UbuntuUpdates.org

Package "linux-riscv"

This package belongs to a PPA: Canonical Kernel Team

Name: linux-riscv

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Header files related to Linux kernel version 6.17.0
  • Header files related to Linux kernel version 6.17.0
  • Header files related to Linux kernel version 6.17.0
  • Header files related to Linux kernel version 6.17.0

Latest version: 6.17.0-22.22.1
Release: questing (25.10)
Level: base
Repository: main

Links



Other versions of "linux-riscv" in Questing

Repository Area Version
base main 6.17.0-5.5.1
security main 6.17.0-19.19.1
updates main 6.17.0-19.19.1
proposed main 6.17.0-19.19.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 6.17.0-22.22.1 2026-03-29 05:11:40 UTC

 linux-riscv (6.17.0-22.22.1) questing; urgency=medium
 .
   * questing/linux-riscv: 6.17.0-22.22.1 -proposed tracker (LP: #2143424)
 .
   [ Ubuntu: 6.17.0-22.22 ]
 .
   * questing/linux: 6.17.0-22.22 -proposed tracker (LP: #2143428)
   * Questing preinstalled server fails to boot on QCS8300 based boards
     (LP: #2134400)
     - [Config] move qcom interconnect/pinctrl/gcc as built-in for QCS8300
   * TBT call trace while connecting TBT4 monitor on TBT5 port (LP: #2137613)
     - SAUCE: thunderbolt: log path activation failures without WARN backtraces
   * efi: Fix swapped arguments to bsearch() in efi_status_to_*() SAUCE patch
     (LP: #2141276)
     - SAUCE efi: Fix swapped arguments to bsearch() in efi_status_to_*()
   * [SRU]Fix xe GPU suspend/resume crash on Battlemage (LP: #2141377)
     - drm/xe: make xe_gt_idle_disable_c6() handle the forcewake internally
   * Accumulative updates for Intel PTL-H component enabling PV rev3.0
     (LP: #2137272)
     - drm/i915/display: Optimize panel power-on wait time
     - HID: intel-ish-hid: Use dedicated unbound workqueues to prevent resume
       blocking
     - drm/xe/guc: Recommend GUC v70.49.4 for PTL, BMG
     - HID: Intel-thc-hid: Intel-thc: Use str_true_false() helper
     - HID: intel-thc-hid: intel-quicki2c: support ACPI config for advanced
       features
     - usb: typec: ucsi: Add SET_POWER_LEVEL UCSI command to debugfs
   * Questing update: upstream stable patchset 2026-03-04 (LP: #2142250)
     - bpf: Fix sleepable context for async callbacks
     - bpf: extract generic helper from process_timer_func()
     - bpf: Fix handling maps with no BTF and non-constant offsets for the
       bpf_wq
     - irqchip: Drop leftover brackets
     - irqchip: Pass platform device to platform drivers
     - arm64: dts: exynos: gs101: fix clock module unit reg sizes
     - ice: move service task start out of ice_init_pf()
     - ice: move ice_init_interrupt_scheme() prior ice_init_pf()
     - ice: ice_init_pf: destroy mutexes and xarrays on memory alloc failure
     - ice: move udp_tunnel_nic and misc IRQ setup into ice_init_pf()
     - ice: move ice_init_pf() out of ice_init_dev()
     - ice: extract ice_init_dev() from ice_init()
     - ice: move ice_deinit_dev() to the end of deinit paths
     - ice: remove duplicate call to ice_deinit_hw() on error paths
     - arm64: dts: qcom: lemans: Add missing quirk for HS only USB controller
     - tools/nolibc: x86: fix section mismatch caused by asm "mem*" functions
     - arm64: dts: ti: k3-j784s4: Fix I2C pinmux pull configuration
     - wifi: ath12k: enforce vdev limit in ath12k_mac_vdev_create()
     - ARM: dts: am33xx: Add missing serial console speed
     - arm64: tegra: Add pinctrl definitions for pcie-ep nodes
     - arm64: mm: Move KPTI helpers to mmu.c
     - arm64/mm: Allow __create_pgd_mapping() to propagate pgtable_alloc()
       errors
     - pwm: Simplify printf to emit chip->npwm in $debugfs/pwm
     - pwm: Use %u to printf unsigned int pwm_chip::npwm and pwm_chip::id
     - soc/tegra: fuse: speedo-tegra210: Update speedo IDs
     - iio: core: add missing mutex_destroy in iio_dev_release()
     - iio: core: Clean up device correctly on iio_device_alloc() failure
     - iommu/vt-d: Set INTEL_IOMMU_FLOPPY_WA depend on BLK_DEV_FD
     - of/fdt: Fix the len check in early_init_dt_check_for_elfcorehdr()
     - of/fdt: Fix the len check in early_init_dt_check_for_usable_mem_range()
     - rtla/tests: Extend action tests to 5s
     - rtla: Fix -a overriding -t argument
     - btrfs: make sure extent and csum paths are always released in
       scrub_raid56_parity_stripe()
     - iomap: allocate s_dio_done_wq for async reads as well
     - RDMA/irdma: Remove doorbell elision logic
     - selftests/landlock: Fix makefile header list
     - io_uring/kbuf: use READ_ONCE() for userspace-mapped memory
     - ALSA: wavefront: Clear substream pointers on close
     - btrfs: do not skip logging new dentries when logging a new name
     - btrfs: fix a potential path leak in print_data_reloc_error()
     - bpf, arm64: Do not audit capability check in do_jit()
     - btrfs: fix memory leak of fs_devices in degraded seed device path
     - iomap: account for unaligned end offsets when truncating read range
     - scripts/faddr2line: Fix "Argument list too long" error
     - sched/fair: Revert max_newidle_lb_cost bump
     - x86/ptrace: Always inline trivial accessors
     - ACPI: property: Use ACPI functions in acpi_graph_get_next_endpoint()
       only
     - cpufreq: dt-platdev: Add JH7110S SOC to the allowlist
     - ACPI: fan: Workaround for 64-bit firmware bug
     - cpufreq: s5pv210: fix refcount leak
     - cpuidle: menu: Use residency threshold in polling state override
       decisions
     - livepatch: Match old_sympos 0 and 1 in klp_find_func()
     - fs/ntfs3: Support timestamps prior to epoch
     - kbuild: Use objtree for module signing key path
     - hfsplus: fix volume corruption issue for generic/070
     - hfsplus: fix volume corruption issue for generic/073
     - fs/ntfs3: check for shutdown in fsync
     - wifi: rtl8xxxu: Fix HT40 channel config for RTL8192CU, RTL8723AU
     - wifi: cfg80211: stop radar detection in cfg80211_leave()
     - wifi: cfg80211: use cfg80211_leave() in iftype change
     - wifi: mt76: mt792x: fix wifi init fail by setting MCU_RUNNING after CLC
       load
     - wifi: brcmfmac: Add DMI nvram filename quirk for Acer A1 840 tablet
     - btrfs: scrub: always update btrfs_scrub_progress::last_physical
     - gfs2: fix remote evict for read-only filesystems
     - gfs2: Fix "gfs2: Switch to wait_event in gfs2_quotad"
     - smb/server: fix return value of smb2_ioctl()
     - Bluetooth: btusb: Add new VID/PID 2b89/6275 for RTL8761BUV
     - Bluetooth: btusb: MT7922: Add VID/PID 0489/e170
     - Bluetooth: btusb: MT7920: Add VID/PID 0489/e135
     - Bluetooth: btusb: Add new VID/PID 13d3/3533 for RTL8821CE
     - Bluetooth: btusb: Add new VID/PID 0x0489/0x

