[ubuntu/resolute-proposed] linux-nvidia 7.0.0-1020.20 (Accepted)

Timo Aaltonen tjaalton at ubuntu.com
Tue Sep 22 22:10:49 UTC 2026


linux-nvidia (7.0.0-1020.20) resolute; urgency=medium

  * resolute/linux-nvidia: 7.0.0-1020.20 -proposed tracker (LP: #2167007)

  * drm/ast: DisplayPort edid supports 256 bytes (LP: #2166545)
    - drm/ast: DisplayPort edid supports 256 bytes

  * tee: optee: support shared memory offsets on large-page kernels
    (LP: #2166792)
    - NVIDIA: VR: SAUCE: tee: optee: support shared memory offsets on large-
      page kernels

  * arm_ffa: Failing to load after kexec (LP: #2166208)
    - Revert "firmware: arm_ffa: Change initcall level of ffa_init() to
      rootfs_initcall"
    - firmware: arm_ffa: Register core as a platform driver
    - firmware: arm_ffa: Set the core device as FF-A device parent
    - firmware: arm_ffa: Defer probe until pKVM is initialized
    - security: lsm: allow LSMs to register for late_initcall_sync init
    - security: ima: introduce IMA_INIT_LATE_SYNC option
    - security: ima: rename boot_aggregate when ima is initialised at
      late_sync
    - tpm: tpm_crb_ffa: revert defered_probed when tpm_crb_ffa is built-in
    - firmware: arm_ffa: Tear down driver during shutdown
    - [Config] Enable IMA_INIT_LATE_SYNC

  * Backport watchdog: sbsa_gwdt: add early_enable module parameter
    (LP: #2166165)
    - watchdog: sbsa_gwdt: add early_enable module parameter

  * Backport: "block: check bio split for unaligned bvec" (LP: #2165055)
    - block: check bio split for unaligned bvec

  * linux-nvidia-7.0:  ACPI enablement for the MT8901 I2C controller and its
    HID keyboard interrupt on Spark (LP: #2163407)
    - NVIDIA: SAUCE: i2c: mediatek: Add ACPI/MT8901 support and firmware-
      managed clocks
    - NVIDIA: SAUCE: gpiolib: acpi: route acpi_dev_gpio_irq_wake_get_by()
      debounce through the warn-only wrapper

  [ Ubuntu: 7.0.0-34.34 ]

  * resolute/linux: 7.0.0-34.34 -proposed tracker (LP: #2165995)

  [ Ubuntu: 7.0.0-32.32 ]

