[ubuntu/resolute-updates] u-boot 2025.10-0ubuntu2.1 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Tue Oct 6 17:03:43 UTC 2026


u-boot (2025.10-0ubuntu2.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Integer overflow in ZFS filesystem metadata parsing
    - debian/patches/CVE-2025-70290.patch: Prevent integer overflow in
      zfs_nvlist_lookup in fs/zfs/zfs.c.
    - CVE-2025-70290
  * SECURITY UPDATE: Integer overflow in ext4 block group descriptor sizing
    - debian/patches/CVE-2025-70293.patch: Prevent integer overflow in
      ext4fs_get_bgdtable in fs/ext4/ext4_write.c.
    - CVE-2025-70293
  * SECURITY UPDATE: Stale IP defragmentation state after datagram reassembly
    - debian/patches/CVE-2026-15390_1.patch: Clear IP defragmentation state
      after returning a complete packet in net/net.c.
    - debian/patches/CVE-2026-15390_2.patch: Add IP defragmentation
      duplicate-fragment regression test in test/dm/Makefile,
      test/dm/net_defrag.c.
    - CVE-2026-15390
  * SECURITY UPDATE: Out-of-bounds write in IP fragment reassembly
    - debian/patches/CVE-2026-71971_1.patch: Fix out-of-bounds write in IP
      fragment reassembly in net/net.c.
    - debian/patches/CVE-2026-71971_2.patch: Add regression test for IP
      reassembly overflow in test/dm/net_defrag.c.
    - CVE-2026-71971

Date: 2026-10-05 17:53:12.900679+00:00
Changed-By: Shafayat Hossain Majumder <shafayat.majumder at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/u-boot/2025.10-0ubuntu2.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list