Source diff to previous version
2134400 Questing preinstalled server fails to boot on QCS8300 based boards
2141276 efi: Fix swapped arguments to bsearch() in efi_status_to_*() SAUCE patch
2141377 [SRU]Fix xe GPU suspend/resume crash on Battlemage
2142250 Questing update: upstream stable patchset 2026-03-04
CVE-2025-68791 In the Linux kernel, the following vulnerability has been resolved: fuse: missing copy_finish in fuse-over-io-uring argument copies Fix a possible
CVE-2025-68805 In the Linux kernel, the following vulnerability has been resolved: fuse: fix io-uring list corruption for terminated non-committed requests When a
CVE-2025-68812 In the Linux kernel, the following vulnerability has been resolved: media: iris: Add sanity check for stop streaming Add sanity check in iris_vb2_s
CVE-2025-71117 In the Linux kernel, the following vulnerability has been resolved: block: Remove queue freezing from several sysfs store callbacks Freezing the re
CVE-2025-71070 In the Linux kernel, the following vulnerability has been resolved: ublk: clean up user copy references on ublk server exit If a ublk server proces
CVE-2025-71124 In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: move preempt_prepare_postamble after error check Move the call to
CVE-2025-71115 In the Linux kernel, the following vulnerability has been resolved: um: init cpu_tasks[] earlier This is currently done in uml_finishsetup(), but e
CVE-2025-68823 In the Linux kernel, the following vulnerability has been resolved: ublk: fix deadlock when reading partition table When one process(such as udev)
CVE-2025-68793 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix a job->pasid access race in gpu recovery Avoid a possible UAF i
CVE-2025-68807 In the Linux kernel, the following vulnerability has been resolved: block: fix race between wbt_enable_default and IO submission When wbt_enable_de
CVE-2025-68768 In the Linux kernel, the following vulnerability has been resolved: inet: frags: flush pending skbs in fqdir_pre_exit() We have been seeing occasio
CVE-2025-71140 In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Use spinlock for context list protection lock Previous
CVE-2025-71156 In the Linux kernel, the following vulnerability has been resolved: gve: defer interrupt enabling until NAPI registration Currently, interrupts are
CVE-2024-36347 Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious micr
CVE-2025-71068 In the Linux kernel, the following vulnerability has been resolved: svcrdma: bound check rq_pages index in inline path svc_rdma_copy_inline_range i
CVE-2025-68772 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid updating compression context during writeback Bai, Shuangpen
CVE-2025-71105 In the Linux kernel, the following vulnerability has been resolved: f2fs: use global inline_xattr_slab instead of per-sb slab cache As Hong Yun rep
CVE-2025-71130 In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer Initia
CVE-2025-71138 In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add missing NULL pointer check for pingpong interface It is checke
CVE-2025-71083 In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Avoid NULL pointer deref for evicted BOs It is possible for a BO to ex
CVE-2025-71099 In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix potential UAF in xe_oa_add_config_ioctl() In xe_oa_add_config_io
CVE-2025-71079 In the Linux kernel, the following vulnerability has been resolved: net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write A dea
CVE-2025-71129 In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Sign extend kfunc call arguments The kfunc calls are native cal
CVE-2025-71093 In the Linux kernel, the following vulnerability has been resolved: e1000: fix OOB in e1000_tbi_should_accept() In e1000_tbi_should_accept() we rea
CVE-2025-71084 In the Linux kernel, the following vulnerability has been resolved: RDMA/cm: Fix leaking the multicast GID table reference If the CM ID is destroye
CVE-2025-71096 In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Check for the presence of LS_NLA_TYPE_DGID correctly The netlink res
CVE-2025-71136 In the Linux kernel, the following vulnerability has been resolved: media: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_st
CVE-2025-71143 In the Linux kernel, the following vulnerability has been resolved: clk: samsung: exynos-clkout: Assign .num before accessing .hws Commit f316cdff8
CVE-2025-71078 In the Linux kernel, the following vulnerability has been resolved: powerpc/64s/slb: Fix SLB multihit issue during SLB preload On systems using the
CVE-2025-71089 In the Linux kernel, the following vulnerability has been resolved: iommu: disable SVA when CONFIG_X86 is set Patch series "Fix stale IOTLB entries
CVE-2025-71081 In the Linux kernel, the following vulnerability has been resolved: ASoC: stm32: sai: fix OF node leak on probe The reference taken to the sync pro
CVE-2025-71153 In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix memory leak in get_file_all_info() In get_file_all_info(), if vfs_ge
CVE-2025-71135 In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix possible null-pointer dereferences in raid5_store_group_thread_cnt
CVE-2025-71157 In the Linux kernel, the following vulnerability has been resolved: RDMA/core: always drop device refcount in ib_del_sub_device_and_put() Since nld
CVE-2025-71133 In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: avoid invalid read in irdma_net_event irdma_net_event() should not
CVE-2025-71080 In the Linux kernel, the following vulnerability has been resolved: ipv6: fix a BUG in rt6_get_pcpu_route() under PREEMPT_RT On PREEMPT_RT kernels,
CVE-2025-71086 In the Linux kernel, the following vulnerability has been resolved: net: rose: fix invalid array index in rose_kill_by_device() rose_kill_by_device
CVE-2025-71097 In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix reference count leak when using error routes with nexthop objects Whe
CVE-2025-71085 In the Linux kernel, the following vulnerability has been resolved: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() There exi
CVE-2025-71095 In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix the crash issue for zero copy XDP_TX action There is a crash i
CVE-2025-71137 In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix "UBSAN: shift-out-of-bounds error" This patch ensures that th
CVE-2025-71101 In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing
CVE-2025-71094 In the Linux kernel, the following vulnerability has been resolved: net: usb: asix: validate PHY address before use The ASIX driver reads the PHY a
CVE-2025-71132 In the Linux kernel, the following vulnerability has been resolved: smc91x: fix broken irq-context in PREEMPT_RT When smc91x.c is built with PREEMP
CVE-2025-71154 In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix memory leak on usb_submit_urb() failure In async_set_reg
CVE-2025-71091 In the Linux kernel, the following vulnerability has been resolved: team: fix check for port enabled in team_queue_override_port_prio_changed() The
CVE-2025-71098 In the Linux kernel, the following vulnerability has been resolved: ip6_gre: make ip6gre_header() robust Over the years, syzbot found many ways to
CVE-2025-71082 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: revert use of devm_kzalloc in btusb This reverts commit 98921
CVE-2025-71131 In the Linux kernel, the following vulnerability has been resolved: crypto: seqiv - Do not use req->iv after crypto_aead_encrypt As soon as crypto_
CVE-2025-71087 In the Linux kernel, the following vulnerability has been resolved: iavf: fix off-by-one issues in iavf_config_rss_reg() There are off-by-one bugs
CVE-2025-71100 In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: 8192cu: fix tid out of range in rtl92cu_tx_fill_desc() TID getti
CVE-2025-68821 In the Linux kernel, the following vulnerability has been resolved: fuse: fix readahead reclaim deadlock Commit e26ee4efbc79 ("fuse: allocate ff->r
CVE-2025-71071 In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: fix use-after-free on probe deferral The driver is dropping the
CVE-2025-71111 In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83791d) Convert macros to functions to avoid TOCTOU The macro FAN_FROM
CVE-2025-71113 In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - zero initialize memory allocated via sock_kmalloc Several cryp
CVE-2025-71149 In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: correctly handle io_poll_add() return value on update When the c
CVE-2025-68778 In the Linux kernel, the following vulnerability has been resolved: btrfs: don't log conflicting inode if it's a dir moved in the current transactio
CVE-2025-71119 In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec: Enable SMT before waking offline CPUs If SMT is disabled or a pa
CVE-2025-71120 In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy
CVE-2025-68811 In the Linux kernel, the following vulnerability has been resolved: svcrdma: use rc_pageoff for memcpy byte offset svc_rdma_copy_inline_range added
CVE-2025-68803 In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An NFSv4 client that sets an ACL
CVE-2025-71148 In the Linux kernel, the following vulnerability has been resolved: net/handshake: restore destructor on submit failure handshake_req_submit() repl
CVE-2025-68788 In the Linux kernel, the following vulnerability has been resolved: fsnotify: do not generate ACCESS/MODIFY events on child for special files inoti
CVE-2025-71125 In the Linux kernel, the following vulnerability has been resolved: tracing: Do not register unsupported perf events Synthetic events currently do
CVE-2025-68784 In the Linux kernel, the following vulnerability has been resolved: xfs: fix a UAF problem in xattr repair The xchk_setup_xattr_buf function can al
CVE-2025-71104 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer
CVE-2025-71116 In the Linux kernel, the following vulnerability has been resolved: libceph: make decode_pool() more resilient against corrupted osdmaps If the osd
CVE-2025-71121 In the Linux kernel, the following vulnerability has been resolved: parisc: Do not reprogram affinitiy on ASP chip The ASP chip is a very old varia
CVE-2025-71102 In the Linux kernel, the following vulnerability has been resolved: scs: fix a wrong parameter in __scs_magic __scs_magic() needs a 'void *' variab
CVE-2025-68804 In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_ishtp: Fix UAF after unbinding driver After unbinding
CVE-2025-68771 In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix kernel BUG in ocfs2_find_victim_chain syzbot reported a kernel BUG i
CVE-2025-68808 In the Linux kernel, the following vulnerability has been resolved: media: vidtv: initialize local pointers upon transfer of memory ownership vidtv
CVE-2025-68810 In the Linux kernel, the following vulnerability has been resolved: KVM: Disallow toggling KVM_MEM_GUEST_MEMFD on an existing memslot Reject attemp
CVE-2025-68769 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix return value of f2fs_recover_fsync_data() With below scripts, it will
CVE-2025-71069 In the Linux kernel, the following vulnerability has been resolved: f2fs: invalidate dentry cache on failed whiteout creation F2FS can mount filesy
CVE-2025-68796 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid updating zero-sized extent in extent cache As syzbot reporte
CVE-2025-71065 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadlock As Jiaming Zhang and syzbot reported, the
CVE-2025-71107 In the Linux kernel, the following vulnerability has been resolved: f2fs: ensure node page reads complete before f2fs_put_super() finishes Xfstests
CVE-2025-68782 In the Linux kernel, the following vulnerability has been resolved: scsi: target: Reset t_task_cdb pointer in error case If allocation of cmd->t_ta
CVE-2025-71075 In the Linux kernel, the following vulnerability has been resolved: scsi: aic94xx: fix use-after-free in device removal path The asd_pci_remove() f
CVE-2025-68818 In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path"
CVE-2025-68797 In the Linux kernel, the following vulnerability has been resolved: char: applicom: fix NULL pointer dereference in ac_ioctl Discovered by Atuin -
CVE-2025-68781 In the Linux kernel, the following vulnerability has been resolved: usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal The
CVE-2025-68819 In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg() rlen value is a
CVE-2025-71126 In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid deadlock on fallback while reinjecting Jakub reported an MPTCP dea
CVE-2025-68820 In the Linux kernel, the following vulnerability has been resolved: ext4: xattr: fix null pointer deref in ext4_raw_inode() If ext4_get_inode_loc()
CVE-2025-71123 In the Linux kernel, the following vulnerability has been resolved: ext4: fix string copying in parse_apply_sb_mount_options() strscpy_pad() can't
CVE-2025-71077 In the Linux kernel, the following vulnerability has been resolved: tpm: Cap the number of PCR banks tpm2_get_pcr_allocation() does not cap any upp
CVE-2025-68814 In the Linux kernel, the following vulnerability has been resolved: io_uring: fix filename leak in __io_openat_prep() __io_openat_prep() allocates
CVE-2025-71147 In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix a memory leak in tpm2_load_cmd 'tpm2_load_cmd' allocates a t
CVE-2025-71151 In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory and information leak in smb3_reconfigure() In smb3_reconfigure
CVE-2025-71109 In the Linux kernel, the following vulnerability has been resolved: MIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits Since
CVE-2025-71108 In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Handle incorrect num_connectors capability The UCSI spec stat
CVE-2025-71114 In the Linux kernel, the following vulnerability has been resolved: via_wdt: fix critical boot hang due to unnamed resource allocation The VIA watc
CVE-2025-68783 In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-mixer: us16x08: validate meter packet indices get_meter_levels_from_u
CVE-2025-68776 In the Linux kernel, the following vulnerability has been resolved: net/hsr: fix NULL pointer dereference in prp_get_untagged_frame() prp_get_untag
CVE-2025-68773 In the Linux kernel, the following vulnerability has been resolved: spi: fsl-cpm: Check length parity before switching to 16 bit mode Commit fc96ec
CVE-2025-68822 In the Linux kernel, the following vulnerability has been resolved: Input: alps - fix use-after-free bugs caused by dev3_register_work The dev3_reg
CVE-2025-71073 In the Linux kernel, the following vulnerability has been resolved: Input: lkkbd - disable pending work before freeing device lkkbd_interrupt() sch
CVE-2025-68777 In the Linux kernel, the following vulnerability has been resolved: Input: ti_am335x_tsc - fix off-by-one error in wire_order validation The curren
CVE-2025-68806 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix buffer validation by including null terminator size in EA length The
CVE-2025-71150 In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix refcount leak when invalid session is found on session lookup When a
CVE-2025-68786 In the Linux kernel, the following vulnerability has been resolved: ksmbd: skip lock-range check on equal size to avoid size==0 underflow When size
CVE-2025-71076 In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Limit num_syncs to prevent oversized allocations The OA open paramet
CVE-2025-68802 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Limit num_syncs to prevent oversized allocations The exec and vm_bind i
CVE-2025-71112 In the Linux kernel, the following vulnerability has been resolved: net: hns3: add VLAN id validation before using Currently, the VLAN id may be us
CVE-2025-71064 In the Linux kernel, the following vulnerability has been resolved: net: hns3: using the num_tqps in the vf driver to apply for resources Currently
CVE-2025-68775 In the Linux kernel, the following vulnerability has been resolved: net/handshake: duplicate handshake cancellations leak socket When a handshake r
CVE-2025-68816 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, Validate format string parameters Add validation for forma
CVE-2025-68795 In the Linux kernel, the following vulnerability has been resolved: ethtool: Avoid overflowing userspace buffer on stats query The ethtool -S comma
CVE-2025-71122 In the Linux kernel, the following vulnerability has been resolved: iommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED syzkaller fo
CVE-2025-68815 In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: Remove drr class from the active list if it changes to strict W
CVE-2025-68799 In the Linux kernel, the following vulnerability has been resolved: caif: fix integer underflow in cffrml_receive() The cffrml_receive() function e
CVE-2025-68813 In the Linux kernel, the following vulnerability has been resolved: ipvs: fix ipv4 null-ptr-deref in route error path The IPv4 code path in __ip_vs
CVE-2025-68785 In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix middle attribute validation in push_nsh() action The push
CVE-2025-68770 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix XDP_TX path For XDP_TX action in bnxt_rx_xdp(), clearing of the ev
CVE-2025-68800 In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats Cite
CVE-2025-68801 In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_router: Fix neighbour use-after-free We sometimes observe use-a
CVE-2025-71066 In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: Always remove class from active list before deleting in ets_qdis
CVE-2025-68787 In the Linux kernel, the following vulnerability has been resolved: netrom: Fix memory leak in nr_sendmsg() syzbot reported a memory leak [1]. Whe
CVE-2025-68809 In the Linux kernel, the following vulnerability has been resolved: ksmbd: vfs: fix race on m_flags in vfs_cache ksmbd maintains delete-on-close an
CVE-2025-68817 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency Under hig
CVE-2025-68767 In the Linux kernel, the following vulnerability has been resolved: hfsplus: Verify inode mode when loading from disk syzbot is reporting that S_IF
CVE-2025-68774 In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix missing hfs_bnode_get() in __hfs_bnode_create When sync() and link
CVE-2025-71067 In the Linux kernel, the following vulnerability has been resolved: ntfs: set dummy blocksize to read boot_block when mounting When mounting, sb->s
CVE-2025-71118 In the Linux kernel, the following vulnerability has been resolved: ACPICA: Avoid walking the Namespace if start_node is NULL Although commit 0c999
CVE-2025-68780 In the Linux kernel, the following vulnerability has been resolved: sched/deadline: only set free_cpus for online runqueues Commit 16b269436b72 ("s
CVE-2025-68798 In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd: Check event before enable to avoid GPF On AMD machines cpuc->even
CVE-2025-68794 In the Linux kernel, the following vulnerability has been resolved: iomap: adjust read range correctly for non-block-aligned positions iomap_adjust
CVE-2025-71072 In the Linux kernel, the following vulnerability has been resolved: shmem: fix recovery on rename failures maple_tree insertions can fail if we are
CVE-2025-68351 In the Linux kernel, the following vulnerability has been resolved: exfat: fix refcount leak in exfat_find Fix refcount leaks in `exfat_find` relat
CVE-2025-68736 In the Linux kernel, the following vulnerability has been resolved: landlock: Fix handling of disconnected directories Disconnected files or direct
CVE-2025-68353 In the Linux kernel, the following vulnerability has been resolved: net: vxlan: prevent NULL deref in vxlan_xmit_one Neither sock4 nor sock6 pointe
CVE-2025-68745 In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit aefed3e5548f ("scsi: qla2xxx:
CVE-2025-68365 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize allocated memory before use KMSAN reports: Multiple uninit
CVE-2025-68368 In the Linux kernel, the following vulnerability has been resolved: md: init bioset in mddev_init IO operations may be needed before md_run(), such
CVE-2025-68725 In the Linux kernel, the following vulnerability has been resolved: bpf: Do not let BPF test infra emit invalid GSO types to stack Yinhao et al. re
CVE-2026-23111 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()
CVE-2026-23209 In the Linux kernel, the following vulnerability has been resolved: macvlan: fix error recovery in macvlan_common_newlink() valis provided a nice r
CVE-2026-23074 In the Linux kernel, the following vulnerability has been resolved: net/sched: Enforce that teql can only be used as root qdisc Design intent of te
CVE-2026-23060 In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec au