  * resolute/linux: 7.0.0-32.32 -proposed tracker (LP: #2165777)
  * CVE-2026-72064
    - net: mana: Sync page pool RX frags for CPU
  * CVE-2026-72065
    - net: mana: Validate the packet length reported by the NIC
  * CVE-2026-72098
    - dm-verity-fec: replace {MAX,MIN}_RSN with {MIN,MAX}_ROOTS
    - dm-verity: fix buffer overflow in FEC calculation
  * CVE-2026-72248
    - netfilter: flowtable: support IPIP tunnel with direct xmit
    - netfilter: flowtable: use correct direction to set up tunnel route
  * CVE-2026-72249
    - netfilter: flowtable: use dst in this direction when pushing IPIP header
  * CVE-2026-72287
    - KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal"
      checks
  * CVE-2026-72329
    - net/liquidio: drop cached VF pci_dev LUT
  * CVE-2026-72355
    - netfs: Fix barriering when walking subrequest list
  * CVE-2026-72412
    - s390/mm: Fix handling of _PAGE_UNUSED pte bit
  * CVE-2026-72417
    - netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()
  * CVE-2026-72442
    - netfilter: flowtable: fix and simplify IP6IP6 tunnel handling
  * CVE-2026-72463
    - xfrm: Fix dev use-after-free in xfrm async resumption
  * CVE-2026-72477
    - fs/ntfs3: call _ntfs_bad_inode() when failing to rename
  * CVE-2026-72493
    - net: serialize netif_running() check in enqueue_to_backlog()
  * CVE-2026-72494
    - RDMA/irdma: Replace waitqueue and flag with completion
  * CVE-2026-72496
    - RDMA/bnxt_re: Proper rollback if the ioremap fails
  * CVE-2026-74269
    - bnxt: fix head underflow on XDP head-grow
  * CVE-2026-74350
    - ocfs2: validate fast symlink target during inode read
  * CVE-2026-72495
    - RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
  * CVE-2026-72501
    - RDMA/bnxt_re: Initialize dpi variable to zero
  * CVE-2026-72278
    - KVM: arm64: nv: Re-translate VNCR before injecting abort
  * CVE-2026-68083
    - ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
  * CVE-2026-68457
    - ksmbd: use opener credentials for FSCTL mutations
  * CVE-2026-68476
    - ipvs: reload ip header after head reallocation
  * CVE-2026-68477
    - ipvs: fix more places with wrong ipv6 transport offsets
  * CVE-2026-72014
    - drbd: reject data replies with an out-of-range payload size
  * CVE-2026-72020
    - ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
  * CVE-2026-72033
    - orangefs: keep the readdir entry size 64-bit in fill_from_part()
  * CVE-2026-72041
    - espintcp: use sk_msg_free_partial to fix partial send
  * CVE-2026-72046
    - gve: fix header buffer corruption with header-split and HW-GRO
  * CVE-2026-72069
    - locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
  * CVE-2026-72083
    - scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
  * CVE-2026-72084
    - scsi: target: Bound PR-OUT TransportID parsing to the received buffer
  * CVE-2026-72085
    - scsi: xen: scsiback: Free unsubmitted command instead of double-putting
      it
  * CVE-2026-72129
    - nvmet-rdma: handle inline data with a nonzero offset
  * CVE-2026-72130
    - nvmet-auth: reject short AUTH_RECEIVE buffers
  * CVE-2026-64551
    - sctp: validate STALE_COOKIE cause length before reading staleness
  * CVE-2026-72137
    - xfrm: nat_keepalive: avoid double free on send error
  * CVE-2026-72139
    - tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
  * CVE-2026-72191
    - ntfs3: validate split-point offset in indx_insert_into_buffer
  * CVE-2026-72192
    - ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
  * CVE-2026-72194
    - fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
  * CVE-2026-72217
    - SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
  * CVE-2026-72220
    - sunrpc: harden rq_procinfo lifecycle to prevent double-free
  * CVE-2026-72221
    - sunrpc: wait for in-flight TLS handshake callback when cancel loses race
  * CVE-2026-72222
    - sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
  * CVE-2026-72226
    - batman-adv: tt: prevent TVLV OOB check overflow
  * CVE-2026-72234
    - batman-adv: access unicast_ttvn skb->data only after skb realloc
  * CVE-2026-72251
    - netfilter: nf_nat_sip: reload possible stale data pointer
  * CVE-2026-72277
    - KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
    - KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
  * CVE-2026-72279
    - KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
  * CVE-2026-72288
    - KVM: arm64: vgic: Handle race between interrupt affinity change and LPI
      disabling
  * CVE-2026-72289
    - KVM: arm64: vgic: Check the interrupt is still ours before migrating it
  * CVE-2026-72296
    - net: ife: require ETH_HLEN to be pullable in ife_decode()
  * CVE-2026-72299
    - tipc: restrict socket queue dumps in enqueue tracepoints
  * CVE-2026-72317
    - SUNRPC: pin upper rpc_clnt across the TLS connect_worker
  * CVE-2026-72318
