UbuntuUpdates.org

Package "linux-libc-dev"

This package belongs to a PPA: Canonical Kernel Team

Name: linux-libc-dev

Description:

Linux Kernel Headers for development

Latest version: 6.8.0-147.147
Release: noble (24.04)
Level: base
Repository: main
Head package: linux

Links


Download "linux-libc-dev"


Other versions of "linux-libc-dev" in Noble

Repository Area Version
base main 6.8.0-31.31
security main 6.8.0-142.142
updates main 6.8.0-142.142
proposed main 6.8.0-146.146

Changelog

Version: 6.8.0-147.147 2026-09-24 14:08:48 UTC

 linux (6.8.0-147.147) noble; urgency=medium
 .
   * noble/linux: 6.8.0-147.147 -proposed tracker (LP: #2168142)
 .
   * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026)
     - platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug
     - selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs
     - drm/virtio: fix deadlock in display_info_cb by removing hotplug from
       dequeue worker
     - mtd: mtdswap: remove debugfs stats file on teardown
     - seqlock: Cure some more scoped_seqlock() optimization fails
     - seqlock: Allow KASAN to fail optimizing
     - seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
     - xprtrdma: Clear receive-side ownership pointers on release
     - Input: ims-pcu - fix logic error in packet reset
     - arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
     - mtd: nand: mtk-ecc: stop on ECC idle timeouts
     - RDMA/cma: Fix hardware address comparison length in netevent callback
     - RDMA/umem: Add support for creating pinned DMABUF umem with a given dma
       device
     - RDMA/umem: Introduce an option to revoke DMABUF umem
     - RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper
     - RDMA/umem: Move umem dmabuf revoke logic into helper function
     - RDMA/umem: Add pinned revocable dmabuf import interface
     - RDMA/umem: Add helpers for umem dmabuf revoke lock
     - RDMA/erdma: initialize ret for empty receive WR lists
     - RDMA/hns: Fix potential integer overflow in mhop hem cleanup
     - selftests/alsa: Fix memory leak in find_controls error path
     - RDMA/irdma: Prevent overflows in memory contiguity checks
     - wifi: nl80211: validate nested MBSSID IE blobs
     - wifi: cfg80211: validate PMSR measurement type data
     - wifi: cfg80211: reject unsupported PMSR FTM location requests
     - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on
       start/stop
     - ASoC: amd: ps: fix wrong ACP version string in pci_request_regions()
     - ASoC: cs42l43: Correct report for forced microphone jack
     - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after
       lookup
     - firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
     - ata: sata_dwc_460ex: use platform_get_irq()
     - ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending
       interrupts
     - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
     - drm/i915/gt: use correct selftest config symbol
     - sched/vtime: Get rid of generic vtime_task_switch() implementation
     - powerpc/time: Prepare to stop elapsing in dynticks-idle
     - powerpc/vtime: Initialize starttime at boot for native accounting
     - can: j1939: fix lockless local-destination check
     - drm/i915/selftests: Fix GT PM sort comparators
     - USB: storage: add NO_ATA_1X quirk for Longmai USB Key
     - usb: chipidea: fix usage_count leak when autosuspend_delay is negative
     - USB: gadget: snps-udc: fix device name leak on probe failure
     - USB: gadget: fsl-udc: fix device name leak on probe failure
     - USB: serial: ftdi_sio: add support for E+H FXA291
     - USB: serial: keyspan_pda: fix data loss on receive throttling
     - USB: serial: option: add TDTECH MT5710-CN
     - crypto: rsa-pkcs1pad: Don't WARN on an empty digest
     - RISC-V: KVM: Serialize virtual interrupt pending state updates
     - usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
     - wifi: ath11k: Flush the posted write after writing to
       PCIE_SOC_GLOBAL_RESET
     - wifi: ath12k: Flush the posted write after writing to
       PCIE_SOC_GLOBAL_RESET
     - btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
     - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
     - ASoC: cs35l56: Don't use devres to unregister component
     - ASoC: cs35l56: Fix potential probe() deadlock
     - ASoC: cs35l56: Use complete_all() to signal init_completion
     - wifi: iwlwifi: mvm: validate SAR GEO response payload size
     - wifi: iwlwifi: mvm: fix read in wake packet notification handler
     - hwmon: (asus-ec-sensors) fix looping over banks while reading from EC
     - hwmon: (asus-ec-sensors) fix EC read intervals
     - hwmon: (asus-ec-sensors) add missed handle for ENOMEM
     - wifi: mac80211: recalculate TIM when a station enters power save
     - pds_core: reject component parameter in legacy firmware update
     - amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
     - pds_core: yield the CPU while waiting for the adminq to drain
     - pds_core: order completion reads after the ownership check
     - pds_core: check for workqueue allocation failure
     - tls: device: push pending open record on splice EOF
     - selftest: af_unix: Add Kconfig file.
     - selftests: af_unix: add USER_NS config
     - selftests: openvswitch: add config file
     - amt: make the head writable before rewriting the L2 header
     - net: bridge: vlan: fix vlan range dumps starting with pvid
     - net: dpaa: fix mode setting
     - iomap: correct the range of a partial dirty clear
     - net: stmmac: fix l3l4 filter rejecting unsupported offload requests
     - net: stmmac: reset residual action in L3L4 filters on delete
     - net: stmmac: enable the MAC on link up for all supported speeds
     - octeontx2-vf: set TC flower flag on MCAM entry allocation
     - ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
     - ppp: use IFF_NO_QUEUE in virtual interfaces
     - ppp: convert to percpu netstats
     - ppp: enable TX scatter-gather
     - ppp: annotate data races in ppp_generic
     - hinic: remove unused ethtool RSS user configuration buffers
     - net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
     - net/mlx5e: Report zero bandwidth for non-ETS traffic classes
     - net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
     - net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
     - ice: fix LAG recipe to profile