Version: 6.17.0-16.16.1 2026-02-15 10:08:59 UTC

 linux-riscv (6.17.0-16.16.1) questing; urgency=medium
 .
   * questing/linux-riscv: 6.17.0-16.16.1 -proposed tracker (LP: #2141144)
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] debian.riscv/dkms-versions -- update from kernel-versions
       (main/2026.02.09)
 .
   [ Ubuntu: 6.17.0-16.16 ]
 .
   * questing/linux: 6.17.0-16.16 -proposed tracker (LP: #2141148)
   * Packaging resync (LP: #1786013)
     - [Packaging] debian.master/dkms-versions -- update from kernel-versions
       (main/2026.02.09)
   * Support Intel Scorpius Peak, Whale Peak WiFi/Bluetooth for Intel Panther
     Lake platforms (LP: #2116169)
     - Bluetooth: btintel_pcie: Add Bluetooth core/platform as comments
     - Bluetooth: btintel_pcie: Add id of Scorpious, Panther Lake-H484
   * Boot up hang with ucsi call trace while plug power cord or device on tbt5
     port (LP: #2127764)
     - SAUCE: usb: typec: ucsi: Fix workqueue destruction race during connector
       cleanup
   * net:rtnetlink.sh in ubuntu_kernel_selftests failed with FAIL: address
     proto IPv4 / IPv6 (LP: #2031531)
     - selftests: rtnetlink: skip tests if tools or feats are missing
   * TBT call trace while connecting TBT4 monitor on TBT5 port (LP: #2137613)
     - drm/i915/psr: Do not unnecessarily remove underrun on idle PSR WA
   * No output on external monitor when connecting to dell dock (LP: #2131066)
     - drm/i915/dsc: Add helper to enable the DSC configuration for a CRTC
     - drm/i915/dp: Ensure the FEC state stays disabled for UHBR links
     - drm/i915/dp: Export helper to determine if FEC on non-UHBR links is
       required
     - drm/i915/dp_mst: Reuse the DP-SST helper function to compute FEC config
     - drm/i915/dp_mst: Track DSC enabled status on the MST link
     - drm/i915/dp_mst: Recompute all MST link CRTCs if DSC gets enabled on the
       link
     - drm/i915/psr: Underrun on idle PSR wa only when pkgc latency > delayed
       vblank
     - drm/i915/display: Remove unused declarations of intel_io_*
     - drm/i915/dp: Fix panel replay when DSC is enabled
   * [questing] kernel BUG at lib/string_helpers.c:1043! (LP: #2129580)
     - erspan: Initialize options_len before referencing options.
   * Hotplug dock with monitor leads to call trace (LP: #2130998)
     - drm/i915/psr: Check pause counter before continuing to PSR activation
     - drm/i915/psr: Check PSR pause counter in __psr_wait_for_idle_locked
   * [SRU] Fix the error during suspend on cs42l43 (LP: #2138423)
     - mfd: cs42l43: Remove IRQ masking in suspend
     - ASoC: cs42l43: Rename system suspend callback and fix debug print
     - ASoC: cs42l43: Store IRQ domain in codec private data
     - ASoC: cs42l43: Disable IRQs in system suspend
     - ASoC: cs42l43: Shutdown jack detection on suspend
   * noble/plucky: ubuntu_kselftests_ftrace fails 7 ftrace:test.d tests for
     riscv64 on openstack:riscv64.vm (LP: #2124276)
     - riscv: Enable ARCH_HAVE_NMI_SAFE_CMPXCHG
     - [Config] Enable ARCH_HAVE_NMI_SAFE_CMPXCHG for riscv64
   * Got call trace when plug in device/AC in type-c port(both TBT5/TBT4)
     (LP: #2138192)
     - usb: typec: ucsi: Add support for READ_POWER_LEVEL command
     - usb: typec: ucsi: Add check for UCSI version
   * Export CWSR size to userspace (LP: #2134491)
     - drm/amdkfd: bump minimum vgpr size for gfx1151
     - drm/amdkfd: Export the cwsr_size and ctl_stack_size to userspace
   * [SRU] add pmc c6 support of Arrow Lake (LP: #2137615)
     - platform/x86:intel/pmc: Update Arrow Lake telemetry GUID
     - platform/x86:intel/pmc: Add support for multiple DMU GUIDs
     - platform/x86:intel/pmc: Add DMU GUID to Arrow Lake U/H
   * net:tap in ubuntu_kselftests_net fails on Noble (buffer overflow detected)
     (LP: #2067642)
     - SAUCE: selftests: net: fix "buffer overflow detected" for tap.c
   * MT7925 wifi is hard blocked on HP's machine (LP: #2127044)
     - SAUCE: wifi: mt76: mt7925: add DMI quirk for HP Z2 Mini G1a Workstation
   * No on-screen keyboard on dell tablets (LP: #2122398)
     - platform/x86/intel/hid: Add Dell Pro Rugged 10/12 tablet to VGBS DMI
       quirks
   * Enable RTL ASPM for more new Dell platforms (LP: #2133144)
     - SAUCE: r8169: Add more Dell platforms to enable ASPM
   * Enable RTL ASPM for new Dell platforms (LP: #2121200)
     - SAUCE: r8169: enable ASPM on all new Dell platforms
   * Questing update: v6.17.13 upstream stable release (LP: #2139960)
     - smack: deduplicate "does access rule request transmutation"
     - smack: fix bug: SMACK64TRANSMUTE set on non-directory
     - smack: deduplicate xattr setting in smack_inode_init_security()
     - smack: always "instantiate" inode in smack_inode_init_security()
     - smack: fix bug: invalid label of unix socket file
     - smack: fix bug: setting task label silently ignores input garbage
     - accel/ivpu: Ensure rpm_runtime_put in case of engine reset/resume fail
     - drm/panel: visionox-rm69299: Fix clock frequency for SHIFT6mq
     - drm/panel: visionox-rm69299: Don't clear all mode flags
     - accel/ivpu: Rework bind/unbind of imported buffers
     - accel/ivpu: Make function parameter names consistent
     - accel/ivpu: Fix DCT active percent format
     - bpf: Cleanup unused func args in rqspinlock implementation
     - tools/nolibc: handle NULL wstatus argument to waitpid()
     - USB: Fix descriptor count when handling invalid MBIM extended descriptor
     - perf bpf_counter: Fix opening of "any"(-1) CPU events
     - ima: Attach CREDS_CHECK IMA hook to bprm_creds_from_file LSM hook
     - pinctrl: renesas: rzg2l: Fix PMC restore
     - clk: renesas: cpg-mssr: Add missing 1ms delay into reset toggle callback
     - clk: renesas: cpg-mssr: Read back reset registers to assure values
       latched
     - drm: atmel-hlcdc: fix atmel_xlcdc_plane_setup_scaler()
     - HID: logitech-hidpp: Do not assume FAP in hidpp_send_message_sync()
     - remoteproc: imx_rproc: Fix runtime PM cleanup and improve remove path
     