    - cifs: validate DFS referral string offsets
  * CVE-2026-72319
    - ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
    - ipvs: ensure inner headers in ICMP errors are in headroom
  * CVE-2026-72320
    - netfilter: nft_lookup: fix catchall element handling with inverted
      lookups
  * CVE-2026-72322
    - ipv6: mcast: Fix potential UAF in MLD delayed work
  * CVE-2026-72323
    - ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
  * CVE-2026-64541
    - net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
  * CVE-2026-72339
    - qede: fix off-by-one in BD ring consumption on build_skb failure
  * CVE-2026-72348
    - netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
  * CVE-2026-72351
    - gue: validate REMCSUM private option length
  * CVE-2026-72366
    - netfs: Fix netfs_create_write_req() to handle async cache object
      creation
  * CVE-2026-72381
    - ksmbd: fix use-after-free of fp->owner.name in durable handle owner
      check
  * CVE-2026-72393
    - eth: fbnic: don't cache shinfo across skb realloc
  * CVE-2026-72398
    - sctp: add INIT verification after cookie unpacking
  * CVE-2026-72399
    - net: enetc: check the number of BDs needed for xdp_frame
  * CVE-2026-64530
    - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
  * CVE-2026-72422
    - ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2
      NEGOTIATE
  * CVE-2026-72429
    - ipv6: ioam: fix type confusion of dst_entry
  * CVE-2026-72436
    - netfilter: ipset: Fix data race between add and dump in all hash types
    - netfilter: ipset: annotate "pos" for concurrent readers/writers
    - netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash
      types
  * CVE-2026-72451
    - xfrm: Fix xfrm state cache insertion race
  * CVE-2026-72466
    - xprtrdma: Fix bcall rep leak and unbounded peek
  * CVE-2026-72472
    - nfs: use nfsi->rwsem to protect traversal of the file lock list
  * CVE-2026-72473
    - xprtrdma: Avoid 250 ms delay on backlog wakeup
    - xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot
    - xprtrdma: Post receive buffers after RPC completion
    - xprtrdma: Use sendctx DMA state for Send signaling
    - xprtrdma: Decouple req recycling from RPC completion
  * CVE-2026-72491
    - net/9p: fix race condition on rdma->state in trans_rdma.c
  * CVE-2026-72495 // CVE-2026-72501
    - RDMA/bnxt_re: Move the UAPI methods to a dedicated file
  * CVE-2026-74255
    - tipc: fix UAF in tipc_l2_send_msg()
  * CVE-2026-74267
    - net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek
      before restoring qlen
  * CVE-2026-74268
    - tcp: clear sock_ops cb flags before force-closing a child socket
  * CVE-2026-74287
    - sctp: validate embedded address parameter length
  * CVE-2026-74310
    - vhost/net: complete zerocopy ubufs only once
  * CVE-2026-74345
    - RDMA/siw: Fix endpoint/socket association handling
  * CVE-2026-74361
    - nvme: fix FDP fdpcidx bounds check
  * CVE-2026-74376
    - md/raid10: reset read_slot when reusing r10bio for discard
  * CVE-2026-74384
    - nvme-multipath: fix flex array size in struct nvme_ns_head
  * CVE-2026-74394
    - RDMA/srpt: fix integer overflow in immediate data length check
  * CVE-2026-74398
    - ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
  * CVE-2026-74401
    - dlm: fix add msg handle in send_queue ordered
  * CVE-2026-74406
    - vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
  * CVE-2026-74427
    - afs: Fix netns teardown to cancel the preallocation charger
    - afs: Fix further netns teardown to cancel the preallocation charger
  * CVE-2026-74428
    - rxrpc: Fix double unlock in rxrpc_recvmsg()
  * CVE-2026-74433
    - rxrpc: Fix UAF in rxgk_issue_challenge()
  * CVE-2026-74434
    - rxrpc: Don't move a peeked OOB message onto the pending queue
  * CVE-2026-74436
    - rxrpc: serialize kernel accept preallocation with socket teardown
  * CVE-2026-64535
    - nvmet-tcp: Fix potential UAF when ddgst mismatch
  * CVE-2026-74439
    - iommu/vt-d: Clear Present bit before tearing down scalable-mode context
      entry
  * CVE-2026-64534
    - nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error
      path

linux-nvidia (7.0.0-1019.19) resolute; urgency=medium

  * resolute/linux-nvidia: 7.0.0-1019.19 -proposed tracker (LP: #2166493)

  * Packaging resync (LP: #1786013)
    - [Packaging] debian.nvidia/dkms-versions -- remove dkms-versions
      (main/d2026.09.04)

  * Perf binary for linux-nvidia kernel not including event aliases
    (LP: #2162778)
    - [Packaging] Reintroduce flavor specific perf

  * Miscellaneous Ubuntu changes
    - [Packaging] remove stale debian/dkms-versions scripting

Date: 2026-09-11 20:28:11.356754+00:00
Changed-By: Jacob Martin <jacob.martin at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-nvidia/7.0.0-1020.20
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list