UbuntuUpdates.org

Package "linux-azure-nvidia"

This package belongs to a PPA: Canonical Kernel Team

Name: linux-azure-nvidia

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Linux kernel version specific cloud tools for version 6.8.0
  • Header files related to Linux kernel version 6.8.0
  • Header files related to Linux kernel version 6.8.0
  • Header files related to Linux kernel version 6.8.0

Latest version: 6.8.0-1028.31
Release: noble (24.04)
Level: base
Repository: main

Links



Other versions of "linux-azure-nvidia" in Noble

Repository Area Version
security main 6.8.0-1025.27
updates main 6.8.0-1027.30
proposed universe 6.8.0-1012.13
proposed main 6.8.0-1028.31

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 6.8.0-1028.31 2025-10-25 00:08:25 UTC

 linux-azure-nvidia (6.8.0-1028.31) noble; urgency=medium
 .
   * noble/linux-azure-nvidia: 6.8.0-1028.31 -proposed tracker (LP: #2127580)
 .
   * Add pvpanic kernel modules to linux-modules (LP: #2126659)
     - [Packaging] azure-nvidia: Add pvpanic kernel modules to linux-modules
 .
   [ Ubuntu-azure: 6.8.0-1043.49 ]
 .
   * noble/linux-azure: 6.8.0-1043.49 -proposed tracker (LP: #2127583)
   * Add pvpanic kernel modules to linux-modules (LP: #2126659)
     - [Packaging] azure: Add pvpanic kernel modules to linux-modules
   * [STORVSC] [Backport] Backport for Linux storage driver patch for fixing
     performance issues (LP: #2128842)
     - scsi: storvsc: Prefer returning channel with the same CPU as on the I/O
       issuing CPU
   * [MANA][Backport] net: mana: Reduce waiting time if HWC not responding
     (LP: #2128833)
     - net: mana: Reduce waiting time if HWC not responding
   * Mana-IB Patches - Part 2 (LP: #2128662)
     - RDMA/mana_ib: add support of multiple ports
     - RDMA/mana_ib: Fix DSCP value in modify QP
     - RDMA/mana_ib: Access remote atomic for MRs
     - RDMA/mana_ib: support of the zero based MRs
     - RDMA/mana_ib: Fix integer overflow during queue creation
     - RDMA/mana_ib: Use safer allocation function()
   * Mana-IB Patches - Part 1 (LP: #2127201)
     - RDMA/mana_ib: Extend modify QP
     - RDMA/mana_ib: Drain send wrs of GSI QP
     - RDMA/mana_ib: add additional port counters
   [ Ubuntu: 6.8.0-88.89 ]
   * noble/linux: 6.8.0-88.89 -proposed tracker (LP: #2127619)
   * Enable Xilinx PS UART configs (LP: #2121337)
     - [Config] Enable Xilinx PS UART configs
   * Fix ARL-U/H suspend issues (LP: #2112469)
     - platform/x86/intel/pmc: Add Arrow Lake U/H support to intel_pmc_core
       driver
     - platform/x86/intel/pmc: Fix Arrow Lake U/H NPU PCI ID
   * r8169 can not wake on LAN via SFP moudule (LP: #2123901)
     - r8169: set EEE speed down ratio to 1
   * Add pvpanic kernel modules to linux-modules (LP: #2126659)
     - [Packaging] Add pvpanic kernel modules to linux-modules
   * CVE-2025-21729
     - wifi: rtw89: fix race between cancel_hw_scan and hw_scan completion
   * Fix failure to build TDX module (LP: #2126698)
     - x86/paravirt: Move halt paravirt calls under CONFIG_PARAVIRT
   * Ubuntu 24.04.2: error in audit_log_object_context keep printing in the
     kernel and console (LP: #2123815)
     - SAUCE: fix: apparmor4.0.0 [26/90]: LSM stacking v39: Audit: Add record
       for multiple object contexts
   * ensure mptcp keepalives are honored when set (LP: #2125444)
     - mptcp: sockopt: make sync_socket_options propagate SOCK_KEEPOPEN
   * System hangs when running the memory stress test (LP: #2103680)
     - mm: page_alloc: avoid kswapd thrashing due to NUMA restrictions
   * UBUNTU: fan: fail to check kmalloc() return could cause a NULL pointer
     dereference (LP: #2125053)
     - SAUCE: fan: vxlan: check memory allocation for map
   * jammy:linux-riscv-6.8 is FTBFS because of wrong include (LP: #2122592)
     - SAUCE: riscv: KVM: Remove broken include
   * Performance degrades rapidly when spawning more processes to run benchmark
     (LP: #2122006)
     - cpuidle: menu: Avoid discarding useful information
     - cpuidle: governors: menu: Avoid using invalid recent intervals data
   * CVE-2025-38227
     - media: vidtv: Terminating the subsequent process of initialization
       failure
   * CVE-2025-38678
     - netfilter: nf_tables: reject duplicate device on updates
   * CVE-2025-38616
     - tls: handle data disappearing from under the TLS ULP
   * CVE-2025-37838
     - HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol
       Driver Due to Race Condition
   * VMSCAPE CVE-2025-40300 (LP: #2124105) // CVE-2025-40300
     - Documentation/hw-vuln: Add VMSCAPE documentation
     - x86/vmscape: Enumerate VMSCAPE bug
     - x86/vmscape: Add conditional IBPB mitigation
     - x86/vmscape: Enable the mitigation
     - x86/bugs: Move cpu_bugs_smt_update() down
     - x86/vmscape: Warn when STIBP is disabled with SMT
     - x86/vmscape: Add old Intel CPUs to affected list
   * VMSCAPE CVE-2025-40300 (LP: #2124105)
     - [Config] Enable MITIGATION_VMSCAPE config
   * CVE-2025-38352
     - posix-cpu-timers: fix race between handle_posix_cpu_timers() and
       posix_cpu_timer_del()
   * CVE-2025-38118
     - Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete
     - Bluetooth: MGMT: Fix sparse errors