Source diff to previous version
1786013 Packaging resync
2031531 net:rtnetlink.sh in ubuntu_kernel_selftests failed with FAIL: address proto IPv4 / IPv6
2129580 [questing] kernel BUG at lib/string_helpers.c:1043!
2138423 [SRU] Fix the error during suspend on cs42l43
2138192 Got call trace when plug in device/AC in type-c port(both TBT5/TBT4)
2137615 [SRU] add pmc c6 support of Arrow Lake
2067642 net:tap in ubuntu_kselftests_net fails on Noble (buffer overflow detected)
2139960 Questing update: v6.17.13 upstream stable release
2139373 Questing update: v6.17.12 upstream stable release
2138824 Questing update: v6.17.11 upstream stable release
2137723 Questing update: v6.17.10 upstream stable release
2136979 Intel,External monitor flickers or no output when connected to WD25 dock
CVE-2025-68344 In the Linux kernel, the following vulnerability has been resolved: ALSA: wavefront: Fix integer overflow in sample size validation The wavefront_s
CVE-2025-68345 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_hda_read_acpi() The
CVE-2025-68346 In the Linux kernel, the following vulnerability has been resolved: ALSA: dice: fix buffer overflow in detect_stream_formats() The function detect_
CVE-2025-68323 In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: fix use-after-free caused by uec->work The delayed work uec->
CVE-2025-68766 In the Linux kernel, the following vulnerability has been resolved: irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc() If irq_domain_trans
CVE-2025-68324 In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinished delayed work The delayed
CVE-2025-68756 In the Linux kernel, the following vulnerability has been resolved: block: Use RCU in blk_mq_[un]quiesce_tagset() instead of set->tag_list_lock blk
CVE-2025-68753 In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: add bounds check in put_user loop for DSP events In the DS
CVE-2025-68347 In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events The DSP e
CVE-2025-68348 In the Linux kernel, the following vulnerability has been resolved: block: fix memory leak in __blkdev_issue_zero_pages Move the fatal signal check
CVE-2025-68764 In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags When a f
CVE-2025-68735 In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Prevent potential UAF in group creation This commit prevents the p
CVE-2025-68349 In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid Fixe
CVE-2025-68754 In the Linux kernel, the following vulnerability has been resolved: rtc: amlogic-a4: fix double free caused by devm The clock obtained via devm_clk
CVE-2025-68325 In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop In cake_drop(),
CVE-2025-68762 In the Linux kernel, the following vulnerability has been resolved: net: netpoll: initialize work queue before error checks Prevent a kernel warnin
CVE-2025-68352 In the Linux kernel, the following vulnerability has been resolved: spi: ch341: fix out-of-bounds memory access in ch341_transfer_one Discovered by
CVE-2025-68752 In the Linux kernel, the following vulnerability has been resolved: iavf: Implement settime64 with -EOPNOTSUPP ptp_clock_settime() assumes every pt
CVE-2025-68354 In the Linux kernel, the following vulnerability has been resolved: regulator: core: Protect regulator_supply_alias_list with regulator_list_mutex
CVE-2025-68356 In the Linux kernel, the following vulnerability has been resolved: gfs2: Prevent recursive memory reclaim Function new_inode() returns a new inode
CVE-2025-68758 In the Linux kernel, the following vulnerability has been resolved: backlight: led-bl: Add devlink to supplier LEDs LED Backlight is a consumer of
CVE-2025-68358 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix racy bitfield write in btrfs_clear_space_info_full() From the memory
CVE-2025-68359 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free of qgroup record after failure to add delayed ref head I
CVE-2025-68765 In the Linux kernel, the following vulnerability has been resolved: mt76: mt7615: Fix memory leak in mt7615_mcu_wtbl_sta_add() In mt7615_mcu_wtbl_s
CVE-2025-68360 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: wed: use proper wed reference in mt76 wed driver callabacks MT7996
CVE-2025-68738 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix null pointer deref in mt7996_conf_tx() If a link does n
CVE-2025-68361 In the Linux kernel, the following vulnerability has been resolved: erofs: limit the level of fs stacking for file-backed mounts Otherwise, it coul
CVE-2025-68739 In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: hisi: Fix potential UAF in OPP handling Ensure all required data
CVE-2025-68763 In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Correctly handle return of sg_nents_for_len The return value
CVE-2025-68740 In the Linux kernel, the following vulnerability has been resolved: ima: Handle error code returned by ima_filter_rule_match() In ima_match_rules()
CVE-2025-68362 In the Linux kernel, the following vulnerability has been resolved: wifi: rtl818x: rtl8187: Fix potential buffer underflow in rtl8187_rx_cb() The r
CVE-2025-68741 In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix improper freeing of purex item In qla2xxx_process_purls_iocb
CVE-2025-68742 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix invalid prog->stats access when update_effective_progs fails Syzkaller
CVE-2025-68759 In the Linux kernel, the following vulnerability has been resolved: wifi: rtl818x: Fix potential memory leaks in rtl8180_init_rx_ring() In rtl8180_
CVE-2025-68743 In the Linux kernel, the following vulnerability has been resolved: mshv: Fix create memory region overlap check The current check is incorrect; it
CVE-2025-68363 In the Linux kernel, the following vulnerability has been resolved: bpf: Check skb->transport_header is set in bpf_skb_check_mtu The bpf_skb_check_
CVE-2025-68751 In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Fix false-positive kmsan report in fpu_vstl() A false-positive kmsan
CVE-2025-68744 In the Linux kernel, the following vulnerability has been resolved: bpf: Free special fields when update [lru_,]percpu_hash maps As [lru_,]percpu_h
CVE-2025-68364 In the Linux kernel, the following vulnerability has been resolved: ocfs2: relax BUG() to ocfs2_error() in __ocfs2_move_extent() In '__ocfs2_move_e
CVE-2025-68366 In the Linux kernel, the following vulnerability has been resolved: nbd: defer config unlock in nbd_genl_connect There is one use-after-free warnin
CVE-2025-68367 In the Linux kernel, the following vulnerability has been resolved: macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse The following
CVE-2025-68369 In the Linux kernel, the following vulnerability has been resolved: ntfs3: init run lock for extend inode After setting the inode mode of $Extend t
CVE-2025-68370 In the Linux kernel, the following vulnerability has been resolved: coresight: tmc: add the handle of the event to the path The handle is essential
CVE-2025-68755 In the Linux kernel, the following vulnerability has been resolved: staging: most: remove broken i2c driver The MOST I2C driver has been completely
CVE-2025-68371 In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Fix device resources accessed after device removal Correct poss
CVE-2025-68372 In the Linux kernel, the following vulnerability has been resolved: nbd: defer config put in recv_work There is one uaf issue in recv_work when run
CVE-2025-68373 In the Linux kernel, the following vulnerability has been resolved: md: avoid repeated calls to del_gendisk There is a uaf problem which is found b
CVE-2025-68374 In the Linux kernel, the following vulnerability has been resolved: md: fix rcu protection in md_wakeup_thread We attempted to use RCU to protect t
CVE-2025-68375 In the Linux kernel, the following vulnerability has been resolved: perf/x86: Fix NULL event access and potential PEBS record loss When intel_pmu_d
CVE-2025-68376 In the Linux kernel, the following vulnerability has been resolved: coresight: ETR: Fix ETR buffer use-after-free issue When ETR is enabled as CS_M
CVE-2025-68746 In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Fix timeout handling When the CPU that the QSPI interrupt h
CVE-2025-68760 In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix potential out-of-bounds read in iommu_mmio_show In iommu_mmio_wr
CVE-2025-68747 In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF on kernel BO VA nodes If the MMU is down, panthor_vm_unmap
CVE-2025-68748 In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF race between device unplug and FW event processing The fun
CVE-2025-68749 In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix race condition when unbinding BOs Fix 'Memory manager not clean
CVE-2025-68378 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stackmap overflow check in __bpf_get_stackid() Syzkaller reported a KA
CVE-2025-68379 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix null deref on srq->rq.queue after resize failure A NULL pointer d
CVE-2025-68380 In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix peer HE MCS assignment In ath11k_wmi_send_peer_assoc_cmd(), p
CVE-2025-68724 In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id Use ch
CVE-2025-68726 In the Linux kernel, the following vulnerability has been resolved: crypto: aead - Fix reqsize handling Commit afddce13ce81d ("crypto: api - Add re
CVE-2025-68727 In the Linux kernel, the following vulnerability has been resolved: ntfs3: Fix uninit buffer allocated by __getname() Fix uninit errors caused afte
CVE-2025-68728 In the Linux kernel, the following vulnerability has been resolved: ntfs3: fix uninit memory after failed mi_read in mi_format_new Fix a KMSAN un-i
CVE-2025-68729 In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix MSDU buffer types handling in RX error path Currently, packet
CVE-2025-68757 In the Linux kernel, the following vulnerability has been resolved: drm/vgem-fence: Fix potential deadlock on release A timer that expires a vgem f
CVE-2025-68730 In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix page fault in ivpu_bo_unbind_all_bos_from_context() Don't add B
CVE-2025-68732 In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix race in syncpt alloc/free Fix race condition between host1x_sy
CVE-2025-68733 In the Linux kernel, the following vulnerability has been resolved: smack: fix bug: unprivileged task can create labels If an unprivileged task is
CVE-2025-68282 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: fix use-after-free in usb_gadget_state_work A race condition
CVE-2025-68283 In the Linux kernel, the following vulnerability has been resolved: libceph: replace BUG_ON with bounds check for map->max_osd OSD indexes come fro
CVE-2025-68284 In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() Th
CVE-2025-68285 In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop i
CVE-2025-68338 In the Linux kernel, the following vulnerability has been resolved: net: dsa: microchip: Don't free uninitialized ksz_irq If something goes wrong a
CVE-2025-68286 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check NULL before accessing [WHAT] IGT kms_cursor_legacy's lon
CVE-2025-68326 In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Fix stack_depot usage Add missing stack_depot_init() call when CONF
CVE-2025-68287 In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call pat
CVE-2025-68331 In the Linux kernel, the following vulnerability has been resolved: usb: uas: fix urb unmapping issue when the uas device is remove during ongoing d
CVE-2025-40345 In the Linux kernel, the following vulnerability has been resolved: usb: storage: sddr55: Reject out-of-bound new_pba Discovered by Atuin - Automat
CVE-2025-68288 In the Linux kernel, the following vulnerability has been resolved: usb: storage: Fix memory leak in USB bulk transport A kernel memory leak was id
CVE-2025-68327 In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Fix synchronous external abort on unbind A synchronous exte
CVE-2025-68289 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_eem: Fix memory leak in eem_unwrap The existing code did not han
CVE-2025-68290 In the Linux kernel, the following vulnerability has been resolved: most: usb: fix double free on late probe failure The MOST subsystem has a non-s
CVE-2025-68292 In the Linux kernel, the following vulnerability has been resolved: mm/memfd: fix information leak in hugetlb folios When allocating hugetlb folios
CVE-2025-68293 In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix NULL pointer deference when splitting folio Commit c010d47f
CVE-2025-68328 In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix bug in saving controller data Fix the incorrect us
CVE-2025-68294 In the Linux kernel, the following vulnerability has been resolved: io_uring/net: ensure vectored buffer node import is tied to notification When s
CVE-2025-68295 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix memory leak in cifs_construct_tcon() When having a multiuser m
CVE-2025-68296 In the Linux kernel, the following vulnerability has been resolved: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup Protect vga_swi
CVE-2025-68297 In the Linux kernel, the following vulnerability has been resolved: ceph: fix crash in process_v2_sparse_read() for encrypted directories The crash
CVE-2025-68298 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Avoid btusb_mtk_claim_iso_intf() NULL deref In btus
CVE-2025-68339 In the Linux kernel, the following vulnerability has been resolved: atm/fore200e: Fix possible data race in fore200e_open() Protect access to fore2
CVE-2025-68329 In the Linux kernel, the following vulnerability has been resolved: tracing: Fix WARN_ON in tracing_buffers_mmap_close for split VMAs When a VMA is
CVE-2025-68330 In the Linux kernel, the following vulnerability has been resolved: iio: accel: bmc150: Fix irq assumption regression The code in bmc150-accel-core
CVE-2025-68299 In the Linux kernel, the following vulnerability has been resolved: afs: Fix delayed allocation of a cell's anonymous key The allocation of a cell'
CVE-2025-68300 In the Linux kernel, the following vulnerability has been resolved: fs/namespace: fix reference leak in grab_requested_mnt_ns lookup_mnt_ns() alrea
CVE-2025-68301 In the Linux kernel, the following vulnerability has been resolved: net: atlantic: fix fragment overflow handling in RX path The atlantic driver ca
CVE-2025-40290 In the Linux kernel, the following vulnerability has been resolved: xsk: avoid data corruption on cq descriptor number Since commit 30f241fcf52a ("
CVE-2025-68302 In the Linux kernel, the following vulnerability has been resolved: net: sxgbe: fix potential NULL dereference in sxgbe_rx() Currently, when skb is
CVE-2025-68340 In the Linux kernel, the following vulnerability has been resolved: team: Move team device type change at the end of team_port_add Attempting to ad
CVE-2025-68303 In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel: punit_ipc: fix memory corruption This passes the address o
CVE-2025-68341 In the Linux kernel, the following vulnerability has been resolved: veth: reduce XDP no_direct return section to fix race As explain in commit fa34
CVE-2025-68304 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: lookup hci_conn on RX path on protocol side The hdev lock/
CVE-2025-68305 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sock: Prevent race in socket write iter and sock bind There is a
CVE-2025-68306 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Fix kernel crash when releasing mtk iso interface W
CVE-2025-68342 In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessin
CVE-2025-68343 In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessin
CVE-2025-68307 In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs Th
CVE-2025-68308 In the Linux kernel, the following vulnerability has been resolved: can: kvaser_usb: leaf: Fix potential infinite loop in command parsers The `kvas
CVE-2025-68221 In the Linux kernel, the following vulnerability has been resolved: mptcp: fix address removal logic in mptcp_pm_nl_rm_addr Fix inverted WARN_ON_ON
CVE-2025-40246 In the Linux kernel, the following vulnerability has been resolved: xfs: fix out of bounds memory read error in symlink repair xfs/286 produced thi
CVE-2025-68230 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix gpu page fault after hibernation on PF passthrough On PF passth
CVE-2025-68220 In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: netcp: Standardize knav_dma_open_channel to return NULL on er
CVE-2025-68236 In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: ufs-qcom: Fix UFS OCP issue during UFS power down (PC=3) According t
CVE-2025-40247 In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix pgtable prealloc error path The following splat was reported:
CVE-2025-40248 In the Linux kernel, the following vulnerability has been resolved: vsock: Ignore signal/timeout on connect() if already established During connect
CVE-2025-68219 In the Linux kernel, the following vulnerability has been resolved: cifs: fix memory leak in smb3_fs_context_parse_param error path Add proper clea
CVE-2025-40249 In the Linux kernel, the following vulnerability has been resolved: gpio: cdev: make sure the cdev fd is still active before emitting events With t
CVE-2025-40250 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clean up only new IRQ glue on request_irq() failure The mlx5_irq_allo
CVE-2025-40251 In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy The function dev
CVE-2025-68222 In the Linux kernel, the following vulnerability has been resolved: pinctrl: s32cc: fix uninitialized memory in s32_pinctrl_desc s32_pinctrl_desc i
CVE-2025-68215 In the Linux kernel, the following vulnerability has been resolved: ice: fix PTP cleanup on driver removal in error path Improve the cleanup on rel
CVE-2025-68213 In the Linux kernel, the following vulnerability has been resolved: idpf: fix possible vport_config NULL pointer deref in remove Attempting to remo
CVE-2025-40252 In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_t
CVE-2025-40253 In the Linux kernel, the following vulnerability has been resolved: s390/ctcm: Fix double-kfree The function 'mpc_rcvd_sweep_req(mpcginfo)' is call
CVE-2025-68218 In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix lockdep WARN due to partition scan work Blktests test cases
CVE-2025-68232 In the Linux kernel, the following vulnerability has been resolved: veth: more robust handing of race to avoid txq getting stuck Commit dc82a33297f
CVE-2025-40254 In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: remove never-working support for setting nsh fields The valid
CVE-2025-68233 In the Linux kernel, the following vulnerability has been resolved: drm/tegra: Add call to put_pid() Add a call to put_pid() corresponding to get_t
CVE-2025-40255 In the Linux kernel, the following vulnerability has been resolved: net: core: prevent NULL deref in generic_hwtstamp_ioctl_lower() The ethtool tsc
CVE-2025-68228 In the Linux kernel, the following vulnerability has been resolved: drm/plane: Fix create_in_format_blob() return value create_in_format_blob() is
CVE-2025-68223 In the Linux kernel, the following vulnerability has been resolved: drm/radeon: delete radeon_fence_process in is_signaled, no deadlock Delete the
CVE-2025-40257 In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptcp_pm_del_add_timer() can call
CVE-2025-40258 In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() syzbot reported use-after-fr
CVE-2025-68216 In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Disable trampoline for kernel module function trace The current
CVE-2025-68229 In the Linux kernel, the following vulnerability has been resolved: scsi: target: tcm_loop: Fix segfault in tcm_loop_tpg_address_show() If the allo
CVE-2025-40259 In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Do not sleep in atomic context sg_finish_rem_req() calls blk_rq_unmap
CVE-2025-40260 In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix scx_enable() crash on helper kthread creation failure A crash wa
CVE-2025-40261 In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() nvme_f
CVE-2025-68235 In the Linux kernel, the following vulnerability has been resolved: nouveau/firmware: Add missing kfree() of nvkm_falcon_fw::boot nvkm_falcon_fw::b
CVE-2025-68231 In the Linux kernel, the following vulnerability has been resolved: mm/mempool: fix poisoning order>0 pages with HIGHMEM The kernel test has report
CVE-2025-68217 In the Linux kernel, the following vulnerability has been resolved: Input: pegasus-notetaker - fix potential out-of-bounds access In the pegasus_no
CVE-2025-40262 In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload This is supposed to be "pri
CVE-2025-40263 In the Linux kernel, the following vulnerability has been resolved: Input: cros_ec_keyb - fix an invalid memory access If cros_ec_keyb_register_mat
CVE-2025-68234 In the Linux kernel, the following vulnerability has been resolved: io_uring/cmd_net: fix wrong argument types for skb_queue_splice() If timestamp
CVE-2025-40264 In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called wit
CVE-2025-68225 In the Linux kernel, the following vulnerability has been resolved: lib/test_kho: check if KHO is enabled We must check whether KHO is enabled prio
CVE-2025-68227 In the Linux kernel, the following vulnerability has been resolved: mptcp: Fix proto fallback detection with BPF The sockmap feature allows bpf sys
CVE-2025-68237 In the Linux kernel, the following vulnerability has been resolved: mtdchar: fix integer overflow in read/write ioctls The "req.start" and "req.len
CVE-2025-68212 In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized 'offp' in statmount_string() In statmount_string(), most
CVE-2025-68238 In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: cadence: fix DMA device NULL pointer dereference The DMA device p
CVE-2025-40265 In the Linux kernel, the following vulnerability has been resolved: vfat: fix missing sb_min_blocksize() return value checks When emulating an nvme
CVE-2025-68214 In the Linux kernel, the following vulnerability has been resolved: timers: Fix NULL function pointer race in timer_shutdown_sync() There is a race
CVE-2025-40266 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memory share Verify the offset t