Source diff to previous version
2168026 Noble update: upstream stable patchset 2026-09-23
2071590 test_vxlan_vnifiltering.sh from ubuntu_kselftests_net failed on linux-oem-6.8 (with ipv6 default rdst)
2160493 ubuntu_bpf failed to build in noble (error: redefinition of 'stack_load_preserves_const_precision')
2165140 qrtr: ns: node limit of 64 breaks QRTR routing on large multi-node deployments
2165732 [UBUNTU 24.04] kernel: CPU hotplug unsupported by CPUMF
2167237 Noble update: upstream stable patchset 2026-09-14
2166995 Noble update: upstream stable patchset 2026-09-10
2166192 Noble update: upstream stable patchset 2026-09-02
CVE-2026-68371 In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Do not put borrowed of_node in probe omap2430_probe() stor
CVE-2026-72130 In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject short AUTH_RECEIVE buffers nvmet_execute_auth_receive() trus
CVE-2026-72168 In the Linux kernel, the following vulnerability has been resolved: mtd: maps: vmu-flash: fix fault in unaligned fixup Use kzalloc_obj() / kzalloc_
CVE-2026-72213 In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch In alloc_hugetlb_f
CVE-2026-72244 In the Linux kernel, the following vulnerability has been resolved: gpu/buddy: bail out of try_harder when alignment cannot be honoured The try_har
CVE-2026-68129 In the Linux kernel, the following vulnerability has been resolved: gve: fix Rx queue stall on alloc failure When the system is under extreme memor
CVE-2026-53078 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops When a BPF
CVE-2026-68119 In the Linux kernel, the following vulnerability has been resolved: tcp: initialize standalone TCP-AO response padding tcp_v4_send_ack() and tcp_v6
CVE-2026-68136 In the Linux kernel, the following vulnerability has been resolved: net: gro: fix double aggregation of flush-marked skbs Commit 0ab03f353d36 ("net
CVE-2026-68139 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Use sender devcom for MPV master-up After PCIe DPC recovery, mlx5 re
CVE-2026-68145 In the Linux kernel, the following vulnerability has been resolved: iomap: fix out-of-bounds bitmap_set() with zero-length range ifs_set_range_dirt
CVE-2026-68161 In the Linux kernel, the following vulnerability has been resolved: sctp: close UDP tunnel sockets during netns teardown proc_sctp_do_udp_port() st
CVE-2026-68162 In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() up
CVE-2026-68178 In the Linux kernel, the following vulnerability has been resolved: misc: nsm: pin the module while the device is open misc_open() installs a misc
CVE-2026-68179 In the Linux kernel, the following vulnerability has been resolved: misc: nsm: only unlock nsm_dev on post-lock error paths nsm_dev_ioctl() jumps t
CVE-2026-68183 In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix memory leaks and list corruption bugs Fix a memory
CVE-2026-68193 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is
CVE-2026-68203 In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix cleanup bugs in vivid_init() When platform_device_register()
CVE-2026-68205 In the Linux kernel, the following vulnerability has been resolved: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_s
CVE-2026-68221 In the Linux kernel, the following vulnerability has been resolved: media: nuvoton: npcm-video: fix memory leaks in probe and remove npcm_video_pro
CVE-2026-68225 In the Linux kernel, the following vulnerability has been resolved: media: i2c: alvium: fix critical pointer access in alvium_ctrl_init The current
CVE-2026-68228 In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Move src_buf Removal to finish_encode During encoder
CVE-2026-68235 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: dce100: skip non-DP stream encoders for DP MST On DCE8-class A
CVE-2026-68247 In the Linux kernel, the following vulnerability has been resolved: drm/i915/bios: range check LFP Data Block panel_type2 While the panel_type from
CVE-2026-68260 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM The drm g
CVE-2026-68261 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: fix error checking of pvr_vm_context_lookup() Since pvr_vm_con
CVE-2026-68262 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix user array stride in pvr_set_uobj_array() pvr_set_uobj_arr
CVE-2026-68263 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix double call to drm_sched_entity_fini() Call sequence of do
CVE-2026-68437 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fit paired fragment job in the correct CCCB For geometry jobs
CVE-2026-68281 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Count paired job fence as dependency in prepare_job() The DRM
CVE-2026-68290 In the Linux kernel, the following vulnerability has been resolved: rds: tcp: unregister sysctl before tearing down listen socket rds_tcp_exit_net(
CVE-2026-68293 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads The MCIA register
CVE-2026-68439 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
CVE-2026-68314 In the Linux kernel, the following vulnerability has been resolved: net: mctp i3c: clean up notifier and buses if driver register fails mctp_i3c_mo
CVE-2026-68318 In the Linux kernel, the following vulnerability has been resolved: pds_core: fix use-after-free on workqueue during remove In pdsc_remove(), the w
CVE-2026-68319 In the Linux kernel, the following vulnerability has been resolved: pds_core: fix deadlock between reset thread and remove pci_reset_function() acq
CVE-2026-68346 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: validate and free ACPI mute object cs35l41_get_acpi_mute_st
CVE-2025-40098 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state(
CVE-2026-68442 In the Linux kernel, the following vulnerability has been resolved: btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps When btrfs_drop
CVE-2026-68443 In the Linux kernel, the following vulnerability has been resolved: hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop Calling
CVE-2026-68372 In the Linux kernel, the following vulnerability has been resolved: usb: core: port: Deattach Type-C connector on component unbind connector_unbind
CVE-2026-68396 In the Linux kernel, the following vulnerability has been resolved: scsi: core: wake eh reliably when using scsi_schedule_eh Drivers which use the
CVE-2026-68408 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock When a netli
CVE-2026-64570 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on alloc failure ieee80211_set_f
CVE-2026-64568 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure ieee802
CVE-2026-72175 In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race Patch series "us
CVE-2026-45901 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: revert commit_mutex usage in reset path It causes circula
CVE-2026-45897 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_counter: serialize reset with spinlock Add a global static spinl
CVE-2026-68093 In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotpl
CVE-2026-68164 In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow overlapping input ranges for damon_set_regions() damon_
CVE-2026-68165 In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: validate ranges in damon_set_regions() DAMON core logic assumes
CVE-2026-72015 In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list A pseudo
CVE-2026-72017 In the Linux kernel, the following vulnerability has been resolved: net: macb: drop in-flight Tx SKBs on close The MACB driver has since forever le
CVE-2026-72030 In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Reject an invalid concurrent positioning ranges count ata_dev
CVE-2026-72023 In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix SQB pointer leak on init failure otx2_init_hw_resources() ini
CVE-2026-72040 In the Linux kernel, the following vulnerability has been resolved: ipmi: fix refcount leak in i_ipmi_request() When a caller provides a `supplied_
CVE-2026-72045 In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF rvu_mbox_handler
CVE-2026-72062 In the Linux kernel, the following vulnerability has been resolved: gpio: mt7621: avoid corruption of shared interrupt trigger state The bank-share
CVE-2026-72051 In the Linux kernel, the following vulnerability has been resolved: net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink ip6_t
CVE-2026-72065 In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by the NIC Validate the packet l
CVE-2026-72069 In the Linux kernel, the following vulnerability has been resolved: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() rt_spin_unlock
CVE-2026-72070 In the Linux kernel, the following vulnerability has been resolved: wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() lbtf_free_adapter(
CVE-2026-72142 In the Linux kernel, the following vulnerability has been resolved: i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) SMBus 3.1 6.5.7 allo
CVE-2026-72147 In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma-pcie: Reject devices without driver data dw_edma_pcie_probe(
CVE-2026-72254 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_fib: reject fib expression on the netdev egress hook A fib expre
CVE-2026-72253 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: validate skb_dst() before accessing it tc ingress
CVE-2026-72260 In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8192: Check runtime resume during probe The MT8192 AFE probe
CVE-2026-72305 In the Linux kernel, the following vulnerability has been resolved: VDUSE: avoid leaking information to userspace The bounceing is not necessarily
CVE-2026-72299 In the Linux kernel, the following vulnerability has been resolved: tipc: restrict socket queue dumps in enqueue tracepoints tipc_sk_enqueue() runs
CVE-2026-74436 In the Linux kernel, the following vulnerability has been resolved: rxrpc: serialize kernel accept preallocation with socket teardown rxrpc_kernel_
CVE-2026-64205 In the Linux kernel, the following vulnerability has been resolved: i2c: i801: fix hardware state machine corruption in error path A severe liveloc
CVE-2026-68096 In the Linux kernel, the following vulnerability has been resolved: audit: fix recursive locking deadlock in audit_dupe_exe() A deadlock occurs in
CVE-2026-64280 In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() afu_ioctl_dm
CVE-2026-68147 In the Linux kernel, the following vulnerability has been resolved: fscrypt: Avoid dynamic allocation in fscrypt_get_devices() When a blk_crypto_ke
CVE-2026-68123 In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix GSO userspace truncation underflow OVS_ACTION_ATTR_TRUNC curre
CVE-2026-68097 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ACE size against SID sub-authorities set_ntacl_dacl() validates
CVE-2026-68098 In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound DACL dedup walk to copied ACEs set_ntacl_dacl() can stop copying A
CVE-2026-68099 In the Linux kernel, the following vulnerability has been resolved: ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL check_a
CVE-2026-68100 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl set_ntacl_dacl()
CVE-2026-68104 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: invoke pm_genpd_remove() before freeing genpd Call pm_genpd_remove(
CVE-2026-68106 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix division by zero with invalid uvd dimensions When width or heig
CVE-2026-68429 In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_pr
CVE-2026-68107 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param length Reuse the parameter length ret
CVE-2026-68108 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image size Fix a security vulnerability
CVE-2026-68110 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() There's no need to crash
CVE-2026-68111 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() There's no need to crash the k
CVE-2026-68112 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() There's no need to crash t
CVE-2026-68430 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx8: drop unecessary BUG_ON() There's no need to crash the kernel f
CVE-2026-68246 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() There's no need to crash the
CVE-2026-68115 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() There's no need to crash the
CVE-2026-68116 In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix source list corruption on a failed replace When replacing the s
CVE-2026-68117 In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() When tipc_sk
CVE-2026-68121 In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a po
CVE-2026-68124 In the Linux kernel, the following vulnerability has been resolved: mctp: serial: handle zero-length frames to prevent rx buffer overflow The MCTP
CVE-2026-68125 In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: reject frames shorter than the authentication tag llsec_do_de
CVE-2026-68126 In the Linux kernel, the following vulnerability has been resolved: mac802154: hold an interface reference across the scan worker mac802154_scan_wo
CVE-2026-68127 In the Linux kernel, the following vulnerability has been resolved: ila: reload IPv6 header after pskb_may_pull in checksum adjust ila_csum_adjust_
CVE-2026-68130 In the Linux kernel, the following vulnerability has been resolved: ksmbd: defer destroy_previous_session() until after NTLM authentication In ntlm
CVE-2026-68131 In the Linux kernel, the following vulnerability has been resolved: rbd: Reset positive result codes to zero in object map update path In a reply m
CVE-2026-68135 In the Linux kernel, the following vulnerability has been resolved: net: hip04: fix RX buffer leak on build_skb failure When build_skb() fails in h
CVE-2026-68137 In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free in x25_kill_by_neigh() x25_kill_by_neigh() walks th
CVE-2026-68140 In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix use-after-free of a severed iucv_path af_iucv queues not-yet-rece
CVE-2026-68141 In the Linux kernel, the following vulnerability has been resolved: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() afiucv_hs_callback_syn(
CVE-2026-68142 In the Linux kernel, the following vulnerability has been resolved: geneve: require CAP_NET_ADMIN in the device netns for changelink A tunnel chang
CVE-2026-68143 In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive against buffer reallocation sl_realloc_bufs() repl
CVE-2026-68432 In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns for changelink A tunnel change
CVE-2026-68144 In the Linux kernel, the following vulnerability has been resolved: phonet: pep: fix use-after-free in pep_get_sb() pep_get_sb() doesn't consider t
CVE-2026-68146 In the Linux kernel, the following vulnerability has been resolved: ftrace: Add global mutex to serialize trace_parser access In ftrace, the trace_
CVE-2026-68148 In the Linux kernel, the following vulnerability has been resolved: fscrypt: Add missing superblock check in find_or_insert_direct_key() The legacy
CVE-2026-68149 In the Linux kernel, the following vulnerability has been resolved: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() The ACL_DONT_CACHE sta
CVE-2026-68151 In the Linux kernel, the following vulnerability has been resolved: binfmt_elf_fdpic: only honour the first PT_INTERP The program header scan handl
CVE-2026-68153 In the Linux kernel, the following vulnerability has been resolved: libceph: remove debugfs files before client teardown ceph_destroy_client() tear
CVE-2026-68154 In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode CRUSH bucket type 0 is reserv
CVE-2026-68155 In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MO
CVE-2026-68156 In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_cre
CVE-2026-68157 In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH type name lookup Localized read selection can walk
CVE-2026-68158 In the Linux kernel, the following vulnerability has been resolved: libceph: Fix multiplication overflow in decode_new_up_state_weight() If a messa
CVE-2026-68433 In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front len handle_get_version_reply()
CVE-2026-68160 In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() ceph_h
CVE-2026-68175 In the Linux kernel, the following vulnerability has been resolved: tracing: Fix resource leak on mmiotrace trace_pipe close The mmiotrace tracer w
CVE-2026-68176 In the Linux kernel, the following vulnerability has been resolved: tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev If the mmio_pi
CVE-2026-68180 In the Linux kernel, the following vulnerability has been resolved: intel_th: fix MSC output device reference leak intel_th_output_open() looks up
CVE-2026-68181 In the Linux kernel, the following vulnerability has been resolved: mei: bus: access mei_device under device_lock on cleanup Fix couple of problems
CVE-2026-68182 In the Linux kernel, the following vulnerability has been resolved: comedi: comedi_parport: deal with premature interrupt Syzbot reported a general
CVE-2026-68184 In the Linux kernel, the following vulnerability has been resolved: cdrom: fix stack out-of-bounds read in CDROMVOLCTRL mmc_ioctl_cdrom_volume() fi
CVE-2026-68186 In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: set have_execfd only once the interpreter is opened load_misc_bina
CVE-2026-68187 In the Linux kernel, the following vulnerability has been resolved: exec: fix unsigned loop counter wrap in transfer_args_to_stack() The stop value
CVE-2026-68188 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() test
CVE-2026-68189 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Protect UUID list traversal The hci_sync conversion moved
CVE-2026-68190 In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() rtw_get_wps_ie() iterates
CVE-2026-68192 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: make release_scratchbuffers idempotent brcmf_pcie_release_scrat
CVE-2026-68194 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is
CVE-2026-68195 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is
CVE-2026-68196 In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: validate assoc response length before subtracting header wilc_p
CVE-2026-68197 In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper mwifi
CVE-2026-68199 In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB access from firmware ADDBA window size aggr_recv_addba_re
CVE-2026-68202 In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: close a re-opened queue timer in the destructor queue_delete() close
CVE-2026-68204 In the Linux kernel, the following vulnerability has been resolved: media: vivid: check for vb2_is_busy() when toggling caps The vivid_update_forma
CVE-2026-68206 In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC active reference counts HEVC slice parameters
CVE-2026-68207 In the Linux kernel, the following vulnerability has been resolved: media: ti: vpe: unwind v4l2 device registration on probe error If the vpe_top r
CVE-2026-68209 In the Linux kernel, the following vulnerability has been resolved: media: sun4i-csi: Return queued buffers on start_streaming() failure The vb2 fr
CVE-2026-68210 In the Linux kernel, the following vulnerability has been resolved: media: stm32: dcmi: unregister notifier on probe failure dcmi_graph_init() regi
CVE-2026-68212 In the Linux kernel, the following vulnerability has been resolved: media: saa7134: Fix a possible memory leak in saa7134_video_init1 In saa7134_vi
CVE-2026-68213 In the Linux kernel, the following vulnerability has been resolved: media: rtl2832_sdr: Return queued buffers on start_streaming() failure The vb2
CVE-2026-68214 In the Linux kernel, the following vulnerability has been resolved: media: rtl2832: fix use-after-free in rtl2832_remove() cancel_delayed_work_sync
CVE-2026-68215 In the Linux kernel, the following vulnerability has been resolved: media: radio-si476x: Unregister v4l2_device on probe failure si476x_radio_probe
CVE-2026-68216 In the Linux kernel, the following vulnerability has been resolved: media: pwc: Return queued buffers on start_streaming() failure The vb2 framewor
CVE-2026-68217 In the Linux kernel, the following vulnerability has been resolved: media: pwc: Drain fill_buf on start_streaming() failure pwc_isoc_init() submits
CVE-2026-68218 In the Linux kernel, the following vulnerability has been resolved: media: pci: dm1105: Free allocated workqueue Destroy allocated workqueue in rem
CVE-2026-68219 In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: Fix potential out-of-bounds issues The maximum downscalin
CVE-2026-68220 In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe Bo
CVE-2026-68222 In the Linux kernel, the following vulnerability has been resolved: media: msi2500: Return queued buffers on start_streaming() failure The vb2 fram
CVE-2026-68223 In the Linux kernel, the following vulnerability has been resolved: media: meson: vdec: Fix memory leak in error path of vdec_open The vdec_open()
CVE-2026-68226 In the Linux kernel, the following vulnerability has been resolved: media: cx23885: add ioremap return check and cleanup Add a check for the return
CVE-2026-68227 In the Linux kernel, the following vulnerability has been resolved: media: cx231xx: fix devres lifetime USB drivers bind to USB interfaces and any
CVE-2026-68229 In the Linux kernel, the following vulnerability has been resolved: media: cedrus: skip invalid H.264 reference list entries Cedrus consumes H.264
CVE-2026-68231 In the Linux kernel, the following vulnerability has been resolved: media: airspy: Return queued buffers on start_streaming() failure The vb2 frame
CVE-2026-68445 In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Prevent shader BO mappings from becoming writable vc4_gem_object_mmap(
CVE-2026-68446 In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate vmw_surface_metadata::array_size This field comes from use
CVE-2026-68234 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved amdgpu_bo_create_r
CVE-2026-68236 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: set new_stream to NULL after release In dm_update_crtc_state()
CVE-2026-68243 In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU Setting context engine
CVE-2026-68244 In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Do not leak siblings[] on proto context error After a successful
CVE-2026-68248 In the Linux kernel, the following vulnerability has been resolved: drm/i915: Return NULL on error in active_instance Avoid returning &node->base w
CVE-2026-68249 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() There's no need to crash th
CVE-2026-68250 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() There's no need to crash th
CVE-2026-68251 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() There's no need to crash th
CVE-2026-68255 In the Linux kernel, the following vulnerability has been resolved: drm/virtio: bound EDID block reads to the response buffer virtio_get_edid_block
CVE-2026-68256 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev
CVE-2026-68259 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds in allocate_event_notification_slot The valid event id
CVE-2026-68269 In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Add missing nospec on parallel submit slot Add missing Spectre mi
CVE-2026-68271 In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix reversed error cleanup order in ucopy functions nouveau_uvmm_v
CVE-2026-68272 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 Add a minimum-length
CVE-2026-68277 In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers Three side
CVE-2026-68278 In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix buffer overflows in sideband chunk accumulation drm_dp_sideband