Source diff to previous version
2126659 Add pvpanic kernel modules to linux-modules
2128842 [STORVSC] [Backport] Backport for Linux storage driver patch for fixing performance issues
2128833 [MANA][Backport] net: mana: Reduce waiting time if HWC not responding
2128662 Mana-IB Patches - Part 2
2121337 Enable Xilinx PS UART configs
2112469 Fix ARL-U/H suspend issues
2123901 r8169 can not wake on LAN via SFP moudule
2126698 Fix failure to build TDX module
2123815 Ubuntu 24.04.2: error in audit_log_object_context keep printing in the kernel and console
2125444 ensure mptcp keepalives are honored when set
2103680 System hangs when running the memory stress test
2125053 UBUNTU: fan: fail to check kmalloc() return could cause a NULL pointer dereference
2122592 jammy:linux-riscv-6.8 is FTBFS because of wrong include
2122006 Performance degrades rapidly when spawning more processes to run benchmark
2124105 VMSCAPE CVE-2025-40300
CVE-2025-21729 In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix race between cancel_hw_scan and hw_scan completion The rtwdev-
CVE-2025-38227 In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the subsequent process of initialization failure syzb
CVE-2025-38678 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject duplicate device on updates A chain/flowtable upda
CVE-2025-38616 In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS ULP TLS expects that it owns t
CVE-2025-37838 In the Linux kernel, the following vulnerability has been resolved: HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due t
CVE-2025-40300 In the Linux kernel, the following vulnerability has been resolved: x86/vmscape: Add conditional IBPB mitigation VMSCAPE is a vulnerability that ex
CVE-2025-38352 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer
CVE-2025-38118 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete This reworks MGMT_

Version: 6.8.0-1026.29 2025-10-08 21:08:23 UTC

 linux-azure-nvidia (6.8.0-1026.29) noble; urgency=medium
 .
   * noble/linux-azure-nvidia: 6.8.0-1026.28 -proposed tracker (LP: #2125352)
 .
   * sources list generation using dwarfdump takes up to 0.5hr in build process
     (LP: #2104911)
     - [Packaging] azure-nvidia: Don't generate list of source files
 .
   [ Ubuntu-azure: 6.8.0-1041.47 ]
 .
   * noble/linux-azure: 6.8.0-1041.47 -proposed tracker (LP: #2125355)
   * Fix failure to build TDX module (LP: #2126698)
     - x86/paravirt: Move halt paravirt calls under CONFIG_PARAVIRT
   * sources list generation using dwarfdump takes up to 0.5hr in build process
     (LP: #2104911)
     - [Packaging] azure: Don't generate list of source files
   * MANA Catchup (LP: #2125704)
     - RDMA/mana_ib: Use struct mana_ib_queue for WQs
     - RDMA/mana_ib: Use struct mana_ib_queue for RAW QPs
     - RDMA/mana_ib: remove useless return values from dbg prints
     - RDMA/mana_ib: Use num_comp_vectors of ib_device
     - RDMA/mana_ib: Add EQ creation for rnic adapter
     - RDMA/mana_ib: Create and destroy rnic adapter
     - RDMA/mana_ib: Implement port parameters
     - RDMA/mana_ib: Adding and deleting GIDs
     - RDMA/mana_ib: Configure mac address in RNIC
     - RDMA/mana_ib: create EQs for RNIC CQs
     - RDMA/mana_ib: create and destroy RNIC cqs
     - RDMA/mana_ib: introduce a helper to remove cq callbacks
     - RDMA/mana_ib: implement uapi for creation of rnic cq
     - RDMA/mana_ib: Create and destroy RC QP
     - RDMA/mana_ib: Implement uapi to create and destroy RC QP
     - RDMA/mana_ib: Modify QP state
     - RDMA/mana_ib: set node_guid
     - RDMA/mana_ib: extend query device
     - RDMA/mana_ib: Process QP error events in mana_ib
     - RDMA/mana_ib: Allow registration of DMA-mapped memory in PDs
     - RDMA/mana_ib: implement get_dma_mr
     - RDMA/mana_ib: helpers to allocate kernel queues
     - RDMA/mana_ib: create kernel-level CQs
     - RDMA/mana_ib: Create and destroy UD/GSI QP
     - RDMA/mana_ib: UD/GSI QP creation for kernel
