[ubuntu/resolute-security] linux-raspi 7.0.0-1020.20 (Accepted)

Andy Whitcroft apw at canonical.com
Wed Sep 23 15:02:53 UTC 2026


linux-raspi (7.0.0-1020.20) resolute; urgency=medium

  * resolute/linux-raspi: 7.0.0-1020.20 -proposed tracker (LP: #2165766)

  [ Ubuntu: 7.0.0-34.34 ]

  * resolute/linux: 7.0.0-34.34 -proposed tracker (LP: #2165995)

  [ Ubuntu: 7.0.0-32.32 ]

  * resolute/linux: 7.0.0-32.32 -proposed tracker (LP: #2165777)
  * CVE-2026-72064
    - net: mana: Sync page pool RX frags for CPU
  * CVE-2026-72065
    - net: mana: Validate the packet length reported by the NIC
  * CVE-2026-72098
    - dm-verity-fec: replace {MAX,MIN}_RSN with {MIN,MAX}_ROOTS
    - dm-verity: fix buffer overflow in FEC calculation
  * CVE-2026-72248
    - netfilter: flowtable: support IPIP tunnel with direct xmit
    - netfilter: flowtable: use correct direction to set up tunnel route
  * CVE-2026-72249
    - netfilter: flowtable: use dst in this direction when pushing IPIP header
  * CVE-2026-72287
    - KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal"
      checks
  * CVE-2026-72329
    - net/liquidio: drop cached VF pci_dev LUT
  * CVE-2026-72355
    - netfs: Fix barriering when walking subrequest list
  * CVE-2026-72412
    - s390/mm: Fix handling of _PAGE_UNUSED pte bit
  * CVE-2026-72417
    - netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()
  * CVE-2026-72442
    - netfilter: flowtable: fix and simplify IP6IP6 tunnel handling
  * CVE-2026-72463
    - xfrm: Fix dev use-after-free in xfrm async resumption
  * CVE-2026-72477
    - fs/ntfs3: call _ntfs_bad_inode() when failing to rename
  * CVE-2026-72493
    - net: serialize netif_running() check in enqueue_to_backlog()
  * CVE-2026-72494
    - RDMA/irdma: Replace waitqueue and flag with completion
  * CVE-2026-72496
    - RDMA/bnxt_re: Proper rollback if the ioremap fails
  * CVE-2026-74269
    - bnxt: fix head underflow on XDP head-grow
  * CVE-2026-74350
    - ocfs2: validate fast symlink target during inode read
  * CVE-2026-72495
    - RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
  * CVE-2026-72501
    - RDMA/bnxt_re: Initialize dpi variable to zero
  * CVE-2026-72278
    - KVM: arm64: nv: Re-translate VNCR before injecting abort
  * CVE-2026-68083
    - ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
  * CVE-2026-68457
    - ksmbd: use opener credentials for FSCTL mutations
  * CVE-2026-68476
    - ipvs: reload ip header after head reallocation
  * CVE-2026-68477
    - ipvs: fix more places with wrong ipv6 transport offsets
  * CVE-2026-72014
    - drbd: reject data replies with an out-of-range payload size
  * CVE-2026-72020
    - ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
  * CVE-2026-72033
    - orangefs: keep the readdir entry size 64-bit in fill_from_part()
  * CVE-2026-72041
    - espintcp: use sk_msg_free_partial to fix partial send
  * CVE-2026-72046
    - gve: fix header buffer corruption with header-split and HW-GRO
  * CVE-2026-72069
    - locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
  * CVE-2026-72083
    - scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
  * CVE-2026-72084
    - scsi: target: Bound PR-OUT TransportID parsing to the received buffer
  * CVE-2026-72085
    - scsi: xen: scsiback: Free unsubmitted command instead of double-putting
      it
  * CVE-2026-72129
    - nvmet-rdma: handle inline data with a nonzero offset
  * CVE-2026-72130
    - nvmet-auth: reject short AUTH_RECEIVE buffers
  * CVE-2026-64551
    - sctp: validate STALE_COOKIE cause length before reading staleness
  * CVE-2026-72137
    - xfrm: nat_keepalive: avoid double free on send error
  * CVE-2026-72139
    - tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
  * CVE-2026-72191
    - ntfs3: validate split-point offset in indx_insert_into_buffer
  * CVE-2026-72192
    - ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
  * CVE-2026-72194
    - fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
  * CVE-2026-72217
    - SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
  * CVE-2026-72220
    - sunrpc: harden rq_procinfo lifecycle to prevent double-free
  * CVE-2026-72221
    - sunrpc: wait for in-flight TLS handshake callback when cancel loses race
  * CVE-2026-72222
    - sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
  * CVE-2026-72226
    - batman-adv: tt: prevent TVLV OOB check overflow
  * CVE-2026-72234
    - batman-adv: access unicast_ttvn skb->data only after skb realloc
  * CVE-2026-72251
    - netfilter: nf_nat_sip: reload possible stale data pointer
  * CVE-2026-72277
    - KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
    - KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
  * CVE-2026-72279
    - KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
  * CVE-2026-72288