CVE-2026-68279 In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers drm_dp_side
CVE-2026-68280 In the Linux kernel, the following vulnerability has been resolved: drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() The deprecated
CVE-2026-68284 In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() tcp_bpf_sendmsg() ke
CVE-2026-68294 In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial network namespace QRTR keeps
CVE-2026-68297 In the Linux kernel, the following vulnerability has been resolved: tipc: fix u16 MTU truncation in media and bearer MTU validation Both TIPC_NL_ME
CVE-2026-68299 In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr
CVE-2026-68300 In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_ver
CVE-2026-68301 In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix memory leak on slave unregistration by removing synced VLANs When
CVE-2026-68302 In the Linux kernel, the following vulnerability has been resolved: amt: re-read skb header pointers after every pull Several AMT receive and trans
CVE-2026-68304 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix 802.1X-SHA256 call trace warning Based on wpa_auth as 1x_25
CVE-2026-68306 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
CVE-2026-68308 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() mt76
CVE-2026-68309 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_h
CVE-2026-68310 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: guard HE capability lookups mt7915_mcu_bss_he_tlv() and mt7
CVE-2026-68313 In the Linux kernel, the following vulnerability has been resolved: tipc: fix infinite loop in __tipc_nl_compat_dumpit cmd->dumpit callback can ret
CVE-2026-64576 In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate() nh_res_bucket_migrate() p
CVE-2026-64577 In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() gtp1u_send_echo_res
CVE-2026-68315 In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a
CVE-2026-68317 In the Linux kernel, the following vulnerability has been resolved: pds_core: fix auxiliary device add/del races Two paths add or delete the same s
CVE-2026-68320 In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid sctp_auth_
CVE-2026-68324 In the Linux kernel, the following vulnerability has been resolved: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() dmar_latency_di
CVE-2026-68325 In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Bound the early ACPI HID map The ivrs_acpihid command-line parser ap
CVE-2026-68326 In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: bound uAP association event IEs to the event buffer mwifiex_proc
CVE-2026-68327 In the Linux kernel, the following vulnerability has been resolved: wan: wanxl: Only reset hardware after BAR mapping wanxl_pci_init_one() stores t
CVE-2026-68328 In the Linux kernel, the following vulnerability has been resolved: nfp: Check resource mutex allocation nfp_cpp_resource_find() allocates a CPP mu
CVE-2026-64574 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update error path When ieee80211_vif
CVE-2026-68329 In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Wait for completion instead of returning early in iommu_completion_wa
CVE-2026-68331 In the Linux kernel, the following vulnerability has been resolved: dpaa2-eth: put MAC endpoint device on disconnect fsl_mc_get_endpoint() returns
CVE-2026-68333 In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: put MAC endpoint device on disconnect fsl_mc_get_endpoint() retur
CVE-2026-68335 In the Linux kernel, the following vulnerability has been resolved: rds: drop incoming messages that cross network namespace boundaries rds_find_bo
CVE-2026-68336 In the Linux kernel, the following vulnerability has been resolved: bonding: fix devconf_all NULL dereference when IPv6 is disabled When booting wi
CVE-2026-68338 In the Linux kernel, the following vulnerability has been resolved: net/packet: avoid fanout hook re-registration after unregister packet_set_ring(
CVE-2026-68339 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: validate Realtek vendor event length btusb_recv_event_realtek
CVE-2026-68340 In the Linux kernel, the following vulnerability has been resolved: hwmon: occ: validate poll response sensor blocks The OCC poll response parser w
CVE-2026-68343 In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates
CVE-2026-68348 In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2781: bound firmware description string parsing The TAS2781 firmware p
CVE-2026-68450 In the Linux kernel, the following vulnerability has been resolved: btrfs: free mapping node on duplicate reloc root insert __add_reloc_root() allo
CVE-2026-68349 In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: fix buffer overflow in rx_stream failover path The failover con
CVE-2026-68350 In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: fix OOB read from off-by-two in TX status handler The bounds ch
CVE-2026-68351 In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read When th
CVE-2026-68352 In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event The firmwa
CVE-2026-68353 In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler The fir
CVE-2026-68354 In the Linux kernel, the following vulnerability has been resolved: firewire: net: Fix fragmented datagram reassembly fwnet_frag_new() keeps a sort
CVE-2026-68355 In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() W
CVE-2026-68357 In the Linux kernel, the following vulnerability has been resolved: watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() When a watchdog
CVE-2026-68359 In the Linux kernel, the following vulnerability has been resolved: hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop Calling hid_hw_s
CVE-2026-68360 In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop Calling hid_hw_
CVE-2026-68361 In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop hid_hw_stop() do
CVE-2026-68362 In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin In A
CVE-2026-68363 In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
CVE-2026-68365 In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_edgeport: cap received transmit credits The interrupt-status pa
CVE-2026-68366 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer uvc_send_re
CVE-2026-64583 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown The
CVE-2026-68368 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() When unpacking
CVE-2026-68369 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: printer: fix infinite loop in printer_read() printer_read() uses t
CVE-2026-64584 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before freeing the midi object The
CVE-2026-68370 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback dummy_hcd embeds
CVE-2026-68373 In the Linux kernel, the following vulnerability has been resolved: wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() at76_guess_freq
CVE-2026-64569 In the Linux kernel, the following vulnerability has been resolved: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n On CONFIG_IN
CVE-2026-68376 In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_hmacs array size in struct sctp_cookie The auth_hmacs array in s
CVE-2026-68377 In the Linux kernel, the following vulnerability has been resolved: net/sched: act_tunnel_key: Defer dst_release to RCU callback Fix a race-conditi
CVE-2026-64578 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before reading StructureSize2 When ksmbd
CVE-2026-68381 In the Linux kernel, the following vulnerability has been resolved: ksmbd: pin conn during async oplock break notification smb2_oplock_break_noti()
CVE-2026-68386 In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Reject unhashed UDP sockets on sockmap update UDP sockets get SOC
CVE-2026-68388 In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_falloc
CVE-2026-68389 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: Clear memdump state on invalid dump size qca_controller_mem
CVE-2026-68391 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Dereferencing
CVE-2026-68392 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync Dereferencing RCU
CVE-2026-64573 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NVM tag length underflow in TLV parser In the TLV_TYPE_NVM
CVE-2026-68449 In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning The h
CVE-2026-68395 In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
CVE-2026-68397 In the Linux kernel, the following vulnerability has been resolved: net/iucv: take a reference on the socket found in afiucv_hs_rcv() afiucv_hs_rcv
CVE-2026-64572 In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: free fib_alias with kfree_rcu() on insert error path fib_table_inser
CVE-2026-68398 In the Linux kernel, the following vulnerability has been resolved: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF pppol2tp_
CVE-2026-68402 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking non-inheritance cfg80211_is
CVE-2026-68403 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: initialize SDIO data work before cleanup brcmf_sdio_probe() sto
CVE-2026-68405 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock ieee80211_do_stop() r
CVE-2026-68406 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate PMSR FTM preamble range PMSR FTM request parsing accep
CVE-2026-68407 In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: free RNR data on MBSSID mismatch nl80211_parse_beacon() rejects
CVE-2026-64571 In the Linux kernel, the following vulnerability has been resolved: wifi: p54: validate RX frame length in p54_rx_eeprom_readback() p54_rx_eeprom_r
CVE-2026-68410 In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix memory leak in helper_firmware_cb() helper_firmware_cb() ne
CVE-2026-68411 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: clamp virtio RX length before skb_put hwsim_virtio_rx_wor
CVE-2026-68413 In the Linux kernel, the following vulnerability has been resolved: wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() The memory a
CVE-2026-68414 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel sched scan results work on unregister cfg80211_sched_sca
CVE-2026-64579 In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert xfrm_h
CVE-2026-64580 In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() On
CVE-2026-68416 In the Linux kernel, the following vulnerability has been resolved: mtd: fix double free and WARN_ON in add_mtd_device() error paths When device_re
CVE-2026-68417 In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: publish QP after initialization siw_create_qp() currently calls siw_q
CVE-2026-68419 In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Prevent rereg_mr for non-mem regions When a QP/CQ/SRQ is created, a
CVE-2026-68444 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() ffa_partiti
CVE-2026-68422 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() If
CVE-2026-64567 In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries than pages When loading a v1 f
CVE-2026-68425 In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reassembly Kernel-handled RMPP rec
CVE-2026-64565 In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() The `ims_pc
CVE-2026-68427 In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings __host1x_bo_
CVE-2026-72146 In the Linux kernel, the following vulnerability has been resolved: dmaengine: sh: rz-dmac: Move interrupt request after everything is set up Once
CVE-2026-72124 In the Linux kernel, the following vulnerability has been resolved: can: isotp: serialize TX state transitions under so->rx_lock The TX state machi
CVE-2026-72125 In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER isotp_rel
CVE-2026-72115 In the Linux kernel, the following vulnerability has been resolved: can: bcm: track a single source interface for ANYDEV timeout/throttle ops An AN
CVE-2026-72117 In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() For an rx op
CVE-2026-72116 In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix stale rx/tx ops after device removal RX: an RX_SETUP update(!) fo
CVE-2026-72113 In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing device refcount for CAN filter removal sashiko-bot remark
CVE-2026-72114 In the Linux kernel, the following vulnerability has been resolved: can: bcm: validate frame length in bcm_rx_setup() for RTR replies bcm_tx_setup(
CVE-2026-72119 In the Linux kernel, the following vulnerability has been resolved: can: bcm: extend bcm_tx_lock usage for data and timer updates Stage new CAN fra
CVE-2026-72118 In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix CAN frame rx/tx statistics KCSAN detected a data race within the
CVE-2026-72121 In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking when updating filter and timer values KCSAN detected a si
CVE-2026-68428 In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Fix use-after-free on vendor module reload mmu_destroy_caches() d
CVE-2026-64562 In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow
CVE-2026-64561 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Ch
CVE-2026-53090 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix ld_{abs,ind} failure path analysis in subprogs Usage of ld_{abs,ind} i
CVE-2026-64564 In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_a
CVE-2026-68399 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF in sock clone early bailouts Similar to recent commit 9b51a6155d14
CVE-2025-38563 In the Linux kernel, the following vulnerability has been resolved: perf/core: Prevent VMA split of buffer mappings The perf mmap code is careful a
CVE-2025-38565 In the Linux kernel, the following vulnerability has been resolved: perf/core: Exit early on perf_mmap() fail When perf_mmap() fails to allocate a
CVE-2025-38187 In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() The RPC container is r
CVE-2025-38069 In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: pci-epf-test: Fix double free that causes kernel to oops Fix a k
CVE-2025-40014 In the Linux kernel, the following vulnerability has been resolved: objtool, spi: amd: Fix out-of-bounds stack access in amd_set_spi_freq() If spee
CVE-2025-21985 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bound accesses [WHAT & HOW] hpo_stream_to_link_enco
CVE-2024-56552 In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc_submit: fix race around suspend_pending Currently in some testcases
CVE-2025-21687 In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are pas
CVE-2026-64560 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwo
CVE-2026-53365 In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb sends When a large message
CVE-2025-37964 In the Linux kernel, the following vulnerability has been resolved: x86/mm: Eliminate window where TLB flushes may be inadvertently skipped tl;dr:
CVE-2026-53389 In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: fix use-after-free of key in del_async path In tcp_ao_delete_key(),
CVE-2026-53393 In the Linux kernel, the following vulnerability has been resolved: nfsd: reset write verifier on deferred writeback errors nfsd_vfs_write() and nf
CVE-2026-53400 In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter registration race Adapters can be looked up based on the
CVE-2026-63806 In the Linux kernel, the following vulnerability has been resolved: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligne
CVE-2026-63940 In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length '0' Explicitly ignore Port I/O req
CVE-2026-53387 In the Linux kernel, the following vulnerability has been resolved: iio: light: veml6075: add bounds check to veml6075_it_ms index veml6075_it_ms h
CVE-2026-53070 In the Linux kernel, the following vulnerability has been resolved: sctp: disable BH before calling udp_tunnel_xmit_skb() udp_tunnel_xmit_skb() / u
CVE-2026-43216 In the Linux kernel, the following vulnerability has been resolved: net: Drop the lock in skb_may_tx_timestamp() skb_may_tx_timestamp() may acquire
CVE-2026-64244 In the Linux kernel, the following vulnerability has been resolved: drivers/base/memory: set mem->altmap after successful device registration If __
CVE-2026-53384 In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_p
CVE-2026-53390 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds read in smb_check_perm_dacl() The permission-check ACE
CVE-2026-53391 In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr nfs4_decode_mp_
CVE-2026-53397 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix posix_acl leak on SETACL decode failure nfsaclsvc_decode_setaclargs()
CVE-2026-53398 In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() c
CVE-2026-64245 In the Linux kernel, the following vulnerability has been resolved: fbdev: modedb: fix a possible UAF in fb_find_mode() If mode_option is NULL, it
CVE-2026-53403 In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var inf
CVE-2026-64246 In the Linux kernel, the following vulnerability has been resolved: power: reset: linkstation-poweroff: fix use-after-free in the linkstation_powero
CVE-2026-63794 In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path In sev_dbg_cryp
CVE-2026-64247 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: hyper-v: Bound the bank index when querying sparse banks When checkin
CVE-2026-63795 In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() i
CVE-2026-63796 In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject oversized group bitmap descriptors ocfs2_validate_gd_parent() onl
CVE-2026-63797 In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Fix use-after-free on probe error path rpmsg_chrdev_probe() stores
CVE-2026-64249 In the Linux kernel, the following vulnerability has been resolved: fpga: region: fix use-after-free in child_regions_with_firmware() Move of_node_
CVE-2026-63798 In the Linux kernel, the following vulnerability has been resolved: irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
CVE-2026-63800 In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RE
CVE-2026-63801 In the Linux kernel, the following vulnerability has been resolved: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done tipc_aead_decrypt(
CVE-2026-63802 In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix UAF in __blkcg_rstat_flush() When multiple blkgs in the same bl
CVE-2026-63803 In the Linux kernel, the following vulnerability has been resolved: hdlc_ppp: sync per-proto timers before freeing hdlc state Each PPP control prot
CVE-2026-63804 In the Linux kernel, the following vulnerability has been resolved: gfs2: fix use-after-free in gfs2_qd_dealloc gfs2_qd_dealloc(), called as an RCU
CVE-2026-63808 In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir
CVE-2026-63809 In the Linux kernel, the following vulnerability has been resolved: bpf: use kvfree() for replaced sysctl write buffer proc_sys_call_handler() allo
CVE-2026-63812 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() When __des
CVE-2026-63814 In the Linux kernel, the following vulnerability has been resolved: f2fs: validate ACL entry sizes in f2fs_acl_from_disk() f2fs_acl_count() only va
CVE-2026-63817 In the Linux kernel, the following vulnerability has been resolved: f2fs: validate compress cache inode only when enabled F2FS_COMPRESS_INO() uses
CVE-2026-63821 In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: usb: fix memory leaks on USB write failures When rtw_usb_write_por
CVE-2026-63822 In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix warning when unbinding If there is an error during some initi
CVE-2026-63823 In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key()
CVE-2026-63824 In the Linux kernel, the following vulnerability has been resolved: KEYS: fix overflow in keyctl_pkey_params_get_2() The length for the internal ou
CVE-2026-63826 In the Linux kernel, the following vulnerability has been resolved: fbdev: fix use-after-free in store_modes() store_modes() replaces a framebuffer
CVE-2026-64254 In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR W
CVE-2026-63827 In the Linux kernel, the following vulnerability has been resolved: apparmor: fix use-after-free in rawdata dedup loop aa_replace_profiles() walks
CVE-2026-63828 In the Linux kernel, the following vulnerability has been resolved: apparmor: mediate the implicit connect of TCP fast open sendmsg sendmsg()/sendt
CVE-2026-63830 In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms The sk_msg sg.copy bitmap is
CVE-2026-63831 In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: add skb_cow_data() before in-place crypto llsec_do_encrypt_un
CVE-2026-53361 In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that un
CVE-2026-63833 In the Linux kernel, the following vulnerability has been resolved: ntfs3: reject direct userspace writes to reserved $LX* xattrs NTFS3 uses $LXUID
CVE-2026-53366 In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), w
CVE-2026-53362 In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(),
CVE-2026-63834 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: restrict number of unacked list entries When the unacked_
CVE-2026-63835 In the Linux kernel, the following vulnerability has been resolved: batman-adv: v: prevent OGM aggregation on disabled hardif When an interface get
CVE-2026-63836 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd The cwnd is always MSS
CVE-2026-63807 In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level W
CVE-2026-53381 In the Linux kernel, the following vulnerability has been resolved: virtiofs: fix UAF on submount umount iput() called from fuse_release_end() can
CVE-2026-53382 In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si syzbot reported
CVE-2026-53383 In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject non-VALID session in compound request branch smb2_check_user_sess
CVE-2026-53385 In the Linux kernel, the following vulnerability has been resolved: vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write A K
CVE-2026-53388 In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before replacing page cache folio fuse_try_move_folio() u
CVE-2026-53157 In the Linux kernel, the following vulnerability has been resolved: net: phonet: free phonet_device after RCU grace period phonet_device_destroy()
CVE-2026-53163 In the Linux kernel, the following vulnerability has been resolved: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued syzbot trigge
CVE-2025-23131 In the Linux kernel, the following vulnerability has been resolved: dlm: prevent NPD when writing a positive value to event_done do_uevent returns
CVE-2026-46252 In the Linux kernel, the following vulnerability has been resolved: regulator: core: fix locking in regulator_resolve_supply() error path If late e
CVE-2026-52928 In the Linux kernel, the following vulnerability has been resolved: af_unix: Reject SIOCATMARK on non-stream sockets SIOCATMARK reports whether the
CVE-2026-43010 In the Linux kernel, the following vulnerability has been resolved: bpf: Reject sleepable kprobe_multi programs at attach time kprobe.multi program
CVE-2026-53325 In the Linux kernel, the following vulnerability has been resolved: agp/amd64: Fix broken error propagation in agp_amd64_probe() A NULL pointer der
CVE-2026-64188 In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() rmnet_dell
CVE-2026-64191 In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid length The I2C_SMBUS_I2C_BLO
CVE-2026-53327 In the Linux kernel, the following vulnerability has been resolved: debugobjects: Do not fill_pool() if pi_blocked_on On RT enabled kernels, fill_p
CVE-2026-52909 In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device. john1988 and Noam Rathaus
CVE-2026-53167 In the Linux kernel, the following vulnerability has been resolved: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios FUSE_NOTIFY_RETRIEVE must b