     - RDMA/mana_ib: create/destroy AH
     - net/mana: fix warning in the writer of client oob
     - RDMA/mana_ib: UD/GSI work requests
     - RDMA/mana_ib: implement req_notify_cq
     - RDMA/mana_ib: extend mana QP table
     - RDMA/mana_ib: polling of CQs for GSI/UD
     - RDMA/mana_ib: indicate CM support
     - SAUCE: mana: Removing string literal "NET_MANA" namespace
     - RDMA/mana_ib: Query feature_flags bitmask from FW
     - RDMA/mana_ib: request error CQEs when supported
     - RDMA/mana_ib: Add port statistics support
     - RDMA: Pass uverbs_attr_bundle as part of '.reg_user_mr_dmabuf' API
     - RDMA/mana_ib: Implement DMABUF MR support
     - RDMA/mana_ib: Fix error code in probe()
     - net: mana: Probe rdma device in mana driver
     - RDMA/mana_ib: Add support of 4M, 1G, and 2G pages
     - RDMA/mana_ib: Add support of mana_ib for RNIC and ETH nic
     - RDMA/mana_ib: unify mana_ib functions to support any gdma device
     - net: mana: Add support for auxiliary device servicing events
     - RDMA/mana_ib: Add device statistics support
     - net: mana: Handle Reset Request from MANA NIC
   [ Ubuntu: 6.8.0-86.87 ]
   * noble/linux: 6.8.0-86.87 -proposed tracker (LP: #2125391)
     - Fix FTBS caused by incorrect pick/backport of
       "perf dso: fix dso__is_kallsyms() check"
   * noble ubuntu_ftrace_smoke_test:mmiotrace timeout on aws:r5.metal
     (LP: #2121673)
     - mm: memcg: add NULL check to obj_cgroup_put()
     - memcg: drain obj stock on cpu hotplug teardown
   * [25.04 FEAT] [post announcement] [KRN2304] CPU-MF Counters for new IBM Z
     hardware - perf part (LP: #2103415)
     - perf list: Add IBM z17 event descriptions
   * memory leaks when configuring a small rate limit in audit (LP: #2122554)
     - audit: fix skb leak when audit rate limit is exceeded
   * [UBUNTU 24.04] PAI/NNPA support for new IBM z17 (LP: #2121956)
     - s390/pai: export number of sysfs attribute files
     - s390/pai_crypto: Add support for MSA 10 and 11 pai counters
     - s390/pai_ext: Update PAI extension 1 counters
   * [UBUNTU 24.04] s390/pci: Don't abort recovery for user-space drivers
     (LP: #2121150)
     - s390/pci: Allow automatic recovery with minimal driver support
   * [UBUNTU 24.04] s390/pci: Fix stale function handles in error handling
     (LP: #2121149)
     - s390/pci: Fix stale function handles in error handling
     - s390/pci: Do not try re-enabling load/store if device is disabled
   * [UBUNTU 24.04] vfio/pci: fix 8-byte PCI loads and stores (LP: #2121146)
     - vfio/pci: Extract duplicated code into macro
     - vfio/pci: Support 8-byte PCI loads and stores
     - vfio/pci: Fix typo in macro to declare accessors
   * x86 systems with PCIe BAR addresses located outside a certain range see
     P2PDMA allocation failures and CUDA initialization errors (LP: #2120209)
     - x86/kaslr: Reduce KASLR entropy on most x86 systems
     - x86/mm/init: Handle the special case of device private pages in
       add_pages(), to not increase max_pfn and trigger
       dma_addressing_limited() bounce buffers
   * sources list generation using dwarfdump takes up to 0.5hr in build process
     (LP: #2104911)
     - [Packaging] Don't generate list of source files
   * [SRU] Apparmor: Unshifted uids for hardlinks and unix sockets in user
     namespaces (LP: #2121257)
     - apparmor: shift ouid when mediating hard links in userns
     - apparmor: shift uid when mediating af_unix in userns
   * UBSAN: shift-out-of-bounds in drivers/edac/skx_common.c:452:16
     (LP: #2119713)
     - EDAC/i10nm: Skip DIMM enumeration on a disabled memory controller
   * [IdeaPad Slim 5 13ARP10 , 83J2] Microphone on AMD Ryzen 7 7735HS does not
     work (LP: #2102749)
     - ASoC: amd: yc: update quirk data for new Lenovo model
   * Fix compilation failure because of incomplete backport (LP: #2120561)
     - SAUCE: netfilter: ctnetlink: Fix -Wuninitialized in
       ctnetlink_secctx_size()
   * Noble