    - KVM: arm64: vgic: Handle race between interrupt affinity change and LPI
      disabling
  * CVE-2026-72289
    - KVM: arm64: vgic: Check the interrupt is still ours before migrating it
  * CVE-2026-72296
    - net: ife: require ETH_HLEN to be pullable in ife_decode()
  * CVE-2026-72299
    - tipc: restrict socket queue dumps in enqueue tracepoints
  * CVE-2026-72317
    - SUNRPC: pin upper rpc_clnt across the TLS connect_worker
  * CVE-2026-72318
    - cifs: validate DFS referral string offsets
  * CVE-2026-72319
    - ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
    - ipvs: ensure inner headers in ICMP errors are in headroom
  * CVE-2026-72320
    - netfilter: nft_lookup: fix catchall element handling with inverted
      lookups
  * CVE-2026-72322
    - ipv6: mcast: Fix potential UAF in MLD delayed work
  * CVE-2026-72323
    - ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
  * CVE-2026-64541
    - net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
  * CVE-2026-72339
    - qede: fix off-by-one in BD ring consumption on build_skb failure
  * CVE-2026-72348
    - netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
  * CVE-2026-72351
    - gue: validate REMCSUM private option length
  * CVE-2026-72366
    - netfs: Fix netfs_create_write_req() to handle async cache object
      creation
  * CVE-2026-72381
    - ksmbd: fix use-after-free of fp->owner.name in durable handle owner
      check
  * CVE-2026-72393
    - eth: fbnic: don't cache shinfo across skb realloc
  * CVE-2026-72398
    - sctp: add INIT verification after cookie unpacking
  * CVE-2026-72399
    - net: enetc: check the number of BDs needed for xdp_frame
  * CVE-2026-64530
    - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
  * CVE-2026-72422
    - ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2
      NEGOTIATE
  * CVE-2026-72429
    - ipv6: ioam: fix type confusion of dst_entry
  * CVE-2026-72436
    - netfilter: ipset: Fix data race between add and dump in all hash types
    - netfilter: ipset: annotate "pos" for concurrent readers/writers
    - netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash
      types
  * CVE-2026-72451
    - xfrm: Fix xfrm state cache insertion race
  * CVE-2026-72466
    - xprtrdma: Fix bcall rep leak and unbounded peek
  * CVE-2026-72472
    - nfs: use nfsi->rwsem to protect traversal of the file lock list
  * CVE-2026-72473
    - xprtrdma: Avoid 250 ms delay on backlog wakeup
    - xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot
    - xprtrdma: Post receive buffers after RPC completion
    - xprtrdma: Use sendctx DMA state for Send signaling
    - xprtrdma: Decouple req recycling from RPC completion
  * CVE-2026-72491
    - net/9p: fix race condition on rdma->state in trans_rdma.c
  * CVE-2026-72495 // CVE-2026-72501
    - RDMA/bnxt_re: Move the UAPI methods to a dedicated file
  * CVE-2026-74255
    - tipc: fix UAF in tipc_l2_send_msg()
  * CVE-2026-74267
    - net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek
      before restoring qlen
  * CVE-2026-74268
    - tcp: clear sock_ops cb flags before force-closing a child socket
  * CVE-2026-74287
    - sctp: validate embedded address parameter length
  * CVE-2026-74310
    - vhost/net: complete zerocopy ubufs only once
  * CVE-2026-74345
    - RDMA/siw: Fix endpoint/socket association handling
  * CVE-2026-74361
    - nvme: fix FDP fdpcidx bounds check
  * CVE-2026-74376
    - md/raid10: reset read_slot when reusing r10bio for discard
  * CVE-2026-74384
    - nvme-multipath: fix flex array size in struct nvme_ns_head
  * CVE-2026-74394
    - RDMA/srpt: fix integer overflow in immediate data length check
  * CVE-2026-74398
    - ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
  * CVE-2026-74401
    - dlm: fix add msg handle in send_queue ordered
  * CVE-2026-74406
    - vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
  * CVE-2026-74427
    - afs: Fix netns teardown to cancel the preallocation charger
    - afs: Fix further netns teardown to cancel the preallocation charger
  * CVE-2026-74428
    - rxrpc: Fix double unlock in rxrpc_recvmsg()
  * CVE-2026-74433
    - rxrpc: Fix UAF in rxgk_issue_challenge()
  * CVE-2026-74434
    - rxrpc: Don't move a peeked OOB message onto the pending queue
  * CVE-2026-74436
    - rxrpc: serialize kernel accept preallocation with socket teardown
  * CVE-2026-64535
    - nvmet-tcp: Fix potential UAF when ddgst mismatch
  * CVE-2026-74439
    - iommu/vt-d: Clear Present bit before tearing down scalable-mode context
      entry
  * CVE-2026-64534
    - nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error
      path

Date: 2026-09-11 14:47:11.775341+00:00
Changed-By: Juerg Haefliger <juerg.haefliger at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-raspi/7.0.0-1020.20
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list