Version: 6.17.0-14.14.1 2026-01-27 06:11:02 UTC

 linux-riscv (6.17.0-14.14.1) questing; urgency=medium
 .
   * questing/linux-riscv: 6.17.0-14.14.1 -proposed tracker (LP: #2137845)
 .
   * Packaging resync (LP: #1786013)
     - [Packaging] debian.riscv/dkms-versions -- update from kernel-versions
       (main/2026.01.12)
 .
   [ Ubuntu: 6.17.0-14.14 ]
 .
   * questing/linux: 6.17.0-14.14 -proposed tracker (LP: #2137849)
   * Packaging resync (LP: #1786013)
     - [Packaging] debian.master/dkms-versions -- update from kernel-versions
       (main/2026.01.12)
   * ubuntu_kselftests:_net/net:gre_gso.sh failing (LP: #2136820)
     - SAUCE increase socat timeout in gre_gso.sh
   * ubuntu_blktrace_smoke_test fails on questing with rust coreutils
     (LP: #2137698)
     - SAUCE: Revert "ext4: fail unaligned direct IO write with EINVAL"
   * bareudp.sh in ubuntu_kselftests_net fails because of dash default shell
     (LP: #2129812)
     - selftests: net: use BASH for bareudp testing
   * CVE-2025-40256
     - xfrm: also call xfrm_state_delete_tunnel at destroy time for states that
       were never added
   * Enable PMF on AMD HPT/STX/KRK (LP: #2125022)
     - platform/x86/amd/pmf: Add support for adjusting PMF PPT and PPT APU
       thresholds
     - platform/x86/amd/pmf: Extend custom BIOS inputs for more policies
     - platform/x86/amd/pmf: Update ta_pmf_action structure member
     - platform/x86/amd/pmf: Add helper to verify BIOS input notifications are
       enable/disable
     - platform/x86/amd/pmf: Add custom BIOS input support for AMD_CPU_ID_PS
     - platform/x86/amd/pmf: Preserve custom BIOS inputs for evaluating the
       policies
     - platform/x86/amd/pmf: Call enact function sooner to process early
       pending requests
     - platform/x86/amd/pmf: Add debug logs for pending requests and custom
       BIOS inputs
   * Questing update: v6.17.8 upstream stable release (LP: #2136850)
     - iommufd/selftest: Fix ioctl return value in _test_cmd_trigger_vevents()
     - drm/mediatek: Add pm_runtime support for GCE power control
     - drm/i915: Fix conversion between clock ticks and nanoseconds
     - drm/amdgpu: set default gfx reset masks for gfx6-8
     - drm/amd/display: Don't stretch non-native images by default in eDP
     - smb: client: fix refcount leak in smb2_set_path_attr
     - iommufd: Make vfio_compat's unmap succeed if the range is already empty
     - futex: Optimize per-cpu reference counting
     - drm/amd: Fix suspend failure with secure display TA
     - drm/xe: Move declarations under conditional branch
     - drm/xe: Do clean shutdown also when using flr
     - drm/amd/display: Add pixel_clock to amd_pp_display_configuration
     - drm/amd/pm: Use pm_display_cfg in legacy DPM (v2)
     - drm/amd/display: Disable fastboot on DCE 6 too
     - drm/amd/pm: Disable MCLK switching on SI at high pixel clocks
     - drm/amd: Disable ASPM on SI
     - arm64: kprobes: check the return value of set_memory_rox()
     - compiler_types: Move unused static inline functions warning to W=2
     - riscv: Build loader.bin exclusively for Canaan K210
     - RISC-V: clear hot-unplugged cores from all task mm_cpumasks to avoid
       rfence errors
     - riscv: acpi: avoid errors caused by probing DT devices when ACPI is used
     - fs: return EOPNOTSUPP from file_setattr/file_getattr syscalls
     - ASoC: nau8821: Avoid unnecessary blocking in IRQ handler
     - NFS4: Fix state renewals missing after boot
     - drm/amdkfd: fix suspend/resume all calls in mes based eviction path
     - NFS4: Apply delay_retrans to async operations
     - HID: intel-thc-hid: intel-quickspi: Add ARL PCI Device Id's
     - HID: quirks: avoid Cooler Master MM712 dongle wakeup bug
     - ixgbe: handle IXGBE_VF_GET_PF_LINK_STATE mailbox operation
     - HID: nintendo: Wait longer for initial probe
     - NFS: check if suid/sgid was cleared after a write as needed
     - HID: quirks: Add ALWAYS_POLL quirk for VRS R295 steering wheel
     - io_uring: fix unexpected placement on same size resizing
     - HID: logitech-hidpp: Add HIDPP_QUIRK_RESET_HI_RES_SCROLL
     - ASoC: max98090/91: fixed max98091 ALSA widget powering up/down
     - ALSA: hda/realtek: Fix mute led for HP Omen 17-cb0xxx
     - ixgbe: handle IXGBE_VF_FEATURES_NEGOTIATE mbox cmd
     - wifi: ath11k: zero init info->status in wmi_process_mgmt_tx_comp()
     - selftests: net: local_termination: Wait for interfaces to come up
     - net: fec: correct rx_bytes statistic for the case SHIFT16 is set
     - net: phy: micrel: Introduce lanphy_modify_page_reg
     - net: phy: micrel: Replace hardcoded pages with defines
     - net: phy: micrel: lan8814 fix reset of the QSGMII interface
     - rust: Add -fno-isolate-erroneous-paths-dereference to
       bindgen_skip_c_flags
     - NFSD: Skip close replay processing if XDR encoding fails
     - Bluetooth: 6lowpan: fix BDADDR_LE vs ADDR_LE_DEV address type confusion
     - Bluetooth: 6lowpan: Don't hold spin lock over sleeping functions
     - Bluetooth: hci_conn: Fix not cleaning up PA_LINK connections
     - net: dsa: tag_brcm: do not mark link local traffic as offloaded
     - net/smc: fix mismatch between CLC header and proposal
     - net/handshake: Fix memory leak in tls_handshake_accept()
     - net: ethernet: ti: am65-cpsw-qos: fix IET verify/response timeout
     - net: ethernet: ti: am65-cpsw-qos: fix IET verify retry mechanism
     - net: mdio: fix resource leak in mdiobus_register_device()
     - wifi: mac80211: skip rate verification for not captured PSDUs
     - Bluetooth: hci_event: Fix not handling PA Sync Lost event
     - net/mlx5e: Fix missing error assignment in mlx5e_xfrm_add_state()
     - net/mlx5e: Fix maxrate wraparound in threshold between units
     - net/mlx5e: Fix wraparound in rate limiting for values above 255 Gbps
     - net/mlx5e: Fix potentially misleading debug message
     - net/mlx5: Fix typo of MLX5_EQ_DOORBEL_OFFSET
     - net/mlx5: Store the global doorbell in mlx5_priv
     - net/mlx5e: Prepare for us