Source diff to previous version
2104911 sources list generation using dwarfdump takes up to 0.5hr in build process
2126698 Fix failure to build TDX module
2125704 MANA Catchup
2121673 noble ubuntu_ftrace_smoke_test:mmiotrace timeout on aws:r5.metal
2103415 [25.04 FEAT] [post announcement] [KRN2304] CPU-MF Counters for new IBM Z hardware - perf part
2122554 memory leaks when configuring a small rate limit in audit
2121956 [UBUNTU 24.04] PAI/NNPA support for new IBM z17
2121150 [UBUNTU 24.04] s390/pci: Don't abort recovery for user-space drivers
2121149 [UBUNTU 24.04] s390/pci: Fix stale function handles in error handling
2121146 [UBUNTU 24.04] vfio/pci: fix 8-byte PCI loads and stores
2120209 x86 systems with PCIe BAR addresses located outside a certain range see P2PDMA allocation failures and CUDA initialization errors
2121257 [SRU] Apparmor: Unshifted uids for hardlinks and unix sockets in user namespaces
2119713 UBSAN: shift-out-of-bounds in drivers/edac/skx_common.c:452:16
2102749 [IdeaPad Slim 5 13ARP10 , 83J2] Microphone on AMD Ryzen 7 7735HS does not work
2120561 Fix compilation failure because of incomplete backport
2121716 Noble update: upstream stable patchset 2025-09-01
2120877 Noble update: upstream stable patchset 2025-08-18
2120516 TLS socket disconnection causes various issues
1786013 Packaging resync
CVE-2025-22028 In the Linux kernel, the following vulnerability has been resolved: media: vimc: skip .s_stream() for stopped entities Syzbot reported [1] a warnin
CVE-2025-22036 In the Linux kernel, the following vulnerability has been resolved: exfat: fix random stack corruption after get_block When get_block is called wit
CVE-2025-22039 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was origina
CVE-2025-22062 In the Linux kernel, the following vulnerability has been resolved: sctp: add mutual exclusion in proc_sctp_do_udp_port() We must serialize calls t
CVE-2025-22065 In the Linux kernel, the following vulnerability has been resolved: idpf: fix adapter NULL pointer dereference on reboot With SRIOV enabled, idpf e
CVE-2025-22068 In the Linux kernel, the following vulnerability has been resolved: ublk: make sure ubq->canceling is set when queue is frozen Now ublk driver depe
CVE-2025-22070 In the Linux kernel, the following vulnerability has been resolved: fs/9p: fix NULL pointer dereference on mkdir When a 9p tree was mounted with op
CVE-2025-40114 In the Linux kernel, the following vulnerability has been resolved: iio: light: Add check for array bounds in veml6075_read_int_time_ms The array c
CVE-2025-22025 In the Linux kernel, the following vulnerability has been resolved: nfsd: put dl_stid if fail to queue dl_recall Before calling nfsd4_run_cb to que
CVE-2025-22027 In the Linux kernel, the following vulnerability has been resolved: media: streamzap: fix race between device disconnection and urb callback Syzkal
CVE-2025-39735 In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds read in ea_get() During the "size_check" label in e
CVE-2025-22033 In the Linux kernel, the following vulnerability has been resolved: arm64: Don't call NULL in do_compat_alignment_fixup() do_alignment_t32_to_handl
CVE-2025-22035 In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in print_graph_function_flags during tracer switchin
CVE-2025-22038 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate zero num_subauth before sub_auth is accessed Access psid->sub_a
CVE-2025-22040 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix session use-after-free in multichannel connection There is a race co
CVE-2025-22041 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregister() In multichannel mode,
CVE-2025-22042 In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for create lease context Add missing bounds check for c
CVE-2025-22044 In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: fix narrowing conversion in acpi_nfit_ctl Syzkaller has reported a
CVE-2025-22045 In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs On the followin
CVE-2025-22050 In the Linux kernel, the following vulnerability has been resolved: usbnet:fix NPE during rx_complete Missing usbnet_going_away Check in Critical P
CVE-2025-22053 In the Linux kernel, the following vulnerability has been resolved: net: ibmveth: make veth_pool_store stop hanging v2: - Created a single error ha
CVE-2025-22054 In the Linux kernel, the following vulnerability has been resolved: arcnet: Add NULL check in com20020pci_probe() devm_kasprintf() returns NULL whe
CVE-2025-22055 In the Linux kernel, the following vulnerability has been resolved: net: fix geneve_opt length integer overflow struct geneve_opt uses 5 bit length
CVE-2025-22056 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix geneve_opt type confusion addition When handling mul
CVE-2025-22057 In the Linux kernel, the following vulnerability has been resolved: net: decrease cached dst counters in dst_release Upstream fix ac888d58869b ("ne
CVE-2025-22058 In the Linux kernel, the following vulnerability has been resolved: udp: Fix memory accounting leak. Matt Dowling reported a weird UDP memory usage
CVE-2025-22060 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: Prevent parser TCAM memory corruption Protect the parser TCAM/SRAM
CVE-2025-38637 In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue assertions In the current implem
CVE-2025-22063 In the Linux kernel, the following vulnerability has been resolved: netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets When cal
CVE-2025-22064 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't unregister hook when table is dormant When nf_table
CVE-2025-22066 In the Linux kernel, the following vulnerability has been resolved: ASoC: imx-card: Add NULL check in imx_card_probe() devm_kasprintf() returns NUL
CVE-2023-53034 In the Linux kernel, the following vulnerability has been resolved: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans There i
CVE-2025-22071 In the Linux kernel, the following vulnerability has been resolved: spufs: fix a leak in spufs_create_context() Leak fixes back in 2008 missed one
CVE-2025-22072 In the Linux kernel, the following vulnerability has been resolved: spufs: fix gang directory lifetimes prior to "[POWERPC] spufs: Fix gang destroy
CVE-2025-22073 In the Linux kernel, the following vulnerability has been resolved: spufs: fix a leak on spufs_new_file() failure It's called from spufs_fill_dir()
CVE-2025-38575 In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_alloc Use aead_request_free(
CVE-2025-22075 In the Linux kernel, the following vulnerability has been resolved: rtnetlink: Allocate vfinfo size for VF GUIDs when supported Commit 30aad41721e0
CVE-2025-37937 In the Linux kernel, the following vulnerability has been resolved: objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds() If dib8000
CVE-2025-22079 In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate l_tree_depth to avoid out-of-bounds access The l_tree_depth fie
CVE-2025-22080 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Prevent integer overflow in hdr_first_de() The "de_off" and "used" va
CVE-2025-22081 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix a couple integer overflows on 32bit systems On 32bit systems the
CVE-2025-22083 In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint If vhost_
CVE-2025-22086 In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow When cur_qp isn't NULL, in or
CVE-2025-22089 In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Don't expose hw_counters outside of init net namespace Commit 467f43
CVE-2025-39728 In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init() With UBSAN_ARRAY_BOUNDS=y,
CVE-2025-22090 In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range() If track
CVE-2025-38152 In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdown There is case as below cou
CVE-2025-38240 In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL ptr The function
CVE-2025-22095 In the Linux kernel, the following vulnerability has been resolved: PCI: brcmstb: Fix error path after a call to regulator_bulk_get() If the regula
CVE-2025-22097 In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Fix use after free and double free on init error If the driver initia
CVE-2025-23136 In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: Add NULL check for adev Not all devices have an ACPI companio
CVE-2025-23138 In the Linux kernel, the following vulnerability has been resolved: watch_queue: fix pipe accounting mismatch Currently, watch_queue_set_size() mod
CVE-2025-39682 In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call mus
CVE-2025-38500 In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing collect_md xfrm interface co
CVE-2025-37756 In the Linux kernel, the following vulnerability has been resolved: net: tls: explicitly disallow disconnect syzbot discovered that it can disconne
CVE-2025-38477 In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix race condition on qfq_aggregate A race condition can oc
CVE-2025-38618 In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It is possible for a vsock to au
CVE-2025-38617 In the Linux kernel, the following vulnerability has been resolved: net/packet: fix a race in packet_set_ring() and packet_notifier() When packet_s
CVE-2025-37785 In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounting a corrupted filesystem wit

