LP: #2153976)
- x86/efi: Fix graceful fault handling after FPU softirq changes
* Lenovo T1g, P16s failed to enter suspend. (LP: #2150523) // dell pro max
16/14 premium failed to enter suspend on 6.17-oem (LP: #2150524)
- drm/i915/dp_mst: Fix check for FEC support for an uncompressed stream
* USB camera lost after suspend due to xhci endpoint_reset failure
(LP: #2153966)
- usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable()
* Kernel lockup on 6.17.0-1017-oem Lenovo P14s gen 6 AMD Ryzen AI 7 pro 350
(LP: #2148538)
- drm/amdgpu: make sure userqs are enabled in userq IOCTLs
- Revert "drm/amdgpu: don't attach the tlb fence for SI"
- drm/amdgpu: rework how we handle TLB fences
* Fix bad audio record quality when volume above 50% on Framework PTL
(LP: #2153155)
- ALSA: hda/realtek: fix mic boost on Framework PTL
[ Ubuntu: 6.17.0-38.38 ]
* questing/linux: 6.17.0-38.38 -proposed tracker (LP: #2154532)
* Generic questing kernel oops on bootup with newer Nvidia machines
(LP: #2154481)
- nouveau: don't attempt fwsec on sb on newer platforms.
* Kernel regression (6.8.0-117.generic) (LP: #2153556)
- bonding: do not set usable_slaves for broadcast mode
* powerpc-build in ubuntu_kernel_selftests fails to build due to
uninitialized value (LP: #2129844)
- selftests/powerpc: Suppress -Wmaybe-uninitialized with GCC 15
* iptables connlimit traffic loss (LP: #2149872)
- netfilter: nf_conncount: fix tracking of connections from localhost
* On Dell system, the internal OLED display drops to a visibly low FPS after
suspend/resume (LP: #2144712)
- drm/i915/psr: Disable Panel Replay on Dell XPS 14 DA14260 as a quirk
- drm/i915/psr: Fixes for Dell XPS DA14260 quirk
* CVE-2026-23272
- netfilter: nf_tables: unconditionally bump set->nelems before insertion
* CVE-2026-31418
- netfilter: ipset: drop logically empty buckets in mtype_del
* CVE-2026-23392
- netfilter: nf_tables: release flowtable after rcu grace period on error
* CVE-2026-23278
- netfilter: nf_tables: always walk all pending catchall elements
* GRO managed-frag use-after-free leading to local privilege escalation
(LP: #2154172)
- net: gro: don't merge zcopy skbs
* AppArmor Vulnerabilities (LP: #2151747)
- SAUCE: apparmor: pass big_resp to handler
- SAUCE: apparmor: remove redundant kref_init for listener->count
- SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47337
- SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47334
- SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47333
- SAUCE: apparmor: fix dfa unpacking size of the notification filter
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47332
- SAUCE: apparmor: fix size check against type instead of pointer
* apparmor: LLVM/clang build failure due to uninitialized variable in
notify.c (LP: #2148809) // CVE-2026-47330
- SAUCE: apparmor: initialize variable used in uninitialized context
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47329
- SAUCE: apparmor: fix name validation bypass on notification
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47327 //
CVE-2026-47328
- SAUCE: apparmor: fix glob memory leak after kstrdup
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47326
- SAUCE: apparmor: fix inverted NULL check after aa_get_buffer
* CVE-2026-46300
- net: skbuff: preserve shared-frag marker during coalescing
- net: skbuff: propagate shared-frag marker through frag-transfer helpers
* net/rds: reset op_nents when zerocopy page pin fails (LP: #2153962)
- net/rds: reset op_nents when zerocopy page pin fails
* CVE-2026-46333
- ptrace: slightly saner 'get_dumpable()' logic
* CVE-2026-43500
- rxrpc: Fix conn-level packet handling to unshare RESPONSE packets
- rxrpc: Fix potential UAF after skb_unshare() failure
- rxrpc: Fix rxrpc_input_call_event() to only unshare DATA packets
- rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
* CVE-2026-31676 // CVE-2026-43500
- rxrpc: only handle RESPONSE during service challenge
* CVE-2026-43284
- xfrm: esp: avoid in-place decrypt on shared skb frags
* CVE-2026-31419
- net: bonding: fix use-after-free in bond_xmit_broadcast()
* CVE-2026-31431
- crypto: algif_aead - Revert to operating out-of-place
- crypto: algif_aead - snapshot IV for async AEAD requests
- crypto: authencesn - Do not place hiseq at end of dst for out-of-place
decryption
- crypto: authencesn - Fix src offset when decrypting in-place
- crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
- crypto: algif_aead - Fix minimum RX size check for decryption
* CVE-2026-31533
- net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
* CVE-2026-31504
- net: fix fanout UAF in packet_release() via NETDEV_UP race
Date: 2026-06-25 06:46:13.672099+00:00
Changed-By: LEE KUAN-YING <kuan-ying.lee at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-oem-6.17/6.17.0-1028.28
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list