Source diff to previous version
1786013 Packaging resync
2136820 ubuntu_kselftests:_net/net:gre_gso.sh failing
2137698 ubuntu_blktrace_smoke_test fails on questing with rust coreutils
2129812 bareudp.sh in ubuntu_kselftests_net fails because of dash default shell
2136850 Questing update: v6.17.8 upstream stable release
2136833 Questing update: v6.17.8 upstream stable release
2136813 Questing update: v6.17.7 upstream stable release
2132317 [UBUNTU 24.04] KVM: s390: improve interrupt cpu for wakeup
2134982 Questing update: v6.17.6 upstream stable release
2133557 Questing update: v6.17.5 upstream stable release
2132095 The machine didn\u2019t go into suspend and got stuck
2131046 CAP_PERFMON insufficient to get perf data
2128792 Re-enable INTEL_SKL_INT3472 for kernels \u003e= 6.16 for Intel IPU camera
2131259 Questing update: v6.17.4 upstream stable release
2131702 Race condition in perf build causes build failure due to missing unistd_64.h header on arm64
2129610 Questing update: v6.17.3 upstream stable release
CVE-2025-40256 In the Linux kernel, the following vulnerability has been resolved: xfrm: also call xfrm_state_delete_tunnel at destroy time for states that were ne
CVE-2025-68204 In the Linux kernel, the following vulnerability has been resolved: pmdomain: arm: scmi: Fix genpd leak on provider registration failure If of_genp
CVE-2025-68203 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix lock warning in amdgpu_userq_fence_driver_process Fix a potenti
CVE-2025-40267 In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: ensure allocated iovec gets cleared for early failure A previous c
CVE-2025-68198 In the Linux kernel, the following vulnerability has been resolved: crash: fix crashkernel resource shrink When crashkernel is configured with a hi
CVE-2025-68199 In the Linux kernel, the following vulnerability has been resolved: codetag: debug: handle existing CODETAG_EMPTY in mark_objexts_empty for slabobj_
CVE-2025-40268 In the Linux kernel, the following vulnerability has been resolved: cifs: client: fix memory leak in smb3_fs_context_parse_param The user calls fsc
CVE-2025-40269 In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential overflow of PCM transfer buffer The PCM stream d
CVE-2025-68205 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/hdmi: Fix breakage at probing nvhdmi-mcp driver After restructuring a
CVE-2025-40270 In the Linux kernel, the following vulnerability has been resolved: mm, swap: fix potential UAF issue for VMA readahead Since commit 78524b05f1a3 (
CVE-2025-40271 In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through
CVE-2025-40272 In the Linux kernel, the following vulnerability has been resolved: mm/secretmem: fix use-after-free race in fault handler When a page fault occurs
CVE-2025-68245 In the Linux kernel, the following vulnerability has been resolved: net: netpoll: fix incorrect refcount handling causing incorrect cleanup commit
CVE-2025-68240 In the Linux kernel, the following vulnerability has been resolved: nilfs2: avoid having an active sc_timer before freeing sci Because kthread_stop
CVE-2025-68241 In the Linux kernel, the following vulnerability has been resolved: ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe The sit driv
CVE-2025-68211 In the Linux kernel, the following vulnerability has been resolved: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item Curr
CVE-2025-68246 In the Linux kernel, the following vulnerability has been resolved: ksmbd: close accepted socket when per-IP limit rejects connection When the per-
CVE-2025-40273 In the Linux kernel, the following vulnerability has been resolved: NFSD: free copynotify stateid in nfs4_free_ol_stateid() Typically copynotify st
CVE-2025-40212 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix refcount leak in nfsd_set_fh_dentry() nfsd exports a "pseudo root fil
CVE-2025-40274 In the Linux kernel, the following vulnerability has been resolved: KVM: guest_memfd: Remove bindings on memslot deletion when gmem is dying When u
CVE-2025-68202 In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix unsafe locking in the scx_dump_state() For built with CONFIG_PRE
CVE-2025-68239 In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write access before closing files opened by open_exec() bm
CVE-2025-68247 In the Linux kernel, the following vulnerability has been resolved: posix-timers: Plug potential memory leak in do_timer_create() When posix timer
CVE-2025-68208 In the Linux kernel, the following vulnerability has been resolved: bpf: account for current allocated stack depth in widen_imprecise_scalars() The
CVE-2025-68200 In the Linux kernel, the following vulnerability has been resolved: bpf: Add bpf_prog_run_data_pointers() syzbot found that cls_bpf_classify() is a
CVE-2025-40275 In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd In
CVE-2025-68242 In the Linux kernel, the following vulnerability has been resolved: NFS: Fix LTP test failures when timestamps are delegated The utimes01 and utime
CVE-2025-68243 In the Linux kernel, the following vulnerability has been resolved: NFS: Check the TLS certificate fields in nfs_match_client() If the TLS security
CVE-2025-40276 In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Flush shmem writes before mapping buffers CPU-uncached The shmem l
CVE-2025-40277 In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This dat
CVE-2025-68206 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: add seqadj extension for natted connections Sequence adjustm
CVE-2025-68209 In the Linux kernel, the following vulnerability has been resolved: mlx5: Fix default values in create CQ Currently, CQs without a completion funct
CVE-2025-40278 In the Linux kernel, the following vulnerability has been resolved: net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak Fix
CVE-2025-40279 In the Linux kernel, the following vulnerability has been resolved: net: sched: act_connmark: initialize struct tc_ife to fix kernel leak In tcf_co
CVE-2025-40280 In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_mon_reinit_self(). syzbot reported use-after-f
CVE-2025-40281 In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto syzbot
CVE-2025-40282 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: reset link-local header on ipv6 recv path Bluetooth 6lowpan
CVE-2025-40283 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF There is a K
CVE-2025-40284 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: cancel mesh send timer when hdev removed mesh_send_done timer
CVE-2025-68210 In the Linux kernel, the following vulnerability has been resolved: erofs: avoid infinite loop due to incomplete zstd-compressed data Currently, th
CVE-2025-40285 In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of
CVE-2025-40286 In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible memory leak in smb2_read() Memory leak occurs when ksm
CVE-2025-40287 In the Linux kernel, the following vulnerability has been resolved: exfat: fix improper check of dentry.stream.valid_size We found an infinite loop
CVE-2025-40288 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix NULL pointer dereference in VRAM logic for APU devices Previous
CVE-2025-40289 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM Otherwise accessing
CVE-2025-68201 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: remove two invalid BUG_ON()s Those can be triggered trivially by us
CVE-2025-68207 In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Synchronize Dead CT worker with unbind Cancel and wait for any Dead
CVE-2025-68244 In the Linux kernel, the following vulnerability has been resolved: drm/i915: Avoid lock inversion when pinning to GGTT on CHV/BXT+VTD On completio
CVE-2025-68316 In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix invalid probe error return value After DME Link Startup, t
CVE-2025-40292 In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix received length check in big packets Since commit 4959aebba8c0
CVE-2025-68180 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL deref in debugfs odm_combine_segments When a connecto
CVE-2025-40327 In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix system hang caused by cpu-clock usage cpu-clock usage by the asy
CVE-2025-40328 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_close_cached_fid() find_or_create_cached
CVE-2025-40291 In the Linux kernel, the following vulnerability has been resolved: io_uring: fix regbuf vector size truncation There is a report of io_estimate_bv
CVE-2025-68322 In the Linux kernel, the following vulnerability has been resolved: parisc: Avoid crash due to unaligned access in unwinder Guenter Roeck reported
CVE-2025-40293 In the Linux kernel, the following vulnerability has been resolved: iommufd: Don't overflow during division for dirty tracking If pgshift is 63 the
CVE-2025-40294 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern() In the parse_adv
CVE-2025-40329 In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix deadlock in drm_sched_entity_kill_jobs_cb The Mesa issue referen
CVE-2025-40295 In the Linux kernel, the following vulnerability has been resolved: fscrypt: fix left shift underflow when inode->i_blkbits > PAGE_SHIFT When simul
CVE-2025-40296 In the Linux kernel, the following vulnerability has been resolved: platform/x86: int3472: Fix double free of GPIO device during unregister regulat
CVE-2025-40297 In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix use-after-free due to MST port state bypass syzbot reported[1]
CVE-2025-68320 In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix sleeping in atomic context The following warning was seen when we
CVE-2025-68169 In the Linux kernel, the following vulnerability has been resolved: netpoll: Fix deadlock in memory allocation under spinlock Fix a AA deadlock in
CVE-2025-68197 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix null pointer dereference in bnxt_bs_trace_check_wrap() With older
CVE-2025-40330 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Shutdown FW DMA in bnxt_shutdown() The netif_close() call in bnxt_shut
CVE-2025-68192 In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup Raw IP pack
CVE-2025-40331 In the Linux kernel, the following vulnerability has been resolved: sctp: Prevent TOCTOU out-of-bounds write For the following path not holding the
CVE-2025-68187 In the Linux kernel, the following vulnerability has been resolved: net: mdio: Check regmap pointer returned by device_node_to_regmap() The call to
CVE-2025-68167 In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix invalid pointer access in debugfs If the memory allocation in gpio
CVE-2025-68319 In the Linux kernel, the following vulnerability has been resolved: netconsole: Acquire su_mutex before navigating configs hierarchy There is a rac
CVE-2025-40298 In the Linux kernel, the following vulnerability has been resolved: gve: Implement settime64 with -EOPNOTSUPP ptp_clock_settime() assumes every ptp
CVE-2025-40299 In the Linux kernel, the following vulnerability has been resolved: gve: Implement gettimex64 with -EOPNOTSUPP gve implemented a ptp_clock for sole
CVE-2025-40301 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: validate skb length for unknown CC opcode In hci_cmd_comp
CVE-2025-40358 In the Linux kernel, the following vulnerability has been resolved: riscv: stacktrace: Disable KASAN checks for non-current tasks Unwinding the sta
CVE-2025-68186 In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Do not warn in ring_buffer_map_get_reader() when reader catches up
CVE-2025-68184 In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Disable AFBC support on Mediatek DRM driver Commit c410fa9b07c3 (
CVE-2025-40302 In the Linux kernel, the following vulnerability has been resolved: media: videobuf2: forbid remove_bufs when legacy fileio is active vb2_ioctl_rem
CVE-2025-40303 In the Linux kernel, the following vulnerability has been resolved: btrfs: ensure no dirty metadata is written back for an fs with errors [BUG] Dur
CVE-2025-40362 In the Linux kernel, the following vulnerability has been resolved: ceph: fix multifs mds auth caps issue The mds auth caps check should also valid
CVE-2025-40332 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix mmap write lock not release If mmap write lock is taken while d
CVE-2025-40304 In the Linux kernel, the following vulnerability has been resolved: fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds Add bounds
CVE-2025-40305 In the Linux kernel, the following vulnerability has been resolved: 9p/trans_fd: p9_fd_request: kick rx thread if EPOLLIN p9_read_work() doesn't se
CVE-2025-68318 In the Linux kernel, the following vulnerability has been resolved: clk: thead: th1520-ap: set all AXI clocks to CLK_IS_CRITICAL The AXI crossbar o
CVE-2025-40209 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak of qgroup_list in btrfs_add_qgroup_relation When btrfs_a
CVE-2025-68183 In the Linux kernel, the following vulnerability has been resolved: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr Current
CVE-2025-68173 In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix softlockup in ftrace_module_enable A soft lockup was observed when
CVE-2025-40306 In the Linux kernel, the following vulnerability has been resolved: orangefs: fix xattr related buffer overflow... Willy Tarreau <w@1wt.eu> forward
CVE-2025-40307 In the Linux kernel, the following vulnerability has been resolved: exfat: validate cluster allocation bits of the allocation bitmap syzbot created
CVE-2025-40308 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bcsp: receive data only if registered Currently, bcsp_recv() can be
CVE-2025-40309 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix UAF on sco_conn_free BUG: KASAN: slab-use-after-free in sco
CVE-2025-68174 In the Linux kernel, the following vulnerability has been resolved: amd/amdkfd: enhance kfd process check in switch partition current switch partit
CVE-2025-40310 In the Linux kernel, the following vulnerability has been resolved: amd/amdkfd: resolve a race in amdgpu_amdkfd_device_fini_sw There is race in amd
CVE-2025-40361 In the Linux kernel, the following vulnerability has been resolved: fs: ext4: change GFP_KERNEL to GFP_NOFS to avoid deadlock The parent function e
CVE-2025-40311 In the Linux kernel, the following vulnerability has been resolved: accel/habanalabs: support mapping cb with vmalloc-backed coherent memory When I
CVE-2025-68185 In the Linux kernel, the following vulnerability has been resolved: nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing
CVE-2025-68176 In the Linux kernel, the following vulnerability has been resolved: PCI: cadence: Check for the existence of cdns_pcie::ops before using it cdns_pc
CVE-2025-68190 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_lock
CVE-2025-68168 In the Linux kernel, the following vulnerability has been resolved: jfs: fix uninitialized waitqueue in transaction manager The transaction manager
CVE-2025-40312 In the Linux kernel, the following vulnerability has been resolved: jfs: Verify inode mode when loading from disk The inode mode loaded from corrup
CVE-2025-40333 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix infinite loop in __insert_extent_tree() When we get wrong extent info
CVE-2025-68321 In the Linux kernel, the following vulnerability has been resolved: page_pool: always add GFP_NOWARN for ATOMIC allocations Driver authors often fo
CVE-2025-40334 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate userq buffer virtual address and size It needs to validate