Version: 6.8.0-1026.28 2025-10-03 22:08:25 UTC

 linux-azure-nvidia (6.8.0-1026.28) noble; urgency=medium
 .
   * noble/linux-azure-nvidia: 6.8.0-1026.28 -proposed tracker (LP: #2125352)
 .
   * sources list generation using dwarfdump takes up to 0.5hr in build process
     (LP: #2104911)
     - [Packaging] azure-nvidia: Don't generate list of source files
 .
   [ Ubuntu-azure: 6.8.0-1041.47 ]
 .
   * noble/linux-azure: 6.8.0-1041.47 -proposed tracker (LP: #2125355)
   * Fix failure to build TDX module (LP: #2126698)
     - x86/paravirt: Move halt paravirt calls under CONFIG_PARAVIRT
   * sources list generation using dwarfdump takes up to 0.5hr in build process
     (LP: #2104911)
     - [Packaging] azure: Don't generate list of source files
   * MANA Catchup (LP: #2125704)
     - RDMA/mana_ib: Use struct mana_ib_queue for WQs
     - RDMA/mana_ib: Use struct mana_ib_queue for RAW QPs
     - RDMA/mana_ib: remove useless return values from dbg prints
     - RDMA/mana_ib: Use num_comp_vectors of ib_device
     - RDMA/mana_ib: Add EQ creation for rnic adapter
     - RDMA/mana_ib: Create and destroy rnic adapter
     - RDMA/mana_ib: Implement port parameters
     - RDMA/mana_ib: Adding and deleting GIDs
     - RDMA/mana_ib: Configure mac address in RNIC
     - RDMA/mana_ib: create EQs for RNIC CQs
     - RDMA/mana_ib: create and destroy RNIC cqs
     - RDMA/mana_ib: introduce a helper to remove cq callbacks
     - RDMA/mana_ib: implement uapi for creation of rnic cq
     - RDMA/mana_ib: Create and destroy RC QP
     - RDMA/mana_ib: Implement uapi to create and destroy RC QP
     - RDMA/mana_ib: Modify QP state
     - RDMA/mana_ib: set node_guid
     - RDMA/mana_ib: extend query device
     - RDMA/mana_ib: Process QP error events in mana_ib
     - RDMA/mana_ib: Allow registration of DMA-mapped memory in PDs
     - RDMA/mana_ib: implement get_dma_mr
     - RDMA/mana_ib: helpers to allocate kernel queues
     - RDMA/mana_ib: create kernel-level CQs
     - RDMA/mana_ib: Create and destroy UD/GSI QP
     - RDMA/mana_ib: UD/GSI QP creation for kernel
     - RDMA/mana_ib: create/destroy AH
     - net/mana: fix warning in the writer of client oob
     - RDMA/mana_ib: UD/GSI work requests
     - RDMA/mana_ib: implement req_notify_cq
     - RDMA/mana_ib: extend mana QP table
     - RDMA/mana_ib: polling of CQs for GSI/UD
     - RDMA/mana_ib: indicate CM support
     - SAUCE: mana: Removing string literal "NET_MANA" namespace
     - RDMA/mana_ib: Query feature_flags bitmask from FW
     - RDMA/mana_ib: request error CQEs when supported
     - RDMA/mana_ib: Add port statistics support
     - RDMA: Pass uverbs_attr_bundle as part of '.reg_user_mr_dmabuf' API
     - RDMA/mana_ib: Implement DMABUF MR support
     - RDMA/mana_ib: Fix error code in probe()
     - net: mana: Probe rdma device in mana driver
     - RDMA/mana_ib: Add support of 4M, 1G, and 2G pages
     - RDMA/mana_ib: Add support of mana_ib for RNIC and ETH nic
     - RDMA/mana_ib: unify mana_ib functions to support any gdma device
     - net: mana: Add support for auxiliary device servicing events
     - RDMA/mana_ib: Add device statistics support
     - net: mana: Handle Reset Request from MANA NIC
   [ Ubuntu: 6.8.0-86.87 ]
   * noble/linux: 6.8.0-86.87 -proposed tracker (LP: #2125391)
     - Fix FTBS caused by incorrect pick/backport of
       "perf dso: fix dso__is_kallsyms() check"
   * noble ubuntu_ftrace_smoke_test:mmiotrace timeout on aws:r5.metal
     (LP: #2121673)
     - mm: memcg: add NULL check to obj_cgroup_put()
     - memcg: drain obj stock on cpu hotplug teardown
   * [25.04 FEAT] [post announcement] [KRN2304] CPU-MF Counters for new IBM Z
     hardware - perf part (LP: #2103415)
     - perf list: Add IBM z17 event descriptions
   * memory leaks when configuring a small rate limit in audit (LP: #2122554)
     - audit: fix skb leak when audit rate limit is exceeded
   * [UBUNTU 24.04] PAI/NNPA support for new IBM z17 (LP: #2121956)
     - s390/pai: export number of sysfs attribute files
     - s390/pai_crypto: Add support for MSA 10 and 11 pai counters
     - s390/pai_ext: Update PAI extension 1 counters
   * [UBUNTU 24.04] s390/pci: Don't abort recovery for user-space drivers
     (LP: #2121150)
     - s390/pci: Allow automatic recovery with minimal driver support
   * [UBUNTU 24.04] s390/pci: Fix stale function handles in error handling
     (LP: #2121149)
     - s390/pci: Fix stale function handles in error handling
     - s390/pci: Do not try re-enabling load/store if device is disabled
   * [UBUNTU 24.04] vfio/pci: fix 8-byte PCI loads and stores (LP: #2121146)
     - vfio/pci: Extract duplicated code into macro
     - vfio/pci: Support 8-byte PCI loads and stores
     - vfio/pci: Fix typo in macro to declare accessors
   * x86 systems with PCIe BAR addresses located outside a certain range see
     P2PDMA allocation failures and CUDA initialization errors (LP: #2120209)
     - x86/kaslr: Reduce KASLR entropy on most x86 systems
     - x86/mm/init: Handle the special case of device private pages in
       add_pages(), to not increase max_pfn and trigger
       dma_addressing_limited() bounce buffers
   * sources list generation using dwarfdump takes up to 0.5hr in build process
     (LP: #2104911)
     - [Packaging] Don't generate list of source files
   * [SRU] Apparmor: Unshifted uids for hardlinks and unix sockets in user
     namespaces (LP: #2121257)
     - apparmor: shift ouid when mediating hard links in userns
     - apparmor: shift uid when mediating af_unix in userns
   * UBSAN: shift-out-of-bounds in drivers/edac/skx_common.c:452:16
     (LP: #2119713)
     - EDAC/i10nm: Skip DIMM enumeration on a disabled memory controller
   * [IdeaPad Slim 5 13ARP10 , 83J2] Microphone on AMD Ryzen 7 7735HS does not
     work (LP: #2102749)
     - ASoC: amd: yc: update quirk data for new Lenovo model
   * Fix compilation failure because of incomplete backport (LP: #2120561)
     - SAUCE: netfilter: ctnetlink: Fix -Wuninitialized in
       ctnetlink_secctx_size()
   * Noble