Version: 6.8.0-146.146 2026-09-03 22:08:20 UTC

 linux (6.8.0-146.146) noble; urgency=medium
 .
   * noble/linux: 6.8.0-146.146 -proposed tracker (LP: #2166353)
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] debian.master/dkms-versions -- update from kernel-versions
       (main/2026.08.31)
 .
   * Bluetooth fails to initialize due to a kernel NULL pointer error
     (LP: #2165873)
     - Bluetooth: btmtk: move btusb_mtk_[setup, shutdown] to btmtk.c
 .
   * Dell Precision fails to shutdown when HDMI display is connected (22.04
     HWE) (LP: #2164507)
     - drm/i915/vbt: Add fields dedicated_external and dyn_port_over_tc
     - drm/i915/display: Handle dedicated external ports in
       intel_encoder_is_tc()
 .
   * ice: E810 interface fails to initialize (ice_init_hw failed: -5) during
     NVM read (LP: #2163508)
     - ice: acquire NVM lock around each flash read
 .
   * [SRU] HPE: Fix for UBSAN array-index-out-of-bounds (LP: #2161004)
     - x86/platform/uv: Fix UBSAN array-index-out-of-bounds
 .
   * vfio_pci soft lockup on VM start while using PCIe passthrough
     (LP: #2089306)
     - SAUCE: Revert "vfio/pci: Use unmap_mapping_range()"
 .
   * Reboot machine with ext4 configured to data=journal could dump spurious
     call trace (LP: #2164716)
     - ext4: clear stale xarray tags on folios skipped during writeback
 .
   * [UBUNTU 22.04] s390/topology: Use zero-based numbering (LP: #2164516)
     - s390/topology: Use zero-based numbering for containing entities
 .
   * [HP][ZBook Power 16 G11] Laptop freezed after upgrading the BIOS
     (LP: #2132119)
     - PCI/ASPM: Avoid L0s for Realtek RTS525A
 .
   * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796)
     - netfilter: bitwise: rename some boolean operation functions
     - netfilter: bitwise: add support for doing AND, OR and XOR directly
     - drm/fbdev-helper: Set and clear VGA switcheroo client from fb_info
     - arm64: io: Rename ioremap_prot() to __ioremap_prot()
     - Disable -Wattribute-alias for clang-23 and newer
     - netfilter: xt_NFQUEUE: prefer raw_smp_processor_id
     - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c
     - pcnet32: stop holding device spin lock during napi_complete_done
     - net: Annotate sk->sk_write_space() for UDP SOCKMAP.
     - net: lan743x: permit VLAN-tagged packets up to configured MTU
     - net: fec: fix pinctrl default state restore order on resume
     - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame()
       extension handling
     - Bluetooth: MGMT: Fix backward compatibility with userspace
     - ptp: vclock: Switch from RCU to SRCU
     - octeontx2-af: npc: Fix CPT channel mask in npc_install_flow
     - vxlan: vnifilter: send notification on VNI add
     - vxlan: vnifilter: fix spurious notification on VNI update
     - ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp
     - time: Fix off-by-one in settimeofday() usec validation
     - tools/rv: Fix cleanup after failed trace setup
     - arm64: tlb: Allow XZR argument to TLBI ops
     - iomap: don't revert iov_iter on partially completed buffered writes
     - net/mlx4: avoid GCC 10 __bad_copy_from() false positive
     - r8152: handle the return value of usb_reset_device()
     - rds: mark snapshot pages dirty in rds_info_getsockopt()
     - net: mvpp2: Add metadata support for xdp mode
     - net: mvpp2: build skb from XDP-adjusted data on XDP_PASS
     - clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time
     - tracing/probes: Point the error offset correctly for eprobe argument
       error
     - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation
     - USB: serial: option: add usb-id for Dell Wireless DW5826e-m
     - ALSA: timer: Fix UAF at snd_timer_user_params()
     - drm/amd/display: Reject gpio_bitshift >= 32 in
       bios_parser_get_gpio_pin_info()
     - mm/damon/ops-common: call folio_test_lru() after folio_get()
     - ARM: socfpga: Fix OF node refcount leak in SMP setup
     - ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O
     - mptcp: fix retransmission loop when csum is enabled
     - mptcp: sockopt: check timestamping ret value
     - selftests: mptcp: add test for extra_subflows underflow on userspace PM
     - ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write
     - inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
     - pidfd: refuse access to tasks that have started exiting harder
     - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter
     - i2c: tegra: Fix NOIRQ suspend/resume
     - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK)
     - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard
     - net/mlx5: Reorder completion before putting command entry in
       cmd_work_handler
     - net: mv643xx: fix OF node refcount
     - octeontx2-af: fix memory leak in rvu_setup_hw_resources()
     - mmc: core: Fix host controller programming for fixed driver type
     - mmc: litex_mmc: Set mandatory idle clocks before CMD0
     - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC
     - mmc: sdhci: add signal voltage switch in sdhci_resume_host
     - slimbus: qcom-ngd-ctrl: fix OF node refcount
     - drm/amdgpu: restart the CS if some parts of the VM are still invalidated
     - fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
     - driver core: reject devices with unregistered buses
     - mm/hugetlb: avoid false positive lockdep assertion
     - soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get()
     - ipmi:ssif: Remove unnecessary indention
     - ipmi:ssif: NULL thread on error
     - selftests: mptcp: drop nanoseconds width specifier
     - tty: serial: samsung: use u32 for register interactions
     - RDMA/umem: fix kernel-doc warnings
     - RDMA: Move DMA block iterator logic into dedicated files
     - arm64: cputype: Add NVIDIA Olympus definitions
     - arm64: errata: Mitigate TLBI errata on Mic

