[ubuntu/questing-security] linux-raspi 6.17.0-1021.21 (Accepted)

Andy Whitcroft apw at canonical.com
Mon Jul 6 20:13:42 UTC 2026


linux-raspi (6.17.0-1021.21) questing; urgency=medium

  * questing/linux-raspi: 6.17.0-1021.21 -proposed tracker (LP: #2157618)

  [ Ubuntu: 6.17.0-40.40 ]

  * questing/linux: 6.17.0-40.40 -proposed tracker (LP: #2157631)
  * CVE-2026-43037
    - ip6_tunnel: clear skb2->cb[] in ip4ip6_err()

linux-raspi (6.17.0-1020.20) questing; urgency=medium

  * questing/linux-raspi: 6.17.0-1020.20 -proposed tracker (LP: #2157133)

  * CONFIG_BPF_LSM not enabled in linux-raspi arm64 kernel (LP: #2150798)
    - [Config] raspi: Enable BPF_LSM

  [ Ubuntu: 6.17.0-39.39 ]

  * questing/linux: 6.17.0-39.39 -proposed tracker (LP: #2157145)
  * Packaging resync (LP: #1786013)
    - [Packaging] update annotations scripts
  * CVE-2026-45988
    - rxrpc: Fix re-decryption of RESPONSE packets
  * CVE-2026-46135
    - nvmet-tcp: fix race between ICReq handling and queue teardown
  * CVE-2026-46195
    - smb: client: validate dacloffset before building DACL pointers
  * CVE-2026-31402
    - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
  * CVE-2026-43378
    - smb: server: fix use-after-free in smb2_open()
  * CVE-2026-31657
    - batman-adv: hold claim backbone gateways by reference
  * CVE-2026-46266
    - inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
  * CVE-2026-46289
    - lib/scatterlist: fix length calculations in extract_kvec_to_sg
  * CVE-2026-31436
    - dmaengine: idxd: fix possible wrong descriptor completion in
      llist_abort_desc()
  * CVE-2026-31649
    - net: stmmac: fix integer underflow in chain mode
  * CVE-2026-31659
    - batman-adv: reject oversized global TT response buffers
  * CVE-2026-31448
    - ext4: avoid infinite loops caused by residual data
  * CVE-2026-43071
    - dcache: Limit the minimal number of bucket to two
  * CVE-2026-31478
    - ksmbd: replace hardcoded hdr2_len with offsetof() in
      smb2_calc_max_out_buf_len()
  * CVE-2026-31682
    - bridge: br_nd_send: linearize skb before parsing ND options
  * CVE-2026-43117
    - btrfs: tracepoints: get correct superblock from dentry in event
      btrfs_sync_file()
  * CVE-2026-31669
    - mptcp: fix slab-use-after-free in __inet_lookup_established
  * CVE-2026-46115
    - block: add pgmap check to biovec_phys_mergeable
  * CVE-2026-45898
    - RDMA/iwcm: Fix workqueue list corruption by removing work_list
  * CVE-2026-46244
    - netfilter: nft_inner: Fix IPv6 inner_thoff desync
  * CVE-2026-43493
    - crypto: pcrypt - Fix handling of MAY_BACKLOG requests
  * CVE-2026-43186
    - ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data()
  * CVE-2026-31685
    - netfilter: ip6t_eui64: reject invalid MAC header for all packets
  * CVE-2026-43114
    - netfilter: nft_set_pipapo_avx2: don't return non-matching entry on
      expiry
  * CVE-2026-46325
    - RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE
  * CVE-2026-31668
    - seg6: separate dst_cache for input and output paths in seg6 lwtunnel
  * CVE-2026-43197
    - netconsole: avoid OOB reads, msg is not nul-terminated
  * CVE-2026-43083
    - net: ioam6: fix OOB and missing lock
  * CVE-2026-46043
    - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
  * CVE-2026-23428
    - ksmbd: fix use-after-free of share_conf in compound request
  * CVE-2026-23450
    - net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
  * CVE-2026-46185
    - smb/client: fix out-of-bounds read in symlink_data()
  * CVE-2026-23455
    - netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
  * CVE-2026-46119
    - libceph: Fix slab-out-of-bounds access in auth message processing
  * CVE-2026-46039
    - rxgk: Fix potential integer overflow in length check
  * CVE-2026-23427
    - ksmbd: fix use-after-free in durable v2 replay of active file handles
  * CVE-2026-31718
    - ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger
  * CVE-2026-31637
    - rxrpc: reject undecryptable rxkad response tickets
  * CVE-2026-43011
    - net/x25: Fix potential double free of skb
  * CVE-2026-43038
    - ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
  * CVE-2026-31635
    - rxrpc: fix oversized RESPONSE authenticator length check
  * CVE-2026-43501
    - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
  * CVE-2026-43125
    - dlm: validate length in dlm_search_rsb_tree
  * CVE-2026-46316
    - KVM: arm64: vgic-its: Drop the translation cache reference only for the
      erased entry
  * CVE-2026-43185
    - ksmbd: fix signededness bug in smb_direct_prepare_negotiation()
  * CVE-2026-43341
    - net/ipv6: ioam6: prevent schema length wraparound in trace fill
  * CVE-2026-31607
    - usbip: validate number_of_packets in usbip_pack_ret_submit()
  * CVE-2026-43402
    - kthread: consolidate kthread exit paths to prevent use-after-free
  * CVE-2026-43384
    - net/tcp-ao: Fix MAC comparison to be constant-time
  * CVE-2026-43383
    - net/tcp-md5: Fix MAC comparison to be constant-time
  * CVE-2026-43376
    - ksmbd: fix use-after-free by using call_rcu() for oplock_info
  * CVE-2026-46243
    - smb: client: reject userspace cifs.spnego descriptions
  * CVE-2026-43414
    - scsi: qla2xxx: Completely fix fcport double free
  * CVE-2026-43407
    - libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()
  * CVE-2026-43406
    - libceph: prevent potential out-of-bounds reads in
      process_message_header()
  * CVE-2026-43304
    - libceph: define and enforce CEPH_MAX_KEY_LEN
  * CVE-2026-22984
    - libceph: prevent potential out-of-bounds reads in handle_auth_done()