Source diff to previous version
2104911 sources list generation using dwarfdump takes up to 0.5hr in build process
2126698 Fix failure to build TDX module
2125704 MANA Catchup
2121673 noble ubuntu_ftrace_smoke_test:mmiotrace timeout on aws:r5.metal
2103415 [25.04 FEAT] [post announcement] [KRN2304] CPU-MF Counters for new IBM Z hardware - perf part
2122554 memory leaks when configuring a small rate limit in audit
2121956 [UBUNTU 24.04] PAI/NNPA support for new IBM z17
2121150 [UBUNTU 24.04] s390/pci: Don't abort recovery for user-space drivers
2121149 [UBUNTU 24.04] s390/pci: Fix stale function handles in error handling
2121146 [UBUNTU 24.04] vfio/pci: fix 8-byte PCI loads and stores
2120209 x86 systems with PCIe BAR addresses located outside a certain range see P2PDMA allocation failures and CUDA initialization errors
2121257 [SRU] Apparmor: Unshifted uids for hardlinks and unix sockets in user namespaces
2119713 UBSAN: shift-out-of-bounds in drivers/edac/skx_common.c:452:16
2102749 [IdeaPad Slim 5 13ARP10 , 83J2] Microphone on AMD Ryzen 7 7735HS does not work
2120561 Fix compilation failure because of incomplete backport
2121716 Noble update: upstream stable patchset 2025-09-01
2120877 Noble update: upstream stable patchset 2025-08-18
2120516 TLS socket disconnection causes various issues
1786013 Packaging resync
CVE-2025-22028 In the Linux kernel, the following vulnerability has been resolved: media: vimc: skip .s_stream() for stopped entities Syzbot reported [1] a warnin
CVE-2025-22036 In the Linux kernel, the following vulnerability has been resolved: exfat: fix random stack corruption after get_block When get_block is called wit
CVE-2025-22039 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was origina
CVE-2025-22062 In the Linux kernel, the following vulnerability has been resolved: sctp: add mutual exclusion in proc_sctp_do_udp_port() We must serialize calls t
CVE-2025-22065 In the Linux kernel, the following vulnerability has been resolved: idpf: fix adapter NULL pointer dereference on reboot With SRIOV enabled, idpf e
CVE-2025-22068 In the Linux kernel, the following vulnerability has been resolved: ublk: make sure ubq->canceling is set when queue is frozen Now ublk driver depe
CVE-2025-22070 In the Linux kernel, the following vulnerability has been resolved: fs/9p: fix NULL pointer dereference on mkdir When a 9p tree was mounted with op
CVE-2025-40114 In the Linux kernel, the following vulnerability has been resolved: iio: light: Add check for array bounds in veml6075_read_int_time_ms The array c
CVE-2025-22025 In the Linux kernel, the following vulnerability has been resolved: nfsd: put dl_stid if fail to queue dl_recall Before calling nfsd4_run_cb to que
CVE-2025-22027 In the Linux kernel, the following vulnerability has been resolved: media: streamzap: fix race between device disconnection and urb callback Syzkal
CVE-2025-39735 In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds read in ea_get() During the "size_check" label in e
CVE-2025-22033 In the Linux kernel, the following vulnerability has been resolved: arm64: Don't call NULL in do_compat_alignment_fixup() do_alignment_t32_to_handl
CVE-2025-22035 In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in print_graph_function_flags during tracer switchin
CVE-2025-22038 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate zero num_subauth before sub_auth is accessed Access psid->sub_a
CVE-2025-22040 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix session use-after-free in multichannel connection There is a race co
CVE-2025-22041 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregister() In multichannel mode,
CVE-2025-22042 In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for create lease context Add missing bounds check for c
CVE-2025-22044 In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: fix narrowing conversion in acpi_nfit_ctl Syzkaller has reported a
CVE-2025-22045 In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs On the followin
CVE-2025-22050 In the Linux kernel, the following vulnerability has been resolved: usbnet:fix NPE during rx_complete Missing usbnet_going_away Check in Critical P
CVE-2025-22053 In the Linux kernel, the following vulnerability has been resolved: net: ibmveth: make veth_pool_store stop hanging v2: - Created a single error ha
CVE-2025-22054 In the Linux kernel, the following vulnerability has been resolved: arcnet: Add NULL check in com20020pci_probe() devm_kasprintf() returns NULL whe
CVE-2025-22055 In the Linux kernel, the following vulnerability has been resolved: net: fix geneve_opt length integer overflow struct geneve_opt uses 5 bit length
CVE-2025-22056 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix geneve_opt type confusion addition When handling mul
CVE-2025-22057 In the Linux kernel, the following vulnerability has been resolved: net: decrease cached dst counters in dst_release Upstream fix ac888d58869b ("ne
CVE-2025-22058 In the Linux kernel, the following vulnerability has been resolved: udp: Fix memory accounting leak. Matt Dowling reported a weird UDP memory usage
CVE-2025-22060 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: Prevent parser TCAM memory corruption Protect the parser TCAM/SRAM
CVE-2025-38637 In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue assertions In the current implem
CVE-2025-22063 In the Linux kernel, the following vulnerability has been resolved: netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets When cal
CVE-2025-22064 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't unregister hook when table is dormant When nf_table
CVE-2025-22066 In the Linux kernel, the following vulnerability has been resolved: ASoC: imx-card: Add NULL check in imx_card_probe() devm_kasprintf() returns NUL
CVE-2023-53034 In the Linux kernel, the following vulnerability has been resolved: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans There i
CVE-2025-22071 In the Linux kernel, the following vulnerability has been resolved: spufs: fix a leak in spufs_create_context() Leak fixes back in 2008 missed one
CVE-2025-22072 In the Linux kernel, the following vulnerability has been resolved: spufs: fix gang directory lifetimes prior to "[POWERPC] spufs: Fix gang destroy
CVE-2025-22073 In the Linux kernel, the following vulnerability has been resolved: spufs: fix a leak on spufs_new_file() failure It's called from spufs_fill_dir()
CVE-2025-38575 In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_alloc Use aead_request_free(
CVE-2025-22075 In the Linux kernel, the following vulnerability has been resolved: rtnetlink: Allocate vfinfo size for VF GUIDs when supported Commit 30aad41721e0
CVE-2025-37937 In the Linux kernel, the following vulnerability has been resolved: objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds() If dib8000
CVE-2025-22079 In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate l_tree_depth to avoid out-of-bounds access The l_tree_depth fie
CVE-2025-22080 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Prevent integer overflow in hdr_first_de() The "de_off" and "used" va
CVE-2025-22081 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix a couple integer overflows on 32bit systems On 32bit systems the
CVE-2025-22083 In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint If vhost_
CVE-2025-22086 In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow When cur_qp isn't NULL, in or
CVE-2025-22089 In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Don't expose hw_counters outside of init net namespace Commit 467f43
CVE-2025-39728 In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init() With UBSAN_ARRAY_BOUNDS=y,
CVE-2025-22090 In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range() If track
CVE-2025-38152 In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdown There is case as below cou
CVE-2025-38240 In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL ptr The function
CVE-2025-22095 In the Linux kernel, the following vulnerability has been resolved: PCI: brcmstb: Fix error path after a call to regulator_bulk_get() If the regula
CVE-2025-22097 In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Fix use after free and double free on init error If the driver initia
CVE-2025-23136 In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: Add NULL check for adev Not all devices have an ACPI companio
CVE-2025-23138 In the Linux kernel, the following vulnerability has been resolved: watch_queue: fix pipe accounting mismatch Currently, watch_queue_set_size() mod
CVE-2025-39682 In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call mus
CVE-2025-38500 In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing collect_md xfrm interface co
CVE-2025-37756 In the Linux kernel, the following vulnerability has been resolved: net: tls: explicitly disallow disconnect syzbot discovered that it can disconne
CVE-2025-38477 In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix race condition on qfq_aggregate A race condition can oc
CVE-2025-38618 In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It is possible for a vsock to au
CVE-2025-38617 In the Linux kernel, the following vulnerability has been resolved: net/packet: fix a race in packet_set_ring() and packet_notifier() When packet_s
CVE-2025-37785 In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounting a corrupted filesystem wit

