[ubuntu/noble-updates] linux-ibm 6.8.0-1065.66 (Accepted)

Andy Whitcroft apw at canonical.com
Tue Sep 22 16:53:41 UTC 2026


linux-ibm (6.8.0-1065.66) noble; urgency=medium

  * noble/linux-ibm: 6.8.0-1065.66 -proposed tracker (LP: #2165688)

  * Packaging resync (LP: #1786013)
    - [Packaging] debian.ibm/dkms-versions -- update from kernel-versions
      (main/s2026.08.03)

  [ Ubuntu: 6.8.0-142.142 ]

  * noble/linux: 6.8.0-142.142 -proposed tracker (LP: #2165997)
  * Packaging resync (LP: #1786013)
    - [Packaging] debian.master/dkms-versions -- update from kernel-versions
      (main/s2026.08.03)

  [ Ubuntu: 6.8.0-140.140 ]

  * noble/linux: 6.8.0-140.140 -proposed tracker (LP: #2165716)
  * CVE-2025-10263 // CVE-2026-53354
    - arm64: errata: Mitigate TLBI errata on various Arm CPUs
    - [Config] Enable CONFIG_ARM64_ERRATUM_4118414
  * CVE-2025-10263
    - arm64: cputype: Add C1-Ultra definitions
    - arm64: cputype: Add C1-Premium definitions
  * CVE-2026-53355
    - net: rds: clear i_sends on setup unwind
  * CVE-2026-53186
    - RDMA/srp: bound SRP_RSP sense copy by the received length
  * CVE-2026-53216
    - net: mvpp2: limit XDP frame size to the RX buffer
  * CVE-2026-63888
    - scsi: target: iscsi: Fix CRC overread and double-free in
      iscsit_handle_text_cmd()
  * CVE-2026-63886
    - scsi: target: iscsi: Validate CHAP_R length before base64 decode
  * CVE-2026-63887
    - scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
  * CVE-2026-63912
    - xfrm: esp: restore combined single-frag length gate
  * CVE-2026-63922
    - ipv6: exthdrs: refresh nh after handling HAO option
  * CVE-2026-63924
    - ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
  * CVE-2026-64091
    - batman-adv: tt: fix TOCTOU race for reported vlans
  * CVE-2026-63984
    - ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
  * CVE-2026-63992
    - tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
  * CVE-2026-63993
    - vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
  * CVE-2026-63994
    - tunnels: load network headers after skb_cow() in
      iptunnel_pmtud_build_icmp[v6]()
  * CVE-2026-64000
    - net: hsr: fix potential OOB access in supervision frame handling
  * CVE-2026-64007
    - netfilter: synproxy: refresh tcphdr after skb_ensure_writable
  * CVE-2026-53221
    - ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
  * CVE-2026-53131
    - netfilter: require Ethernet MAC header before using eth_hdr()

Date: 2026-09-10 23:19:11.035513+00:00
Changed-By: Austin Rhodes <austin.rhodes at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-ibm/6.8.0-1065.66
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list