Source diff to previous version
1786013 Packaging resync
2165873 Bluetooth fails to initialize due to a kernel NULL pointer error
2164507 Dell Precision fails to shutdown when HDMI display is connected (22.04 HWE)
2163508 ice: E810 interface fails to initialize (ice_init_hw failed: -5) during NVM read
2161004 [SRU] HPE: Fix for UBSAN array-index-out-of-bounds
2089306 vfio_pci soft lockup on VM start while using PCIe passthrough
2164716 Reboot machine with ext4 configured to data=journal could dump spurious call trace
2164516 [UBUNTU 22.04] s390/topology: Use zero-based numbering
2132119 [HP][ZBook Power 16 G11] Laptop freezed after upgrading the BIOS
2164796 Noble update: upstream stable patchset 2026-08-21
2161547 Noble update: upstream stable patchset 2026-07-22
CVE-2026-53132 In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unbounded skb queue virtio_transport_inc_rx_pkt() c
CVE-2026-53138 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS record-chain walk loops [Why & How] All record-cha
CVE-2026-53140 In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups v3d_rewrite_csd
CVE-2026-53332 In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd When the remo
CVE-2026-53156 In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix use-after-free bugs in error paths Fix several instances of er
CVE-2026-53202 In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix signed integer truncation in IPC receive Fix potential buffer o
CVE-2026-53205 In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds checks for firmware log indices Add validation that read
CVE-2026-53210 In the Linux kernel, the following vulnerability has been resolved: tee: shm: fix shm leak in register_shm_helper() register_shm_helper() allocates
CVE-2026-31663 In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after transport_finish NF_HOOK After async crypto comp
CVE-2026-53220 In the Linux kernel, the following vulnerability has been resolved: netfilter: revalidate bridge ports ebt_redirect_tg() dereferences br_port_get_r
CVE-2026-53229 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure In the XSK br
CVE-2026-46203 In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: fix unclocked access on unbind Make sure that the control
CVE-2026-63871 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls iso_conne
CVE-2026-53251 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync hci_get_r
CVE-2026-63869 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap Whe
CVE-2026-53261 In the Linux kernel, the following vulnerability has been resolved: devlink: Release nested relation on devlink free devlink relation state is norm
CVE-2026-53262 In the Linux kernel, the following vulnerability has been resolved: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() pppol2tp_ioctl()
CVE-2025-10263 Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Corte
CVE-2026-45850 In the Linux kernel, the following vulnerability has been resolved: ipvs: skip ipv6 extension headers for csum checks Protocol checksum validation
CVE-2026-53133 In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for block sizes >= 4G When the iommu is used the line
CVE-2026-52908 In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_REREG_ACC
CVE-2026-53199 In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf netvsc_copy_to_send_b
CVE-2026-53134 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_fib: fix stale stack leak via the OIFNAME register For NFT_FIB_R
CVE-2026-63883 In the Linux kernel, the following vulnerability has been resolved: serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ W
CVE-2026-64528 In the Linux kernel, the following vulnerability has been resolved: tty: serial: samsung: Remove redundant port lock acquisition in rx helpers Sash
CVE-2026-53329 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector_reserve() [Why & How] dal_v
CVE-2026-53135 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs [Why & How]
CVE-2026-53136 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size [Why & H
CVE-2026-53137 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size [Why & How] Du
CVE-2026-53143 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v
CVE-2026-53144 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix NULL dereference in get_queue_ids() When usr_queue_id_array is
CVE-2026-53331 In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock During the SSR/PDR dow
CVE-2026-53146 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to actual frame size tb_xdomain_copy()
CVE-2026-53147 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Validate XDomain request packet size before type cast tb_xdp_handl
CVE-2026-53148 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Clamp XDomain response data copy to allocation size tb_xdp_propert
CVE-2026-53149 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound root directory content to block size __tb_property_parse_dir
CVE-2026-53150 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Reject zero-length property entries in validator tb_property_entry
CVE-2026-52929 In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-stream state When ADD_OUT_STREAMS is d
CVE-2026-52917 In the Linux kernel, the following vulnerability has been resolved: sctp: diag: reject stale associations in dump_one path The SCTP exact sock_diag
CVE-2026-53154 In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: restore reservation on error in hugetlb folio copy paths Two sites
CVE-2026-53336 In the Linux kernel, the following vulnerability has been resolved: nvmem: layouts: onie-tlv: fix hang on unknown types The EEPROM on my board has
CVE-2026-53337 In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL pointer dereference in bond_do_ioctl() In bond_do_ioctl(
CVE-2026-53158 In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix NULL pointer dereference in rpmsg callback A NULL pointer de
CVE-2026-53159 In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA address corruption due to find_vma misuse fastrpc_get_ar
CVE-2026-53160 In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free race in fastrpc_map_create fastrpc_map_lookup
CVE-2026-53161 In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context There is
CVE-2026-52930 In the Linux kernel, the following vulnerability has been resolved: ipc/shm: serialize orphan cleanup with shm_nattch updates shm_destroy_orphaned(
CVE-2026-53339 In the Linux kernel, the following vulnerability has been resolved: i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() On all modern platf
CVE-2026-53168 In the Linux kernel, the following vulnerability has been resolved: fuse: reject fuse_notify() pagecache ops on directories The operations FUSE_NOT
CVE-2026-53177 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix NULL pointer dereference PCIe errors detected by a Root Port or Do
CVE-2026-53181 In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: fix sk_ack_backlog leak on failed handshake When vmci_transport_rec
CVE-2026-53182 In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject oversized EMA RNR lists nl80211_parse_rnr_elems() stores
CVE-2026-53183 In the Linux kernel, the following vulnerability has been resolved: mptcp: allow subflow rcv wnd to shrink In MPTCP connection, the `window` field
CVE-2026-63867 In the Linux kernel, the following vulnerability has been resolved: mptcp: close TOCTOU race while computing rcv_wnd The MPTCP output path access l
CVE-2026-53343 In the Linux kernel, the following vulnerability has been resolved: ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow Commit 44e9a3bb76
CVE-2026-53184 In the Linux kernel, the following vulnerability has been resolved: udp: clear skb->dev before running a sockmap verdict On the UDP receive path sk
CVE-2026-53185 In the Linux kernel, the following vulnerability has been resolved: zram: fix use-after-free in zram_bvec_write_partial() zram_read_page() picks th
CVE-2026-53190 In the Linux kernel, the following vulnerability has been resolved: drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
CVE-2026-53194 In the Linux kernel, the following vulnerability has been resolved: USB: serial: kl5kusb105: fix bulk-out buffer overflow klsi_105_prepare_write_bu
CVE-2026-53195 In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr()
CVE-2026-53196 In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() read
CVE-2026-52935 In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: do not reuse an in-progress partial send espintcp keeps a singl
CVE-2026-53198 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL A defer
CVE-2026-53356 In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset sg_page() returns struct pag
CVE-2026-53345 In the Linux kernel, the following vulnerability has been resolved: KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying When m
CVE-2026-53208 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig net/bluetooth/l2c
CVE-2026-53209 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend Existing a
CVE-2026-53213 In the Linux kernel, the following vulnerability has been resolved: drm/vc4: fix krealloc() memory leak Don't just overwrite the original pointer p
CVE-2026-53347 In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting are
CVE-2026-43116 In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference
CVE-2026-53214 In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix a potential NPD in cleanup_prefix_route() addrconf_get_prefix_route()
CVE-2026-53217 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: sync RX data at the hardware packet offset mvpp2 programs the RX qu
CVE-2026-53218 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag nft_exthdr_init
CVE-2026-52942 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set before dumping it The fallback p
CVE-2026-53219 In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: avoid leaking percpu counter pointers The native and compa
CVE-2026-53349 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destroy stale expectfn expectations on unregister NAT
CVE-2026-52939 In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
CVE-2026-53223 In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue skbs skb_is_err_queue() treats P
CVE-2026-53227 In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix possible kfree_skb of ERR_PTR After the patch in the "Fix
CVE-2026-53230 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list mlx5_query_ni
CVE-2026-52947 In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove In qrt
CVE-2026-53232 In the Linux kernel, the following vulnerability has been resolved: net: phy: clean the sfp upstream if phy probing fails Sashiko reported that we
CVE-2026-53236 In the Linux kernel, the following vulnerability has been resolved: tcp: restrict SO_ATTACH_FILTER to priv users This patch restricts the use of SO
CVE-2026-53350 In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing firmware controls In wm_adsp_
CVE-2026-53237 In the Linux kernel, the following vulnerability has been resolved: gpio: mvebu: fix NULL pointer dereference in suspend/resume mvebu_pwm_suspend()
CVE-2026-53238 In the Linux kernel, the following vulnerability has been resolved: netlabel: validate unlabeled address and mask attribute lengths netlbl_unlabel_
CVE-2026-53239 In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() Fix
CVE-2026-46320 In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects
CVE-2026-53242 In the Linux kernel, the following vulnerability has been resolved: ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
CVE-2026-53352 In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() When a mult
CVE-2026-53245 In the Linux kernel, the following vulnerability has been resolved: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr In mrp_pdu_p
CVE-2026-63870 In the Linux kernel, the following vulnerability has been resolved: ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() The aoe driver (
CVE-2026-53249 In the Linux kernel, the following vulnerability has been resolved: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options This patch restricts setting L
CVE-2026-53252 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix memory leak in error path of hci_alloc_dev() Early failures in B
CVE-2026-53253 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: reject short frames before parsing A BNEP peer can send a shor
CVE-2026-53254 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate skb length in MCC handlers The RFCOMM MCC handlers
CVE-2026-53255 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate advertising TLV before type checks tlv_data_is_valid(
CVE-2026-53256 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() rfcomm_get_sock
CVE-2026-63868 In the Linux kernel, the following vulnerability has been resolved: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr The receive-si
CVE-2026-53353 In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syzbot reported the warning [0]
CVE-2026-53263 In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix off-by-one in multicast context address compression The second mem
CVE-2026-53264 In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEW
CVE-2026-53265 In the Linux kernel, the following vulnerability has been resolved: dm cache policy smq: check allocation under invalidate lock commit 2d1f7b65f5de
CVE-2026-53266 In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target
CVE-2026-53267 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: bail out on template ct in get eval I noticed this issue whi
CVE-2026-53268 In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible out-of-bounds read When parsing fails af
CVE-2026-53269 In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: add mutex to guard hook reference counting As the synproxy
CVE-2026-53270 In the Linux kernel, the following vulnerability has been resolved: ipvs: clear the svc scheduler ptr early on edit ip_vs_edit_service() while unbi
CVE-2026-53273 In the Linux kernel, the following vulnerability has been resolved: tee: optee: prevent use-after-free when the client exits before the supplicant
CVE-2026-53274 In the Linux kernel, the following vulnerability has been resolved: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS A logic
CVE-2026-53275 In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix use-after-free when processing MLD queries When processing an
CVE-2026-52948 In the Linux kernel, the following vulnerability has been resolved: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl While fuzzing with Syzk
CVE-2026-63898 In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix memory corruption with small endpoint The driver ove
CVE-2026-52910 In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the s
CVE-2026-43311 In the Linux kernel, the following vulnerability has been resolved: soc/tegra: pmc: Fix unsafe generic_handle_irq() call Currently, when resuming f
CVE-2026-43240 In the Linux kernel, the following vulnerability has been resolved: x86/kexec: add a sanity check on previous kernel's ima kexec buffer When the se
CVE-2026-23346 In the Linux kernel, the following vulnerability has been resolved: arm64: io: Extract user memory type in ioremap_prot() The only caller of iorema
CVE-2025-68296 In the Linux kernel, the following vulnerability has been resolved: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup Protect vga_swi
CVE-2026-52944 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SP
CVE-2026-64006 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix dst corruption in same register operation For lshift
CVE-2026-43331 In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Disable KCOV instrumentation after load_segments() The load_segments
CVE-2026-52943 In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb_carve helpers pskb_carve_in
CVE-2026-53358 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_ch
CVE-2026-52923 In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysc
CVE-2025-68768 In the Linux kernel, the following vulnerability has been resolved: inet: frags: flush pending skbs in fqdir_pre_exit() We have been seeing occasio
CVE-2026-43303 In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: clear page->private in free_pages_prepare() Several subsystems (
CVE-2026-52934 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets batadv_tvlv_container_ogm_appen
CVE-2026-52913 In the Linux kernel, the following vulnerability has been resolved: batman-adv: v: stop OGMv2 on disabled interface When a batadv_hard_iface is dis
CVE-2026-46322 In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one() When build_skb() fails in
CVE-2026-46321 In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns
CVE-2026-52927 In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix OOB read in compat_mtw_from_user Luxiao Xu says: The
CVE-2026-43219 In the Linux kernel, the following vulnerability has been resolved: net: cpsw_new: Fix potential unregister of netdev that has not been registered y
CVE-2026-45930 In the Linux kernel, the following vulnerability has been resolved: net: mctp: ensure our nlmsg responses are initialised Syed Faraz Abrar (@farazs
CVE-2026-53080 In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_fw: fix NULL dereference of "old" filters before change() Like p
CVE-2026-53354 In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm CPUs A number of CPUs develo
CVE-2026-53355 In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is
CVE-2026-53186 In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received length srp_process_rsp() cop
CVE-2026-53216 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM p
CVE-2026-63888 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd(
CVE-2026-63886 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_co
CVE-2026-63887 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_
CVE-2026-63912 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast p
CVE-2026-63922 In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_
CVE-2026-63924 In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() ipv6_hop_jumbo() calls
CVE-2026-64091 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans The local TT based TVLV is g
CVE-2026-63984 In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() ipv6_rpl_srh_decomp
CVE-2026-63992 In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() In some
CVE-2026-63993 In the Linux kernel, the following vulnerability has been resolved: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() skb_tun
CVE-2026-63994 In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
CVE-2026-64000 In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervision frame handling Ensure the ent
CVE-2026-64007 In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ensure_writable synproxy_tstamp_a
CVE-2026-53221 In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() In vti6_tnl_lookup(
CVE-2026-53131 In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt

Version: 6.8.0-145.145 2026-09-02 03:08:21 UTC

 linux (6.8.0-145.145) noble; urgency=medium
 .
   * noble/linux: 6.8.0-145.145 -proposed tracker (LP: #2165981)
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] debian.master/dkms-versions -- update from kernel-versions
       (main/2026.08.31)
 .
   * Dell Precision fails to shutdown when HDMI display is connected (22.04
     HWE) (LP: #2164507)
     - drm/i915/vbt: Add fields dedicated_external and dyn_port_over_tc
     - drm/i915/display: Handle dedicated external ports in
       intel_encoder_is_tc()
 .
   * ice: E810 interface fails to initialize (ice_init_hw failed: -5) during
     NVM read (LP: #2163508)
     - ice: acquire NVM lock around each flash read
 .
   * [SRU] HPE: Fix for UBSAN array-index-out-of-bounds (LP: #2161004)
     - x86/platform/uv: Fix UBSAN array-index-out-of-bounds
 .
   * vfio_pci soft lockup on VM start while using PCIe passthrough
     (LP: #2089306)
     - SAUCE: Revert "vfio/pci: Use unmap_mapping_range()"
 .
   * Reboot machine with ext4 configured to data=journal could dump spurious
     call trace (LP: #2164716)
     - ext4: clear stale xarray tags on folios skipped during writeback
 .
   * [UBUNTU 22.04] s390/topology: Use zero-based numbering (LP: #2164516)
     - s390/topology: Use zero-based numbering for containing entities
 .
   * [HP][ZBook Power 16 G11] Laptop freezed after upgrading the BIOS
     (LP: #2132119)
     - PCI/ASPM: Avoid L0s for Realtek RTS525A
 .
   * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796)
     - netfilter: bitwise: rename some boolean operation functions
     - netfilter: bitwise: add support for doing AND, OR and XOR directly
     - drm/fbdev-helper: Set and clear VGA switcheroo client from fb_info
     - arm64: io: Rename ioremap_prot() to __ioremap_prot()
     - Disable -Wattribute-alias for clang-23 and newer
     - netfilter: xt_NFQUEUE: prefer raw_smp_processor_id
     - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c
     - pcnet32: stop holding device spin lock during napi_complete_done
     - net: Annotate sk->sk_write_space() for UDP SOCKMAP.
     - net: lan743x: permit VLAN-tagged packets up to configured MTU
     - net: fec: fix pinctrl default state restore order on resume
     - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame()
       extension handling
     - Bluetooth: MGMT: Fix backward compatibility with userspace
     - ptp: vclock: Switch from RCU to SRCU
     - octeontx2-af: npc: Fix CPT channel mask in npc_install_flow
     - vxlan: vnifilter: send notification on VNI add
     - vxlan: vnifilter: fix spurious notification on VNI update
     - ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp
     - time: Fix off-by-one in settimeofday() usec validation
     - tools/rv: Fix cleanup after failed trace setup
     - arm64: tlb: Allow XZR argument to TLBI ops
     - iomap: don't revert iov_iter on partially completed buffered writes
     - net/mlx4: avoid GCC 10 __bad_copy_from() false positive
     - r8152: handle the return value of usb_reset_device()
     - rds: mark snapshot pages dirty in rds_info_getsockopt()
     - net: mvpp2: Add metadata support for xdp mode
     - net: mvpp2: build skb from XDP-adjusted data on XDP_PASS
     - clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time
     - tracing/probes: Point the error offset correctly for eprobe argument
       error
     - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation
     - USB: serial: option: add usb-id for Dell Wireless DW5826e-m
     - ALSA: timer: Fix UAF at snd_timer_user_params()
     - drm/amd/display: Reject gpio_bitshift >= 32 in
       bios_parser_get_gpio_pin_info()
     - mm/damon/ops-common: call folio_test_lru() after folio_get()
     - ARM: socfpga: Fix OF node refcount leak in SMP setup
     - ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O
     - mptcp: fix retransmission loop when csum is enabled
     - mptcp: sockopt: check timestamping ret value
     - selftests: mptcp: add test for extra_subflows underflow on userspace PM
     - ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write
     - inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
     - pidfd: refuse access to tasks that have started exiting harder
     - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter
     - i2c: tegra: Fix NOIRQ suspend/resume
     - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK)
     - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard
     - net/mlx5: Reorder completion before putting command entry in
       cmd_work_handler
     - net: mv643xx: fix OF node refcount
     - octeontx2-af: fix memory leak in rvu_setup_hw_resources()
     - mmc: core: Fix host controller programming for fixed driver type
     - mmc: litex_mmc: Set mandatory idle clocks before CMD0
     - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC
     - mmc: sdhci: add signal voltage switch in sdhci_resume_host
     - slimbus: qcom-ngd-ctrl: fix OF node refcount
     - drm/amdgpu: restart the CS if some parts of the VM are still invalidated
     - fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
     - driver core: reject devices with unregistered buses
     - mm/hugetlb: avoid false positive lockdep assertion
     - soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get()
     - ipmi:ssif: Remove unnecessary indention
     - ipmi:ssif: NULL thread on error
     - selftests: mptcp: drop nanoseconds width specifier
     - tty: serial: samsung: use u32 for register interactions
     - RDMA/umem: fix kernel-doc warnings
     - RDMA: Move DMA block iterator logic into dedicated files
     - arm64: cputype: Add NVIDIA Olympus definitions
     - arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU
     - mptcp: add-addr: always drop other suboptions
     - mptcp: fix missing wakeups in edge scenarios
     - Revert "selftest/ptp:

Source diff to previous version
1786013 Packaging resync
2164507 Dell Precision fails to shutdown when HDMI display is connected (22.04 HWE)
2163508 ice: E810 interface fails to initialize (ice_init_hw failed: -5) during NVM read
2161004 [SRU] HPE: Fix for UBSAN array-index-out-of-bounds
2089306 vfio_pci soft lockup on VM start while using PCIe passthrough
2164716 Reboot machine with ext4 configured to data=journal could dump spurious call trace
2164516 [UBUNTU 22.04] s390/topology: Use zero-based numbering
2132119 [HP][ZBook Power 16 G11] Laptop freezed after upgrading the BIOS
2164796 Noble update: upstream stable patchset 2026-08-21
2161547 Noble update: upstream stable patchset 2026-07-22
CVE-2026-53132 In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unbounded skb queue virtio_transport_inc_rx_pkt() c
CVE-2026-53138 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS record-chain walk loops [Why & How] All record-cha
CVE-2026-53140 In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups v3d_rewrite_csd
CVE-2026-53332 In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd When the remo
CVE-2026-53156 In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix use-after-free bugs in error paths Fix several instances of er
CVE-2026-53202 In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix signed integer truncation in IPC receive Fix potential buffer o
CVE-2026-53205 In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds checks for firmware log indices Add validation that read
CVE-2026-53210 In the Linux kernel, the following vulnerability has been resolved: tee: shm: fix shm leak in register_shm_helper() register_shm_helper() allocates
CVE-2026-31663 In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after transport_finish NF_HOOK After async crypto comp
CVE-2026-53220 In the Linux kernel, the following vulnerability has been resolved: netfilter: revalidate bridge ports ebt_redirect_tg() dereferences br_port_get_r
CVE-2026-53229 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure In the XSK br
CVE-2026-46203 In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: fix unclocked access on unbind Make sure that the control
CVE-2026-63871 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls iso_conne
CVE-2026-53251 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync hci_get_r
CVE-2026-63869 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap Whe
CVE-2026-53261 In the Linux kernel, the following vulnerability has been resolved: devlink: Release nested relation on devlink free devlink relation state is norm
CVE-2026-53262 In the Linux kernel, the following vulnerability has been resolved: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() pppol2tp_ioctl()
CVE-2025-10263 Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Corte
CVE-2026-45850 In the Linux kernel, the following vulnerability has been resolved: ipvs: skip ipv6 extension headers for csum checks Protocol checksum validation
CVE-2026-53133 In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for block sizes >= 4G When the iommu is used the line
CVE-2026-52908 In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_REREG_ACC
CVE-2026-53199 In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf netvsc_copy_to_send_b
CVE-2026-53134 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_fib: fix stale stack leak via the OIFNAME register For NFT_FIB_R
CVE-2026-63883 In the Linux kernel, the following vulnerability has been resolved: serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ W
CVE-2026-64528 In the Linux kernel, the following vulnerability has been resolved: tty: serial: samsung: Remove redundant port lock acquisition in rx helpers Sash
CVE-2026-53329 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector_reserve() [Why & How] dal_v
CVE-2026-53135 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs [Why & How]
CVE-2026-53136 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size [Why & H
CVE-2026-53137 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size [Why & How] Du
CVE-2026-53143 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v
CVE-2026-53144 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix NULL dereference in get_queue_ids() When usr_queue_id_array is
CVE-2026-53331 In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock During the SSR/PDR dow
CVE-2026-53146 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to actual frame size tb_xdomain_copy()
CVE-2026-53147 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Validate XDomain request packet size before type cast tb_xdp_handl
CVE-2026-53148 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Clamp XDomain response data copy to allocation size tb_xdp_propert
CVE-2026-53149 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound root directory content to block size __tb_property_parse_dir
CVE-2026-53150 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Reject zero-length property entries in validator tb_property_entry
CVE-2026-52929 In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-stream state When ADD_OUT_STREAMS is d
CVE-2026-52917 In the Linux kernel, the following vulnerability has been resolved: sctp: diag: reject stale associations in dump_one path The SCTP exact sock_diag
CVE-2026-53154 In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: restore reservation on error in hugetlb folio copy paths Two sites
CVE-2026-53336 In the Linux kernel, the following vulnerability has been resolved: nvmem: layouts: onie-tlv: fix hang on unknown types The EEPROM on my board has
CVE-2026-53337 In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL pointer dereference in bond_do_ioctl() In bond_do_ioctl(
CVE-2026-53158 In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix NULL pointer dereference in rpmsg callback A NULL pointer de
CVE-2026-53159 In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA address corruption due to find_vma misuse fastrpc_get_ar
CVE-2026-53160 In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free race in fastrpc_map_create fastrpc_map_lookup
CVE-2026-53161 In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context There is
CVE-2026-52930 In the Linux kernel, the following vulnerability has been resolved: ipc/shm: serialize orphan cleanup with shm_nattch updates shm_destroy_orphaned(
CVE-2026-53339 In the Linux kernel, the following vulnerability has been resolved: i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() On all modern platf
CVE-2026-53168 In the Linux kernel, the following vulnerability has been resolved: fuse: reject fuse_notify() pagecache ops on directories The operations FUSE_NOT
CVE-2026-53177 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix NULL pointer dereference PCIe errors detected by a Root Port or Do
CVE-2026-53181 In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: fix sk_ack_backlog leak on failed handshake When vmci_transport_rec
CVE-2026-53182 In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject oversized EMA RNR lists nl80211_parse_rnr_elems() stores
CVE-2026-53183 In the Linux kernel, the following vulnerability has been resolved: mptcp: allow subflow rcv wnd to shrink In MPTCP connection, the `window` field
CVE-2026-63867 In the Linux kernel, the following vulnerability has been resolved: mptcp: close TOCTOU race while computing rcv_wnd The MPTCP output path access l
CVE-2026-53343 In the Linux kernel, the following vulnerability has been resolved: ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow Commit 44e9a3bb76
CVE-2026-53184 In the Linux kernel, the following vulnerability has been resolved: udp: clear skb->dev before running a sockmap verdict On the UDP receive path sk
CVE-2026-53185 In the Linux kernel, the following vulnerability has been resolved: zram: fix use-after-free in zram_bvec_write_partial() zram_read_page() picks th
CVE-2026-53190 In the Linux kernel, the following vulnerability has been resolved: drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
CVE-2026-53194 In the Linux kernel, the following vulnerability has been resolved: USB: serial: kl5kusb105: fix bulk-out buffer overflow klsi_105_prepare_write_bu
CVE-2026-53195 In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr()
CVE-2026-53196 In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() read
CVE-2026-52935 In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: do not reuse an in-progress partial send espintcp keeps a singl
CVE-2026-53198 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL A defer
CVE-2026-53356 In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset sg_page() returns struct pag
CVE-2026-53345 In the Linux kernel, the following vulnerability has been resolved: KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying When m
CVE-2026-53208 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig net/bluetooth/l2c
CVE-2026-53209 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend Existing a
CVE-2026-53213 In the Linux kernel, the following vulnerability has been resolved: drm/vc4: fix krealloc() memory leak Don't just overwrite the original pointer p
CVE-2026-53347 In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting are
CVE-2026-43116 In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference
CVE-2026-53214 In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix a potential NPD in cleanup_prefix_route() addrconf_get_prefix_route()
CVE-2026-53217 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: sync RX data at the hardware packet offset mvpp2 programs the RX qu
CVE-2026-53218 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag nft_exthdr_init
CVE-2026-52942 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set before dumping it The fallback p
CVE-2026-53219 In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: avoid leaking percpu counter pointers The native and compa
CVE-2026-53349 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destroy stale expectfn expectations on unregister NAT
CVE-2026-52939 In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
CVE-2026-53223 In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue skbs skb_is_err_queue() treats P
CVE-2026-53227 In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix possible kfree_skb of ERR_PTR After the patch in the "Fix
CVE-2026-53230 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list mlx5_query_ni
CVE-2026-52947 In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove In qrt
CVE-2026-53232 In the Linux kernel, the following vulnerability has been resolved: net: phy: clean the sfp upstream if phy probing fails Sashiko reported that we
CVE-2026-53236 In the Linux kernel, the following vulnerability has been resolved: tcp: restrict SO_ATTACH_FILTER to priv users This patch restricts the use of SO
CVE-2026-53350 In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing firmware controls In wm_adsp_
CVE-2026-53237 In the Linux kernel, the following vulnerability has been resolved: gpio: mvebu: fix NULL pointer dereference in suspend/resume mvebu_pwm_suspend()
CVE-2026-53238 In the Linux kernel, the following vulnerability has been resolved: netlabel: validate unlabeled address and mask attribute lengths netlbl_unlabel_
CVE-2026-53239 In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() Fix
CVE-2026-46320 In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects
CVE-2026-53242 In the Linux kernel, the following vulnerability has been resolved: ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
CVE-2026-53352 In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() When a mult
CVE-2026-53245 In the Linux kernel, the following vulnerability has been resolved: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr In mrp_pdu_p
CVE-2026-63870 In the Linux kernel, the following vulnerability has been resolved: ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() The aoe driver (
CVE-2026-53249 In the Linux kernel, the following vulnerability has been resolved: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options This patch restricts setting L
CVE-2026-53252 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix memory leak in error path of hci_alloc_dev() Early failures in B
CVE-2026-53253 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: reject short frames before parsing A BNEP peer can send a shor
CVE-2026-53254 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate skb length in MCC handlers The RFCOMM MCC handlers
CVE-2026-53255 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate advertising TLV before type checks tlv_data_is_valid(
CVE-2026-53256 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() rfcomm_get_sock
CVE-2026-63868 In the Linux kernel, the following vulnerability has been resolved: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr The receive-si
CVE-2026-53353 In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syzbot reported the warning [0]
CVE-2026-53263 In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix off-by-one in multicast context address compression The second mem
CVE-2026-53264 In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEW
CVE-2026-53265 In the Linux kernel, the following vulnerability has been resolved: dm cache policy smq: check allocation under invalidate lock commit 2d1f7b65f5de
CVE-2026-53266 In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target
CVE-2026-53267 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: bail out on template ct in get eval I noticed this issue whi
CVE-2026-53268 In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible out-of-bounds read When parsing fails af
CVE-2026-53269 In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: add mutex to guard hook reference counting As the synproxy
CVE-2026-53270 In the Linux kernel, the following vulnerability has been resolved: ipvs: clear the svc scheduler ptr early on edit ip_vs_edit_service() while unbi
CVE-2026-53273 In the Linux kernel, the following vulnerability has been resolved: tee: optee: prevent use-after-free when the client exits before the supplicant
CVE-2026-53274 In the Linux kernel, the following vulnerability has been resolved: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS A logic
CVE-2026-53275 In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix use-after-free when processing MLD queries When processing an
CVE-2026-52948 In the Linux kernel, the following vulnerability has been resolved: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl While fuzzing with Syzk
CVE-2026-63898 In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix memory corruption with small endpoint The driver ove
CVE-2026-52910 In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the s
CVE-2026-43311 In the Linux kernel, the following vulnerability has been resolved: soc/tegra: pmc: Fix unsafe generic_handle_irq() call Currently, when resuming f
CVE-2026-43240 In the Linux kernel, the following vulnerability has been resolved: x86/kexec: add a sanity check on previous kernel's ima kexec buffer When the se
CVE-2026-23346 In the Linux kernel, the following vulnerability has been resolved: arm64: io: Extract user memory type in ioremap_prot() The only caller of iorema
CVE-2025-68296 In the Linux kernel, the following vulnerability has been resolved: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup Protect vga_swi
CVE-2026-52944 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SP
CVE-2026-64006 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix dst corruption in same register operation For lshift
CVE-2026-43331 In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Disable KCOV instrumentation after load_segments() The load_segments
CVE-2026-52943 In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb_carve helpers pskb_carve_in
CVE-2026-53358 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_ch
CVE-2026-52923 In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysc
CVE-2025-68768 In the Linux kernel, the following vulnerability has been resolved: inet: frags: flush pending skbs in fqdir_pre_exit() We have been seeing occasio
CVE-2026-43303 In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: clear page->private in free_pages_prepare() Several subsystems (
CVE-2026-52934 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets batadv_tvlv_container_ogm_appen
CVE-2026-52913 In the Linux kernel, the following vulnerability has been resolved: batman-adv: v: stop OGMv2 on disabled interface When a batadv_hard_iface is dis
CVE-2026-46322 In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one() When build_skb() fails in
CVE-2026-46321 In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns
CVE-2026-52927 In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix OOB read in compat_mtw_from_user Luxiao Xu says: The
CVE-2026-43219 In the Linux kernel, the following vulnerability has been resolved: net: cpsw_new: Fix potential unregister of netdev that has not been registered y
CVE-2026-45930 In the Linux kernel, the following vulnerability has been resolved: net: mctp: ensure our nlmsg responses are initialised Syed Faraz Abrar (@farazs
CVE-2026-53080 In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_fw: fix NULL dereference of "old" filters before change() Like p
CVE-2026-53354 In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm CPUs A number of CPUs develo
CVE-2026-53355 In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is
CVE-2026-53186 In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received length srp_process_rsp() cop
CVE-2026-53216 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM p
CVE-2026-63888 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd(
CVE-2026-63886 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_co
CVE-2026-63887 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_
CVE-2026-63912 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast p
CVE-2026-63922 In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_
CVE-2026-63924 In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() ipv6_hop_jumbo() calls
CVE-2026-64091 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans The local TT based TVLV is g
CVE-2026-63984 In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() ipv6_rpl_srh_decomp
CVE-2026-63992 In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() In some
CVE-2026-63993 In the Linux kernel, the following vulnerability has been resolved: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() skb_tun
CVE-2026-63994 In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
CVE-2026-64000 In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervision frame handling Ensure the ent
CVE-2026-64007 In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ensure_writable synproxy_tstamp_a
CVE-2026-53221 In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() In vti6_tnl_lookup(
CVE-2026-53131 In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt

Version: 6.8.0-141.141 2026-08-29 11:08:26 UTC

 linux (6.8.0-141.141) noble; urgency=medium
 .
   * noble/linux: 6.8.0-141.141 -proposed tracker (LP: #2165542)
 .
   * Dell Precision fails to shutdown when HDMI display is connected (22.04
     HWE) (LP: #2164507)
     - drm/i915/vbt: Add fields dedicated_external and dyn_port_over_tc
     - drm/i915/display: Handle dedicated external ports in
       intel_encoder_is_tc()
 .
   * ice: E810 interface fails to initialize (ice_init_hw failed: -5) during
     NVM read (LP: #2163508)
     - ice: acquire NVM lock around each flash read
 .
   * [SRU] HPE: Fix for UBSAN array-index-out-of-bounds (LP: #2161004)
     - x86/platform/uv: Fix UBSAN array-index-out-of-bounds
 .
   * vfio_pci soft lockup on VM start while using PCIe passthrough
     (LP: #2089306)
     - SAUCE: Revert "vfio/pci: Use unmap_mapping_range()"
 .
   * Reboot machine with ext4 configured to data=journal could dump spurious
     call trace (LP: #2164716)
     - ext4: clear stale xarray tags on folios skipped during writeback
 .
   * [UBUNTU 22.04] s390/topology: Use zero-based numbering (LP: #2164516)
     - s390/topology: Use zero-based numbering for containing entities
 .
   * [HP][ZBook Power 16 G11] Laptop freezed after upgrading the BIOS
     (LP: #2132119)
     - PCI/ASPM: Avoid L0s for Realtek RTS525A
 .
   * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796)
     - netfilter: bitwise: rename some boolean operation functions
     - netfilter: bitwise: add support for doing AND, OR and XOR directly
     - drm/fbdev-helper: Set and clear VGA switcheroo client from fb_info
     - arm64: io: Rename ioremap_prot() to __ioremap_prot()
     - Disable -Wattribute-alias for clang-23 and newer
     - netfilter: xt_NFQUEUE: prefer raw_smp_processor_id
     - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c
     - pcnet32: stop holding device spin lock during napi_complete_done
     - net: Annotate sk->sk_write_space() for UDP SOCKMAP.
     - net: lan743x: permit VLAN-tagged packets up to configured MTU
     - net: fec: fix pinctrl default state restore order on resume
     - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame()
       extension handling
     - Bluetooth: MGMT: Fix backward compatibility with userspace
     - ptp: vclock: Switch from RCU to SRCU
     - octeontx2-af: npc: Fix CPT channel mask in npc_install_flow
     - vxlan: vnifilter: send notification on VNI add
     - vxlan: vnifilter: fix spurious notification on VNI update
     - ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp
     - time: Fix off-by-one in settimeofday() usec validation
     - tools/rv: Fix cleanup after failed trace setup
     - arm64: tlb: Allow XZR argument to TLBI ops
     - iomap: don't revert iov_iter on partially completed buffered writes
     - net/mlx4: avoid GCC 10 __bad_copy_from() false positive
     - r8152: handle the return value of usb_reset_device()
     - rds: mark snapshot pages dirty in rds_info_getsockopt()
     - net: mvpp2: Add metadata support for xdp mode
     - net: mvpp2: build skb from XDP-adjusted data on XDP_PASS
     - clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time
     - tracing/probes: Point the error offset correctly for eprobe argument
       error
     - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation
     - USB: serial: option: add usb-id for Dell Wireless DW5826e-m
     - ALSA: timer: Fix UAF at snd_timer_user_params()
     - drm/amd/display: Reject gpio_bitshift >= 32 in
       bios_parser_get_gpio_pin_info()
     - mm/damon/ops-common: call folio_test_lru() after folio_get()
     - ARM: socfpga: Fix OF node refcount leak in SMP setup
     - ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O
     - mptcp: fix retransmission loop when csum is enabled
     - mptcp: sockopt: check timestamping ret value
     - selftests: mptcp: add test for extra_subflows underflow on userspace PM
     - ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write
     - inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
     - pidfd: refuse access to tasks that have started exiting harder
     - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter
     - i2c: tegra: Fix NOIRQ suspend/resume
     - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK)
     - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard
     - net/mlx5: Reorder completion before putting command entry in
       cmd_work_handler
     - net: mv643xx: fix OF node refcount
     - octeontx2-af: fix memory leak in rvu_setup_hw_resources()
     - mmc: core: Fix host controller programming for fixed driver type
     - mmc: litex_mmc: Set mandatory idle clocks before CMD0
     - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC
     - mmc: sdhci: add signal voltage switch in sdhci_resume_host
     - slimbus: qcom-ngd-ctrl: fix OF node refcount
     - drm/amdgpu: restart the CS if some parts of the VM are still invalidated
     - fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
     - driver core: reject devices with unregistered buses
     - mm/hugetlb: avoid false positive lockdep assertion
     - soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get()
     - ipmi:ssif: Remove unnecessary indention
     - ipmi:ssif: NULL thread on error
     - selftests: mptcp: drop nanoseconds width specifier
     - tty: serial: samsung: use u32 for register interactions
     - RDMA/umem: fix kernel-doc warnings
     - RDMA: Move DMA block iterator logic into dedicated files
     - arm64: cputype: Add NVIDIA Olympus definitions
     - arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU
     - mptcp: add-addr: always drop other suboptions
     - mptcp: fix missing wakeups in edge scenarios
     - Revert "selftest/ptp: update ptp selftest to exercise the gettimex
       options"
     - ARM: fix hash_name() fault
     - wifi: remove zero-length arrays
     - so

Source diff to previous version
2164507 Dell Precision fails to shutdown when HDMI display is connected (22.04 HWE)
2163508 ice: E810 interface fails to initialize (ice_init_hw failed: -5) during NVM read
2161004 [SRU] HPE: Fix for UBSAN array-index-out-of-bounds
2089306 vfio_pci soft lockup on VM start while using PCIe passthrough
2164716 Reboot machine with ext4 configured to data=journal could dump spurious call trace
2164516 [UBUNTU 22.04] s390/topology: Use zero-based numbering
2132119 [HP][ZBook Power 16 G11] Laptop freezed after upgrading the BIOS
2164796 Noble update: upstream stable patchset 2026-08-21
2161547 Noble update: upstream stable patchset 2026-07-22
CVE-2026-53132 In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unbounded skb queue virtio_transport_inc_rx_pkt() c
CVE-2026-53138 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS record-chain walk loops [Why & How] All record-cha
CVE-2026-53140 In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups v3d_rewrite_csd
CVE-2026-53332 In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd When the remo
CVE-2026-53156 In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix use-after-free bugs in error paths Fix several instances of er
CVE-2026-53202 In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix signed integer truncation in IPC receive Fix potential buffer o
CVE-2026-53205 In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds checks for firmware log indices Add validation that read
CVE-2026-53210 In the Linux kernel, the following vulnerability has been resolved: tee: shm: fix shm leak in register_shm_helper() register_shm_helper() allocates
CVE-2026-31663 In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after transport_finish NF_HOOK After async crypto comp
CVE-2026-53220 In the Linux kernel, the following vulnerability has been resolved: netfilter: revalidate bridge ports ebt_redirect_tg() dereferences br_port_get_r
CVE-2026-53229 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure In the XSK br
CVE-2026-46203 In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: fix unclocked access on unbind Make sure that the control
CVE-2026-63871 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls iso_conne
CVE-2026-53251 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync hci_get_r
CVE-2026-63869 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap Whe
CVE-2026-53261 In the Linux kernel, the following vulnerability has been resolved: devlink: Release nested relation on devlink free devlink relation state is norm
CVE-2026-53262 In the Linux kernel, the following vulnerability has been resolved: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() pppol2tp_ioctl()
CVE-2025-10263 Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Corte
CVE-2026-45850 In the Linux kernel, the following vulnerability has been resolved: ipvs: skip ipv6 extension headers for csum checks Protocol checksum validation
CVE-2026-53133 In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for block sizes >= 4G When the iommu is used the line
CVE-2026-52908 In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_REREG_ACC
CVE-2026-53199 In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf netvsc_copy_to_send_b
CVE-2026-53134 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_fib: fix stale stack leak via the OIFNAME register For NFT_FIB_R
CVE-2026-63883 In the Linux kernel, the following vulnerability has been resolved: serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ W
CVE-2026-64528 In the Linux kernel, the following vulnerability has been resolved: tty: serial: samsung: Remove redundant port lock acquisition in rx helpers Sash
CVE-2026-53329 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector_reserve() [Why & How] dal_v
CVE-2026-53135 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs [Why & How]
CVE-2026-53136 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size [Why & H
CVE-2026-53137 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size [Why & How] Du
CVE-2026-53143 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v
CVE-2026-53144 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix NULL dereference in get_queue_ids() When usr_queue_id_array is
CVE-2026-53331 In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock During the SSR/PDR dow
CVE-2026-53146 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to actual frame size tb_xdomain_copy()
CVE-2026-53147 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Validate XDomain request packet size before type cast tb_xdp_handl
CVE-2026-53148 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Clamp XDomain response data copy to allocation size tb_xdp_propert
CVE-2026-53149 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound root directory content to block size __tb_property_parse_dir
CVE-2026-53150 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Reject zero-length property entries in validator tb_property_entry
CVE-2026-52929 In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-stream state When ADD_OUT_STREAMS is d
CVE-2026-52917 In the Linux kernel, the following vulnerability has been resolved: sctp: diag: reject stale associations in dump_one path The SCTP exact sock_diag
CVE-2026-53154 In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: restore reservation on error in hugetlb folio copy paths Two sites
CVE-2026-53336 In the Linux kernel, the following vulnerability has been resolved: nvmem: layouts: onie-tlv: fix hang on unknown types The EEPROM on my board has
CVE-2026-53337 In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL pointer dereference in bond_do_ioctl() In bond_do_ioctl(
CVE-2026-53158 In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix NULL pointer dereference in rpmsg callback A NULL pointer de
CVE-2026-53159 In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA address corruption due to find_vma misuse fastrpc_get_ar
CVE-2026-53160 In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free race in fastrpc_map_create fastrpc_map_lookup
CVE-2026-53161 In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context There is
CVE-2026-52930 In the Linux kernel, the following vulnerability has been resolved: ipc/shm: serialize orphan cleanup with shm_nattch updates shm_destroy_orphaned(
CVE-2026-53339 In the Linux kernel, the following vulnerability has been resolved: i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() On all modern platf
CVE-2026-53168 In the Linux kernel, the following vulnerability has been resolved: fuse: reject fuse_notify() pagecache ops on directories The operations FUSE_NOT
CVE-2026-53177 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix NULL pointer dereference PCIe errors detected by a Root Port or Do
CVE-2026-53181 In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: fix sk_ack_backlog leak on failed handshake When vmci_transport_rec
CVE-2026-53182 In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject oversized EMA RNR lists nl80211_parse_rnr_elems() stores
CVE-2026-53183 In the Linux kernel, the following vulnerability has been resolved: mptcp: allow subflow rcv wnd to shrink In MPTCP connection, the `window` field
CVE-2026-63867 In the Linux kernel, the following vulnerability has been resolved: mptcp: close TOCTOU race while computing rcv_wnd The MPTCP output path access l
CVE-2026-53343 In the Linux kernel, the following vulnerability has been resolved: ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow Commit 44e9a3bb76
CVE-2026-53184 In the Linux kernel, the following vulnerability has been resolved: udp: clear skb->dev before running a sockmap verdict On the UDP receive path sk
CVE-2026-53185 In the Linux kernel, the following vulnerability has been resolved: zram: fix use-after-free in zram_bvec_write_partial() zram_read_page() picks th
CVE-2026-53190 In the Linux kernel, the following vulnerability has been resolved: drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
CVE-2026-53194 In the Linux kernel, the following vulnerability has been resolved: USB: serial: kl5kusb105: fix bulk-out buffer overflow klsi_105_prepare_write_bu
CVE-2026-53195 In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr()
CVE-2026-53196 In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() read
CVE-2026-52935 In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: do not reuse an in-progress partial send espintcp keeps a singl
CVE-2026-53198 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL A defer
CVE-2026-53356 In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset sg_page() returns struct pag
CVE-2026-53345 In the Linux kernel, the following vulnerability has been resolved: KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying When m
CVE-2026-53208 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig net/bluetooth/l2c
CVE-2026-53209 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend Existing a
CVE-2026-53213 In the Linux kernel, the following vulnerability has been resolved: drm/vc4: fix krealloc() memory leak Don't just overwrite the original pointer p
CVE-2026-53347 In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting are
CVE-2026-43116 In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference
CVE-2026-53214 In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix a potential NPD in cleanup_prefix_route() addrconf_get_prefix_route()
CVE-2026-53217 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: sync RX data at the hardware packet offset mvpp2 programs the RX qu
CVE-2026-53218 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag nft_exthdr_init
CVE-2026-52942 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set before dumping it The fallback p
CVE-2026-53219 In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: avoid leaking percpu counter pointers The native and compa
CVE-2026-53349 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destroy stale expectfn expectations on unregister NAT
CVE-2026-52939 In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
CVE-2026-53223 In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue skbs skb_is_err_queue() treats P
CVE-2026-53227 In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix possible kfree_skb of ERR_PTR After the patch in the "Fix
CVE-2026-53230 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list mlx5_query_ni
CVE-2026-52947 In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove In qrt
CVE-2026-53232 In the Linux kernel, the following vulnerability has been resolved: net: phy: clean the sfp upstream if phy probing fails Sashiko reported that we
CVE-2026-53236 In the Linux kernel, the following vulnerability has been resolved: tcp: restrict SO_ATTACH_FILTER to priv users This patch restricts the use of SO
CVE-2026-53350 In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing firmware controls In wm_adsp_
CVE-2026-53237 In the Linux kernel, the following vulnerability has been resolved: gpio: mvebu: fix NULL pointer dereference in suspend/resume mvebu_pwm_suspend()
CVE-2026-53238 In the Linux kernel, the following vulnerability has been resolved: netlabel: validate unlabeled address and mask attribute lengths netlbl_unlabel_
CVE-2026-53239 In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() Fix
CVE-2026-46320 In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects
CVE-2026-53242 In the Linux kernel, the following vulnerability has been resolved: ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
CVE-2026-53352 In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() When a mult
CVE-2026-53245 In the Linux kernel, the following vulnerability has been resolved: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr In mrp_pdu_p
CVE-2026-63870 In the Linux kernel, the following vulnerability has been resolved: ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() The aoe driver (
CVE-2026-53249 In the Linux kernel, the following vulnerability has been resolved: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options This patch restricts setting L
CVE-2026-53252 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix memory leak in error path of hci_alloc_dev() Early failures in B
CVE-2026-53253 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: reject short frames before parsing A BNEP peer can send a shor
CVE-2026-53254 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate skb length in MCC handlers The RFCOMM MCC handlers
CVE-2026-53255 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate advertising TLV before type checks tlv_data_is_valid(
CVE-2026-53256 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() rfcomm_get_sock
CVE-2026-63868 In the Linux kernel, the following vulnerability has been resolved: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr The receive-si
CVE-2026-53353 In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syzbot reported the warning [0]
CVE-2026-53263 In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix off-by-one in multicast context address compression The second mem
CVE-2026-53264 In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEW
CVE-2026-53265 In the Linux kernel, the following vulnerability has been resolved: dm cache policy smq: check allocation under invalidate lock commit 2d1f7b65f5de
CVE-2026-53266 In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target
CVE-2026-53267 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: bail out on template ct in get eval I noticed this issue whi
CVE-2026-53268 In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible out-of-bounds read When parsing fails af
CVE-2026-53269 In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: add mutex to guard hook reference counting As the synproxy
CVE-2026-53270 In the Linux kernel, the following vulnerability has been resolved: ipvs: clear the svc scheduler ptr early on edit ip_vs_edit_service() while unbi
CVE-2026-53273 In the Linux kernel, the following vulnerability has been resolved: tee: optee: prevent use-after-free when the client exits before the supplicant
CVE-2026-53274 In the Linux kernel, the following vulnerability has been resolved: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS A logic
CVE-2026-53275 In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix use-after-free when processing MLD queries When processing an
CVE-2026-52948 In the Linux kernel, the following vulnerability has been resolved: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl While fuzzing with Syzk
CVE-2026-63898 In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix memory corruption with small endpoint The driver ove
CVE-2026-52910 In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the s
CVE-2026-43311 In the Linux kernel, the following vulnerability has been resolved: soc/tegra: pmc: Fix unsafe generic_handle_irq() call Currently, when resuming f
CVE-2026-43240 In the Linux kernel, the following vulnerability has been resolved: x86/kexec: add a sanity check on previous kernel's ima kexec buffer When the se
CVE-2026-23346 In the Linux kernel, the following vulnerability has been resolved: arm64: io: Extract user memory type in ioremap_prot() The only caller of iorema
CVE-2025-68296 In the Linux kernel, the following vulnerability has been resolved: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup Protect vga_swi
CVE-2026-52944 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SP
CVE-2026-64006 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix dst corruption in same register operation For lshift
CVE-2026-43331 In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Disable KCOV instrumentation after load_segments() The load_segments
CVE-2026-52943 In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb_carve helpers pskb_carve_in
CVE-2026-53358 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_ch
CVE-2026-52923 In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysc
CVE-2025-68768 In the Linux kernel, the following vulnerability has been resolved: inet: frags: flush pending skbs in fqdir_pre_exit() We have been seeing occasio
CVE-2026-43303 In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: clear page->private in free_pages_prepare() Several subsystems (
CVE-2026-52934 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets batadv_tvlv_container_ogm_appen
CVE-2026-52913 In the Linux kernel, the following vulnerability has been resolved: batman-adv: v: stop OGMv2 on disabled interface When a batadv_hard_iface is dis
CVE-2026-46322 In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one() When build_skb() fails in
CVE-2026-46321 In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns
CVE-2026-52927 In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix OOB read in compat_mtw_from_user Luxiao Xu says: The
CVE-2026-43219 In the Linux kernel, the following vulnerability has been resolved: net: cpsw_new: Fix potential unregister of netdev that has not been registered y
CVE-2026-45930 In the Linux kernel, the following vulnerability has been resolved: net: mctp: ensure our nlmsg responses are initialised Syed Faraz Abrar (@farazs
CVE-2026-53080 In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_fw: fix NULL dereference of "old" filters before change() Like p
CVE-2026-53354 In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm CPUs A number of CPUs develo
CVE-2026-53355 In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is
CVE-2026-53186 In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received length srp_process_rsp() cop
CVE-2026-53216 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM p
CVE-2026-63888 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd(
CVE-2026-63886 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_co
CVE-2026-63887 In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_
CVE-2026-63912 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast p
CVE-2026-63922 In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_
CVE-2026-63924 In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() ipv6_hop_jumbo() calls
CVE-2026-64091 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans The local TT based TVLV is g
CVE-2026-63984 In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() ipv6_rpl_srh_decomp
CVE-2026-63992 In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() In some
CVE-2026-63993 In the Linux kernel, the following vulnerability has been resolved: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() skb_tun
CVE-2026-63994 In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
CVE-2026-64000 In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervision frame handling Ensure the ent
CVE-2026-64007 In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ensure_writable synproxy_tstamp_a
CVE-2026-53221 In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() In vti6_tnl_lookup(
CVE-2026-53131 In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt

Version: 6.8.0-139.139 2026-08-01 06:10:14 UTC

 linux (6.8.0-139.139) noble; urgency=medium
 .
   * noble/linux: 6.8.0-139.139 -proposed tracker (LP: #2162466)
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] update annotations scripts
     - [Packaging] debian.master/dkms-versions -- update from kernel-versions
       (main/2026.08.03)
 .
   * kselftests_net.net:test_bpf.sh fails on ppc64el (LP: #2072994)
     - powerpc64/bpf: jit support for 32bit offset jmp instruction
     - powerpc64/bpf: jit support for unconditional byte swap
     - powerpc64/bpf: jit support for sign extended load
     - powerpc64/bpf: jit support for sign extended mov
     - powerpc64/bpf: jit support for signed division and modulo
 .
   * noble/linux-raspi FTBFS: bcmasp phylib managed-EEE backport missing
     prerequisites (LP: #2159608)
     - SAUCE: Revert "net: bcm: asp2: convert to phylib managed EEE"
     - SAUCE: Revert "net: bcm: asp2: remove tx_lpi_enabled"
     - SAUCE: Revert "net: bcm: asp2: fix LPI timer handling"
 .
   * Drop DEP-8 tests from kernel packages (LP: #2160302)
     - [Packaging] Drop DEP-8 tests from kernel source
 .
   * noble-stable-2026-06-16 dropped a bracket causing FTBFS (LP: #2158920)
     - SAUCE: drm/v3d: Fix bracket drop FTBFS for non-generic kernels
 .
   * ubuntu_bpf failed to build on Noble ( error: ���XDP_UMEM_TX_METADATA_LEN���
     undeclared ) (LP: #2139686)
     - selftests/bpf: Add XDP_UMEM_TX_METADATA_LEN to XSK TX metadata test
 .
   * Malformed HV_LINUX_VENDOR_ID breaks VM Availability Metric on Azure
     (LP: #2158462)
     - SAUCE: (no-up) hv: Fix supplied vendor ID
 .
   * net/tls: Three upstream fixes without CVE missing from Ubuntu
     6.8.0-124-generic (LP: #2155609)
     - net: tls: fix silent data drop under pipe back-pressure
 .
   * net:fcnal-test.sh fails because it can't find wait_local_port_listen on
     noble (LP: #2142613)
     - selftests: net: move wait_local_port_listen to lib.sh
 .
   * Noble update: upstream stable patchset 2026-07-09 (LP: #2160250)
     - mptcp: sync the msk->sndbuf at accept() time
     - mptcp: pm: ADD_ADDR rtx: allow ID 0
     - s390/debug: Reject zero-length input before trimming a newline
     - Revert "x86/vdso: Fix output operand size of RDPID"
     - Revert "s390/cio: Update purge function to unregister the unused
       subchannels"
     - sysfs: don't remove existing directory on update failure
     - mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()
     - smb: client: protect tc_count increment in
       smb2_find_smb_sess_tcon_unlocked()
     - smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close
     - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
     - ALSA: ua101: Reject too-short USB descriptors
     - ALSA: pcm: Don't setup bogus iov_iter for silencing
     - ALSA: asihpi: Fix potential OOB array access at reading cache
     - efi: Allocate runtime workqueue before ACPI init
     - drivers/base/memory: fix memory block reference leak in poison
       accounting
     - net: wwan: iosm: fix potential memory leaks in ipc_imem_init()
     - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
     - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START
     - Bluetooth: bnep: Fix UAF read of dev->name
     - Bluetooth: MGMT: validate Add Extended Advertising Data length
     - Bluetooth: serialize accept_q access
     - phonet/pep: disable BH around forwarded sk_receive_skb()
     - net: bcmgenet: keep RBUF EEE/PM disabled
     - net: ifb: report ethtool stats over num_tx_queues
     - netfilter: ip6t_hbh: reject oversized option lists
     - netfilter: nf_queue: hold bridge skb->dev while queued
     - netfilter: ipset: stop hash:* range iteration at end
     - qed: fix double free in qed_cxt_tables_alloc()
     - ring-buffer: Fix reporting of missed events in iterator
     - vsock/vmci: fix UAF when peer resets connection during handshake
     - vsock/virtio: reset connection on receiving queue overflow
     - wifi: ath11k: clear shared SRNG pointer state on restart
     - ipv4: raw: reject IP_HDRINCL packets with ihl < 5
     - ixgbevf: fix use-after-free in VEPA multicast source pruning
     - ice: fix setting promisc mode while adding VID filter
     - wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
     - cifs: Fix busy dentry used after unmounting
     - tracing: Do not call map->ops->elt_free() if elt_alloc() fails
     - arm64: probes: Handle probes on hinted conditional branch instructions
     - KVM: arm64: vgic-its: Reject restored DTE with out-of-range
       num_eventid_bits
     - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe
     - spi: qup: fix error pointer deref after DMA setup failure
     - phy: tegra: xusb: Fix per-pad high-speed termination calibration
     - scsi: isci: Fix use-after-free in device removal path
     - spi: sprd: fix error pointer deref after DMA setup failure
     - spi: ti-qspi: fix use-after-free after DMA setup failure
     - RDMA/siw: Reject MPA FPDU length underflow before signed receive math
     - LoongArch: Remove unused code to avoid build warning
     - device property: set fwnode->secondary to NULL in fwnode_init()
     - drm/virtio: use uninterruptible resv lock for plane updates
     - drm/bridge: it66121: acquire reset GPIO in probe
     - drm/bridge: megachips: remove bridge when irq request fails
     - drm/amd/display: Fix integer overflow in bios_get_image()
     - drm/amd/display: Validate GPIO pin LUT table size before iterating
     - drm/amd/display: Validate payload length and link_index in
       dc_process_dmub_aux_transfer_async
     - batman-adv: mcast: fix use-after-free in orig_node RCU release
     - batman-adv: clear current gateway during teardown
     - batman-adv: dat: handle forward allocation error
     - batman-adv: fix tp_meter counter underflow during shutdown
     - batman-adv: frag: disallow unicast fragment in fragment
     - batman-adv: bla: fix report

1786013 Packaging resync
2072994 kselftests_net.net:test_bpf.sh fails on ppc64el
2159608 noble/linux-raspi FTBFS: bcmasp phylib managed-EEE backport missing prerequisites
2160302 Drop DEP-8 tests from kernel packages
2158920 noble-stable-2026-06-16 dropped a bracket causing FTBFS
2139686 ubuntu_bpf failed to build on Noble ( error: \u2018XDP_UMEM_TX_METADATA_LEN\u2019 undeclared )
2158462 Malformed HV_LINUX_VENDOR_ID breaks VM Availability Metric on Azure
2155609 net/tls: Three upstream fixes without CVE missing from Ubuntu 6.8.0-124-generic
2142613 net:fcnal-test.sh fails because it can't find wait_local_port_listen on noble
2160250 Noble update: upstream stable patchset 2026-07-09
CVE-2025-71289 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: handle attr_set_size() errors when truncating files If attr_set_size(
CVE-2026-46315 In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying it to userspace IORING_OP_WAI
CVE-2026-31486 In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) Protect regulator operations with mutex The regulator opera
CVE-2026-23469 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Synchronize interrupts before suspending the GPU The runtime P
CVE-2026-31560 In the Linux kernel, the following vulnerability has been resolved: spi: spi-dw-dma: fix print error log when wait finish transaction If an error o
CVE-2026-31420 In the Linux kernel, the following vulnerability has been resolved: bridge: mrp: reject zero test interval to avoid OOM panic br_mrp_start_test() a
CVE-2026-46275 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulne
CVE-2026-46170 In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: free sk if last When an ADD_ADDR is retransmitted, the
CVE-2026-46158 In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount When an ADD_ADDR is retran
CVE-2026-64531 In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores gene
CVE-2026-53247 In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown mtk_fre
CVE-2026-53224 In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpa
CVE-2026-53246 In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing When a l
CVE-2026-53225 In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup()
CVE-2026-53228 In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offloads ipip6_tunnel_xmit() cach
CVE-2026-46242 In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep
CVE-2026-46331 In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act
CVE-2026-53212 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix use-after-free on object destroy nft_tunnel_obj_dest
CVE-2026-53359 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af
CVE-2026-53151 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table for parsing Fix modificatio
CVE-2026-52924 In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only
CVE-2026-53215 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns t
CVE-2026-53176 In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband
CVE-2026-52931 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender vars batadv_tp_recv_ack() and
CVE-2026-52914 In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a runnin
CVE-2026-46325 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE The current
CVE-2026-43465 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ XDP multi-buf pr
CVE-2026-43198 In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock(
CVE-2026-43197 In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole
CVE-2026-43083 In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (tra



About   -   Send Feedback to @ubuntu_updates