Version: 6.8.0-1024.26 2025-09-05 18:27:13 UTC

 linux-azure-nvidia (6.8.0-1024.26) noble; urgency=medium
 .
   * noble/linux-azure-nvidia: 6.8.0-1024.26 -proposed tracker (LP: #2120004)
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] debian.azure-nvidia/dkms-versions -- update from kernel-
       versions (main/2025.08.11)
 .
   * Set CONFIG_IOMMU_DEFAULT_DMA_LAZY as default for Nvidia CPUs
     (LP: #2119661)
     - [Config] azure-nvidia: Update annotations to set
       CONFIG_IOMMU_DEFAULT_DMA_LAZY
 .
   [ Ubuntu-nvidia: 6.8.0-1037.40 ]
 .
   * noble/linux-nvidia: 6.8.0-1037.40 -proposed tracker (LP: #2120024)
   * Packaging resync (LP: #1786013)
     - [Packaging] resync git-ubuntu-log
     - [Packaging] debian.nvidia/dkms-versions -- update from kernel-versions
       (main/2025.08.11)
   * Pull-request for setting CPU frequency gov to performance (LP: #2028576)
     - [Config] nvidia: Use performance CPU frequency governor on amd64
   * Set CONFIG_IOMMU_DEFAULT_DMA_LAZY as default for Nvidia CPUs
     (LP: #2119661)
     - [Config] nvidia: Update annotations to set CONFIG_IOMMU_DEFAULT_DMA_LAZY
 .
   [ Ubuntu-azure: 6.8.0-1036.42 ]
 .
   * noble/linux-azure: 6.8.0-1036.42 -proposed tracker (LP: #2121967)
   * Packaging resync (LP: #1786013)
     - [Packaging] resync git-ubuntu-log
     - [Packaging] debian.azure/dkms-versions -- update from kernel-versions
       (main/2025.08.11)
   * [MANA][Backport] The big tcp enablement patch (LP: #2119958)
     - net: mana: Allow tso_max_size to go up-to GSO_MAX_SIZE
     - hv_netvsc: Use VF's tso_max_size value when data path is VF
   * [storvsc][Backport] scsi: storvsc: Increase the timeouts to
     storvsc_timeout (LP: #2119690)
     - scsi: storvsc: Increase the timeouts to storvsc_timeout
   * [MANA][Backport]net: mana: Record doorbell physical address in PF mode
     (LP: #2119680)
     - net: mana: Record doorbell physical address in PF mode
   * MANA patch catch-up with azure-nvidia for 6.8 kernel (LP: #2119572)
     - RDMA/mana_ib: Set correct device into ib
     - net: mana: Change the function signature of mana_get_primary_netdev_rcu
     - RDMA/mana_ib: Handle net event for pointing to the current netdev
   * net: mana: Expose additional hardware counters for drop and TC via ethtool
     (LP: #2119686)
     - net: mana: use ethtool string helpers
     - net: mana: Expose additional hardware counters for drop and TC via
       ethtool.
   * [MANA][Backport] net: mana: Switch to page pool for jumbo frames
     (LP: #2118947)
     - net: mana: Switch to page pool for jumbo frames
   * [MANA][Backport] patch: net: mana: Add debug logs in MANA network driver
     (LP: #2119168)
     - net: mana: Add debug logs in MANA network driver
   * Backporting Linux CIFS dentry leak fix: Avoid race in open_cached_dir with
     lease breaks (LP: #2117524)
     - smb: client: Avoid race in open_cached_dir with lease breaks
   [ Ubuntu: 6.8.0-81.81 ]
   * noble/linux: 6.8.0-81.81 -proposed tracker (LP: #2121671)
   * Packaging resync (LP: #1786013)
     - [Packaging] debian.master/dkms-versions -- update from kernel-versions
       (main/2025.08.11)
   * nvme no longer detected on boot after upgrade to 6.8.0-60 (LP: #2111521)
     - SAUCE: PCI: Disable RRS polling for Intel SSDPE2KX020T8 nvme
   * No IP Address assigned after hot-plugging Ethernet cable on HP Platform
     (LP: #2115393)
     - Revert "e1000e: change k1 configuration on MTP and later platforms"
   * minimal kernel lacks modules for blk disk in arm64 openstack environments
     where config_drive is required (LP: #2118499)
     - [Config] Enable SYM53C8XX_2 on arm64
   * rcu: Eliminate deadlocks involving do_exit() and RCU tasks (LP: #2117123)
     - rcu-tasks: Initialize callback lists at rcu_init() time
     - rcu-tasks: Maintain lists to eliminate RCU-tasks/do_exit() deadlocks
     - rcu-tasks: Eliminate deadlocks involving do_exit() and RCU tasks
     - rcu-tasks: Maintain real-time response in rcu_tasks_postscan()
   * BPF header file in wrong location (LP: #2118965)
     - [Packaging] Install bpf header to correct location
   * i915: support ARL-H gpu (LP: #2117716)
     - drm/i915: Add additional ARL PCI IDs
     - drm/i915/mtl: Add fake PCH for Meteor Lake
     - drm/i915/mtl: Wake GT before sending H2G message
     - drm/i915/xelpg: Add workaround 14019877138
     - drm/i915/xelpg: Extend driver code of Xe_LPG to Xe_LPG+
     - drm/i915/display: correct dual pps handling for MTL_PCH+
   * Ubuntu 24.04.2: NULL pointer dereference with Ceph and selinux
     (LP: #2115447)
     - SAUCE: fs/ceph, selinux: fix NULL pointer dereference on CephFS write
       with SELinux in permissive mode
   * Noble update: upstream stable patchset 2025-08-04 (LP: #2119458)
     - clockevents/drivers/i8253: Fix stop sequence for timer 0
     - sched/isolation: Prevent boot crash when the boot CPU is nohz_full
     - hrtimer: Use and report correct timerslack values for realtime tasks
     - mm: add nommu variant of vm_insert_pages()
     - io_uring: get rid of remap_pfn_range() for mapping rings/sqes
     - io_uring: don't attempt to mmap larger than what the user asks for
     - io_uring: fix corner case forgetting to vunmap
     - io_uring: use vmap() for ring mapping
     - io_uring: unify io_pin_pages()
     - io_uring/kbuf: vmap pinned buffer ring
     - io_uring/kbuf: use vm_insert_pages() for mmap'ed pbuf ring
     - io_uring: use unpin_user_pages() where appropriate
     - io_uring: fix error pbuf checking
     - rust: Disallow BTF generation with Rust + LTO
     - rust: init: fix `Zeroable` implementation for `Option>` and
       `Option>`
     - lib/buildid: Handle memfd_secret() files in build_id_parse()
     - mm: split critical region in remap_file_pages() and invoke LSMs in
       between
     - stmmac: loongson: Pass correct arg to PCI function
     - rust: lockdep: Remove support for dynamically allocated LockClassKeys
     - netfilter: nf_tables: allow clone callbacks to sleep
     - drm/amd/display: should s