linux-raspi (6.17.0-1019.19) questing; urgency=medium

  * questing/linux-raspi: 6.17.0-1019.19 -proposed tracker (LP: #2151883)

  [ Ubuntu: 6.17.0-38.38 ]

  * questing/linux: 6.17.0-38.38 -proposed tracker (LP: #2154532)
  * Generic questing kernel oops on bootup with newer Nvidia machines
    (LP: #2154481)
    - nouveau: don't attempt fwsec on sb on newer platforms.
  * Kernel regression (6.8.0-117.generic) (LP: #2153556)
    - bonding: do not set usable_slaves for broadcast mode
  * powerpc-build in ubuntu_kernel_selftests fails to build due to
    uninitialized value (LP: #2129844)
    - selftests/powerpc: Suppress -Wmaybe-uninitialized with GCC 15
  * iptables connlimit traffic loss (LP: #2149872)
    - netfilter: nf_conncount: fix tracking of connections from localhost
  * On Dell system, the internal OLED display drops to a visibly low FPS after
    suspend/resume (LP: #2144712)
    - drm/i915/psr: Disable Panel Replay on Dell XPS 14 DA14260 as a quirk
    - drm/i915/psr: Fixes for Dell XPS DA14260 quirk
  * CVE-2026-23272
    - netfilter: nf_tables: unconditionally bump set->nelems before insertion
  * CVE-2026-31418
    - netfilter: ipset: drop logically empty buckets in mtype_del
  * CVE-2026-23392
    - netfilter: nf_tables: release flowtable after rcu grace period on error
  * CVE-2026-23278
    - netfilter: nf_tables: always walk all pending catchall elements
  * GRO managed-frag use-after-free leading to local privilege escalation
    (LP: #2154172)
    - net: gro: don't merge zcopy skbs
  * AppArmor Vulnerabilities  (LP: #2151747)
    - SAUCE: apparmor: pass big_resp to handler
    - SAUCE: apparmor: remove redundant kref_init for listener->count
    - SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb
  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47337
    - SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr
  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47334
    - SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock
  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47333
    - SAUCE: apparmor: fix dfa unpacking size of the notification filter
  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47332
    - SAUCE: apparmor: fix size check against type instead of pointer
  * apparmor: LLVM/clang build failure due to uninitialized variable in
    notify.c (LP: #2148809) // CVE-2026-47330
    - SAUCE: apparmor: initialize variable used in uninitialized context
  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47329
    - SAUCE: apparmor: fix name validation bypass on notification
  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47327 //
    CVE-2026-47328
    - SAUCE: apparmor: fix glob memory leak after kstrdup
  * AppArmor Vulnerabilities  (LP: #2151747) // CVE-2026-47326
    - SAUCE: apparmor: fix inverted NULL check after aa_get_buffer
  * CVE-2026-46300
    - net: skbuff: preserve shared-frag marker during coalescing
    - net: skbuff: propagate shared-frag marker through frag-transfer helpers
  * net/rds: reset op_nents when zerocopy page pin fails (LP: #2153962)
    - net/rds: reset op_nents when zerocopy page pin fails
  * CVE-2026-46333
    - ptrace: slightly saner 'get_dumpable()' logic
  * CVE-2026-43500
    - rxrpc: Fix conn-level packet handling to unshare RESPONSE packets
    - rxrpc: Fix potential UAF after skb_unshare() failure
    - rxrpc: Fix rxrpc_input_call_event() to only unshare DATA packets
    - rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
  * CVE-2026-31676 // CVE-2026-43500
    - rxrpc: only handle RESPONSE during service challenge
  * CVE-2026-43284
    - xfrm: esp: avoid in-place decrypt on shared skb frags
  * CVE-2026-31419
    - net: bonding: fix use-after-free in bond_xmit_broadcast()
  * CVE-2026-31431
    - crypto: algif_aead - Revert to operating out-of-place
    - crypto: algif_aead - snapshot IV for async AEAD requests
    - crypto: authencesn - Do not place hiseq at end of dst for out-of-place
      decryption
    - crypto: authencesn - Fix src offset when decrypting in-place
    - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
    - crypto: algif_aead - Fix minimum RX size check for decryption
  * CVE-2026-31533
    - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
  * CVE-2026-31504
    - net: fix fanout UAF in packet_release() via NETDEV_UP race

Date: 2026-06-19 16:29:16.045115+00:00
Changed-By: Alessio Faina <alessio.faina at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-raspi/6.17.0-1021.21
-------------- next part --------------
Sorry, changesfile not available.


More information about the Questing-changes mailing list