Source diff to previous version
1786013 Packaging resync
2119661 Set CONFIG_IOMMU_DEFAULT_DMA_LAZY as default for Nvidia CPUs
2119958 [MANA][Backport] The big tcp enablement patch
2119690 [storvsc][Backport] scsi: storvsc: Increase the timeouts to storvsc_timeout
2119680 [MANA][Backport]net: mana: Record doorbell physical address in PF mode
2119572 MANA patch catch-up with azure-nvidia for 6.8 kernel
2119686 net: mana: Expose additional hardware counters for drop and TC via ethtool
2118947 [MANA][Backport] net: mana: Switch to page pool for jumbo frames
2119168 [MANA][Backport] patch: net: mana: Add debug logs in MANA network driver
2117524 Backporting Linux CIFS dentry leak fix: Avoid race in open_cached_dir with lease breaks
2111521 nvme no longer detected on boot after upgrade to 6.8.0-60
2118499 minimal kernel lacks modules for blk disk in arm64 openstack environments where config_drive is required
2117123 rcu: Eliminate deadlocks involving do_exit() and RCU tasks
2118965 BPF header file in wrong location
2117716 i915: support ARL-H gpu
2115447 Ubuntu 24.04.2: NULL pointer dereference with Ceph and selinux
2119458 Noble update: upstream stable patchset 2025-08-04
2118927 Noble update: upstream stable patchset 2025-07-28
2117533 Noble update: upstream stable patchset 2025-07-22
2116878 Noble update: upstream stable patchset 2025-07-14
CVE-2025-21872 In the Linux kernel, the following vulnerability has been resolved: efi: Don't map the entire mokvar table to determine its size Currently, when va
CVE-2025-21880 In the Linux kernel, the following vulnerability has been resolved: drm/xe/userptr: fix EFAULT handling Currently we treat EFAULT from hmm_range_fa
CVE-2025-21890 In the Linux kernel, the following vulnerability has been resolved: idpf: fix checksums set in idpf_rx_rsc() idpf_rx_rsc() uses skb_transport_offse
CVE-2025-21885 In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix the page details for the srq created by kernel consumers Whil
CVE-2025-21888 In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix a WARN during dereg_mr for DM type Memory regions (MR) of type D
CVE-2025-21892 In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix the recovery flow of the UMR QP This patch addresses an issue in
CVE-2025-21873 In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: bsg: Fix crash when arpmb command fails If the device doesn't
CVE-2024-58090 In the Linux kernel, the following vulnerability has been resolved: sched/core: Prevent rescheduling when interrupts are disabled David reported a
CVE-2025-21875 In the Linux kernel, the following vulnerability has been resolved: mptcp: always handle address removal under msk socket lock Syzkaller reported a
CVE-2025-21877 In the Linux kernel, the following vulnerability has been resolved: usbnet: gl620a: fix endpoint checking in genelink_bind() Syzbot reports [1] a w
CVE-2025-21878 In the Linux kernel, the following vulnerability has been resolved: i2c: npcm: disable interrupt enable bit before devm_request_irq The customer re
CVE-2025-21889 In the Linux kernel, the following vulnerability has been resolved: perf/core: Add RCU read lock protection to perf_iterate_ctx() The perf_iterate_
CVE-2025-21898 In the Linux kernel, the following vulnerability has been resolved: ftrace: Avoid potential division by zero in function_stat_show() Check whether
CVE-2025-21899 In the Linux kernel, the following vulnerability has been resolved: tracing: Fix bad hist from corrupting named_triggers list The following command
CVE-2025-21881 In the Linux kernel, the following vulnerability has been resolved: uprobes: Reject the shared zeropage in uprobe_write_opcode() We triggered the f
CVE-2025-21895 In the Linux kernel, the following vulnerability has been resolved: perf/core: Order the PMU list to fix warning about unordered pmu_ctx_list Syska
CVE-2025-21883 In the Linux kernel, the following vulnerability has been resolved: ice: Fix deinitializing VF in error path If ice_ena_vfs() fails after calling i
CVE-2025-21891 In the Linux kernel, the following vulnerability has been resolved: ipvlan: ensure network headers are in skb linear part syzbot found that ipvlan_
CVE-2024-57996 In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: don't allow 1 packet limit The current implementation does
CVE-2025-37752 In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: move the limit validation It is not sufficient to directly
CVE-2025-38350 In the Linux kernel, the following vulnerability has been resolved: net/sched: Always pass notifications when child class becomes empty Certain cla
CVE-2025-21887 In the Linux kernel, the following vulnerability has been resolved: ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up The iss

Version: 6.8.0-1022.23 2025-08-14 05:08:26 UTC

 linux-azure-nvidia (6.8.0-1022.23) noble; urgency=medium
 .
   * noble/linux-azure-nvidia: 6.8.0-1022.23 -proposed tracker (LP: #2120371)
 .
   [ Ubuntu-azure: 6.8.0-1034.39 ]
 .
   * noble/linux-azure: 6.8.0-1034.39 -proposed tracker (LP: #2120374)
   [ Ubuntu: 6.8.0-78.78 ]
   * noble/linux: 6.8.0-78.78 -proposed tracker (LP: #2120405)
   * Incorrect backport for CVE-2025-21861 causes kernel hangs
     (LP: #2120330) // CVE-2025-21861
     - mm/migrate_device: don't add folio to be freed to LRU in
       migrate_device_finalize()
   * Incorrect backport for CVE-2025-21861 causes kernel hangs (LP: #2120330)
     - SAUCE: Revert "mm/migrate_device: don't add folio to be freed to LRU in
       migrate_device_finalize()"
     - mm: migrate_device: use more folio in migrate_device_finalize()
 .

2120330 Incorrect backport for CVE-2025-21861 causes kernel hangs
CVE-2025-21861 In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize



About   -   Send Feedback to @ubuntu_updates