CVE-2025-68191 In the Linux kernel, the following vulnerability has been resolved: udp_tunnel: use netdev_warn() instead of netdev_WARN() netdev_WARN() uses WARN/
CVE-2025-68309 In the Linux kernel, the following vulnerability has been resolved: PCI/AER: Fix NULL pointer access by aer_info The kzalloc(GFP_KERNEL) may return
CVE-2025-40313 In the Linux kernel, the following vulnerability has been resolved: ntfs3: pretend $Extend records as regular files Since commit af153bb63a33 ("vfs
CVE-2025-40335 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate userq input args This will help on validating the userq in
CVE-2025-40314 In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: gadget: Use-after-free during failed initialization and exit of cdns
CVE-2025-40336 In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: fix hmm_pfn_to_map_order() usage Handle the case where the hmm rang
CVE-2025-68193 In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Add devm release action to safely tear down CT When a buffer object
CVE-2025-68175 In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: Fix streaming cleanup on release The current implementati
CVE-2025-68188 In the Linux kernel, the following vulnerability has been resolved: tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() Use RCU to av
CVE-2025-68315 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to detect potential corrupted nid in free_nid_list As reported, on-di
CVE-2025-40337 In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Correctly handle Rx checksum offload errors The stmmac_rx function
CVE-2025-40338 In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Do not share the name pointer between components By sharing '
CVE-2025-40339 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix nullptr err of vm_handle_moved If a amdgpu_bo_va is fpriv->prt_
CVE-2025-68194 In the Linux kernel, the following vulnerability has been resolved: media: imon: make send_packet() more robust syzbot is reporting that imon has t
CVE-2025-40363 In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix field-spanning memcpy warning in AH output Fix field-spanning me
CVE-2025-68311 In the Linux kernel, the following vulnerability has been resolved: tty: serial: ip22zilog: Use platform device for probing After commit 84a9582fd2
CVE-2025-40340 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix oops in xe_gem_fault when running core_hotunplug test. I saw an oop
CVE-2025-68196 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Cache streams targeting link when performing LT automation [WH
CVE-2025-68178 In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix possible deadlock while configuring policy Following deadlock c
CVE-2025-40341 In the Linux kernel, the following vulnerability has been resolved: futex: Don't leak robust_list pointer on exec race sys_get_robust_list() and co
CVE-2025-40342 In the Linux kernel, the following vulnerability has been resolved: nvme-fc: use lock accessing port_state and rport state nvme_fc_unregister_remot
CVE-2025-40343 In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid scheduling association deletion twice When forcefully shutting
CVE-2025-68177 In the Linux kernel, the following vulnerability has been resolved: cpufreq/longhaul: handle NULL policy in longhaul_exit longhaul_exit() was calli
CVE-2025-68317 In the Linux kernel, the following vulnerability has been resolved: io_uring/zctx: check chained notif contexts Send zc only links ubuf_info for re
CVE-2025-40315 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix epfile null pointer access after ep enable. A race condi
CVE-2025-40316 In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix device use-after-free on unbind A recent change fixed device
CVE-2025-40360 In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: Do not dereference NULL pointer in plane reset The plane state in __
CVE-2025-68179 In the Linux kernel, the following vulnerability has been resolved: s390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP As reported by Luiz Capitulino
CVE-2025-68310 In the Linux kernel, the following vulnerability has been resolved: s390/pci: Avoid deadlock between PCI error recovery and mlx5 crdump Do not bloc
CVE-2025-40317 In the Linux kernel, the following vulnerability has been resolved: regmap: slimbus: fix bus_context pointer in regmap init calls Commit 4e65bda827
CVE-2025-40359 In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix KASAN global-out-of-bounds warning When running "perf mem r
CVE-2025-68181 In the Linux kernel, the following vulnerability has been resolved: drm/radeon: Remove calls to drm_put_dev() Since the allocation of the drivers m
CVE-2025-68170 In the Linux kernel, the following vulnerability has been resolved: drm/radeon: Do not kfree() devres managed rdev Since the allocation of the driv
CVE-2025-40213 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a BU
CVE-2025-40318 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once hci_cmd_sync_dequeue
CVE-2025-68312 In the Linux kernel, the following vulnerability has been resolved: usbnet: Prevents free active kevent The root cause of this issue are: 1. When p
CVE-2025-40344 In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Disable periods-elapsed work when closing PCM avs_dai_fe_shut
CVE-2025-68172 In the Linux kernel, the following vulnerability has been resolved: crypto: aspeed - fix double free caused by devm The clock obtained via devm_clk
CVE-2025-40319 In the Linux kernel, the following vulnerability has been resolved: bpf: Sync pending IRQ work before freeing ring buffer Fix a race where irq_work
CVE-2025-68182 In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix potential use after free in iwl_mld_remove_link() This code
CVE-2025-68314 In the Linux kernel, the following vulnerability has been resolved: drm/msm: make sure last_fence is always updated Update last_fence in the vm-bin
CVE-2025-68189 In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix GEM free for imported dma-bufs Imported dma-bufs also have obj->re
CVE-2025-68171 In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Ensure XFD state on signal delivery Sean reported [1] the following sp
CVE-2025-68313 In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Add RDSEED fix for Zen5 There's an issue with RDSEED's 16-bit and
CVE-2025-40320 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential cfid UAF in smb2_query_info_compound When smb2_query
CVE-2025-40321 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode Cur
CVE-2025-40322 In the Linux kernel, the following vulnerability has been resolved: fbdev: bitblit: bound-check glyph index in bit_putcs* bit_putcs_aligned()/unali
CVE-2025-40211 In the Linux kernel, the following vulnerability has been resolved: ACPI: video: Fix use-after-free in acpi_video_switch_brightness() The switch_br
CVE-2025-40323 In the Linux kernel, the following vulnerability has been resolved: fbcon: Set fb_display[i]->mode to NULL when the mode is released Recently, we d
CVE-2025-40210 In the Linux kernel, the following vulnerability has been resolved: Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" I've f
CVE-2025-40324 In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix crash in nfsd4_read_release() When tracing is enabled, the trace_nfsd
CVE-2025-40326 In the Linux kernel, the following vulnerability has been resolved: NFSD: Define actions for the new time_deleg FATTR4 attributes NFSv4 clients won
CVE-2025-40084 In the Linux kernel, the following vulnerability has been resolved: ksmbd: transport_ipc: validate payload size before reading handle handle_respon
CVE-2025-40222 In the Linux kernel, the following vulnerability has been resolved: tty: serial: sh-sci: fix RSCI FIFO overrun handling The receive error handling
CVE-2025-40223 In the Linux kernel, the following vulnerability has been resolved: most: usb: Fix use-after-free in hdm_disconnect hdm_disconnect() calls most_der
CVE-2025-40106 In the Linux kernel, the following vulnerability has been resolved: comedi: fix divide-by-zero in comedi_buf_munge() The comedi_buf_munge() functio
CVE-2025-40224 In the Linux kernel, the following vulnerability has been resolved: hwmon: (cgbc-hwmon) Add missing NULL check after devm_kzalloc() The driver allo
CVE-2025-40225 In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix kernel panic on partial unmap of a GPU VA region This commit a
CVE-2025-40226 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Account for failed debug initialization When the SCMI debug
CVE-2025-40227 In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: dealloc commit test ctx always The damon_ctx for testing online
CVE-2025-40228 In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: catch commit test ctx alloc failure Patch series "mm/damon/sysf
CVE-2025-40229 In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: fix potential memory leak by cleaning ops_filter in damon_destroy
CVE-2025-40230 In the Linux kernel, the following vulnerability has been resolved: mm: prevent poison consumption when splitting THP When performing memory error
CVE-2025-40231 In the Linux kernel, the following vulnerability has been resolved: vsock: fix lock inversion in vsock_assign_transport() Syzbot reported a potenti
CVE-2025-40233 In the Linux kernel, the following vulnerability has been resolved: ocfs2: clear extent cache after moving/defragmenting extents The extent map cac
CVE-2025-40235 In the Linux kernel, the following vulnerability has been resolved: btrfs: directly free partially initialized fs_info in btrfs_check_leaked_roots()
CVE-2025-40236 In the Linux kernel, the following vulnerability has been resolved: virtio-net: zero unused hash fields When GSO tunnel is negotiated virtio_net_hd
CVE-2025-40237 In the Linux kernel, the following vulnerability has been resolved: fs/notify: call exportfs_encode_fid with s_umount Calling intotify_show_fdinfo(
CVE-2025-40238 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix IPsec cleanup over MPV device When we do mlx5e_detach_netdev() we
CVE-2025-40239 In the Linux kernel, the following vulnerability has been resolved: net: phy: micrel: always set shared->phydev for LAN8814 Currently, during the L
CVE-2025-40240 In the Linux kernel, the following vulnerability has been resolved: sctp: avoid NULL dereference when chunk data buffer is missing chunk->skb point
CVE-2025-40241 In the Linux kernel, the following vulnerability has been resolved: erofs: fix crafted invalid cases for encoded extents Robert recently reported t
CVE-2025-40242 In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix unlikely race in gdlm_put_lock In gdlm_put_lock(), there is a small w
CVE-2025-40243 In the Linux kernel, the following vulnerability has been resolved: hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits() The syzbot report
CVE-2025-40244 In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent() The syzbo
CVE-2025-40245 In the Linux kernel, the following vulnerability has been resolved: nios2: ensure that memblock.current_limit is set when setting pfn limits On nio
CVE-2025-40086 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't allow evicting of BOs in same VM in array of VM binds An array of
CVE-2025-40087 In the Linux kernel, the following vulnerability has been resolved: NFSD: Define a proc_layoutcommit for the FlexFiles layout type Avoid a crash if
CVE-2025-40088 In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp() The hfsplus_strcas
CVE-2025-40162 In the Linux kernel, the following vulnerability has been resolved: ASoC: amd/sdw_utils: avoid NULL deref when devm_kasprintf() fails devm_kasprint
CVE-2025-40085 In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card In try_to_r
CVE-2025-40172 In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages() Currentl
CVE-2025-40177 In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Fix bootlog initialization ordering As soon as we queue MHI buffers
CVE-2025-40163 In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Stop dl_server before CPU goes offline IBM CI tool reported ker
CVE-2025-40174 In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix SMP ordering in switch_mm_irqs_off() Stephen noted that it is possi
CVE-2025-40089 In the Linux kernel, the following vulnerability has been resolved: cxl/features: Add check for no entries in cxl_feature_info cxl EDAC calls cxl_f
CVE-2025-40176 In the Linux kernel, the following vulnerability has been resolved: tls: wait for pending async decryptions if tls_strp_msg_hold fails Async decryp
CVE-2025-40164 In the Linux kernel, the following vulnerability has been resolved: usbnet: Fix using smp_processor_id() in preemptible code warnings Syzbot report
CVE-2025-40091 In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix too early devlink_free() in ixgbe_remove() Since ixgbe_adapter is em
CVE-2025-40175 In the Linux kernel, the following vulnerability has been resolved: idpf: cleanup remaining SKBs in PTP flows When the driver requests Tx timestamp
CVE-2025-40173 In the Linux kernel, the following vulnerability has been resolved: net/ip6_tunnel: Prevent perpetual tunnel growth Similarly to ipv4 tunnel, ipv6
CVE-2025-40092 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Refactor bind path to use __free() After an bind/unbind cyc
CVE-2025-40093 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ecm: Refactor bind path to use __free() After an bind/unbind cyc
CVE-2025-40094 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_acm: Refactor bind path to use __free() After an bind/unbind cyc
CVE-2025-40095 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_rndis: Refactor bind path to use __free() After an bind/unbind c
CVE-2025-40165 In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: m2m: Fix streaming cleanup on release If streamon/streamo
CVE-2025-40096 In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies Whe
CVE-2025-40097 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix missing pointer check in hda_component_manager_init function The
CVE-2025-40098 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state(
CVE-2025-40099 In the Linux kernel, the following vulnerability has been resolved: cifs: parse_dfs_referrals: prevent oob on malformed input Malicious SMB server
CVE-2025-40100 In the Linux kernel, the following vulnerability has been resolved: btrfs: do not assert we found block group item when creating free space tree Cu
CVE-2025-40101 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leaks when rejecting a non SINGLE data profile without an RST
CVE-2025-40167 In the Linux kernel, the following vulnerability has been resolved: ext4: detect invalid INLINE_DATA + EXTENTS flag combination syzbot reported a B
CVE-2025-40102 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Prevent access to vCPU events before init Another day, another syzk
CVE-2025-40103 In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix refcount leak for cifs_sb_tlink Fix three refcount inconsisten
CVE-2025-40104 In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix mailbox API compatibility by negotiating supported features There
CVE-2025-40166 In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Check GuC running state before deregistering exec queue In normal o
CVE-2025-40105 In the Linux kernel, the following vulnerability has been resolved: vfs: Don't leak disconnected dentries on umount When user calls open_by_handle_
CVE-2025-40019 In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-place encryption Move the ssi
CVE-2025-40214 In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF

Version: 6.17.0-9.9.1 2025-12-12 18:09:03 UTC

 linux-riscv (6.17.0-9.9.1) questing; urgency=medium
 .
   * questing/linux-riscv: 6.17.0-9.9.1 -proposed tracker (LP: #2133508)
 .
   [ Ubuntu: 6.17.0-9.9 ]
 .
   * questing/linux: 6.17.0-9.9 -proposed tracker (LP: #2132302)
   * The machine didn’t go into suspend and got stuck (LP: #2132095)
     - platform/x86: alienware-wmi-wmax: Fix NULL pointer dereference in sleep
       handlers
   * CAP_PERFMON insufficient to get perf data (LP: #2131046)
     - SAUCE: perf/core: Allow CAP_PERFMON for paranoid level 4
   * Poweroff not working consistently after upgrading kernel 6.14.0-17.17 or
     later (LP: #2115860)
     - drm/amd: Unify shutdown() callback behavior
     - drm/amd: Stop exporting amdgpu_device_ip_suspend() outside amdgpu_device
     - drm/amd: Remove comment about handling errors in
       amdgpu_device_ip_suspend_phase1()
     - drm/amd: Don't always set IP block HW status to false
     - drm/amd: Pass IP suspend errors up to callers
     - drm/amd: Avoid evicting resources at S5
   * kernel crash on bootup for some arm64 machines (LP: #2129770)
     - KVM: arm64: Guard PMSCR_EL1 initialization with SPE presence check
   * crash when reading from /sys/kernel/tracing/rv/enabled_monitors
     (LP: #2131136)
     - rv: Fully convert enabled_monitors to use list_head as iterator
   * i40e driver is triggering VF resets on every link state change
     (LP: #2130552)
     - i40e: avoid redundant VF link state updates
   * Re-enable INTEL_SKL_INT3472 for kernels >= 6.16 for Intel IPU camera
     (LP: #2128792)
     - Revert "UBUNTU: [Config] FTBFS: disable INTEL_SKL_INT3472"
     - Revert "UBUNTU: SAUCE: platform/x86: int3472: Add handshake GPIO
       function"
   * Support Samsung S5K3J1 sensor for Intel MIPI camera (LP: #2121852)
     - SAUCE: media: ipu-bridge: Support s5k3j1 sensor
   * Questing update: v6.17.4 upstream stable release (LP: #2131259)
     - fs: always return zero on success from replace_fd()
     - fscontext: do not consume log entries when returning -EMSGSIZE
     - btrfs: fix the incorrect max_bytes value for find_lock_delalloc_range()
     - arm64: map [_text, _stext) virtual address range non-executable+read-
       only
     - rseq: Protect event mask against membarrier IPI
     - statmount: don't call path_put() under namespace semaphore
     - listmount: don't call path_put() under namespace semaphore
     - clocksource/drivers/clps711x: Fix resource leaks in error paths
     - memcg: skip cgroup_file_notify if spinning is not allowed
     - page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches
     - PM: runtime: Update kerneldoc return codes
     - dma-mapping: fix direction in dma_alloc direction traces
     - cpufreq: Make drivers using CPUFREQ_ETERNAL specify transition latency
     - nfsd: unregister with rpcbind when deleting a transport
     - KVM: x86: Add helper to retrieve current value of user return MSR
     - KVM: SVM: Emulate PERF_CNTR_GLOBAL_STATUS_SET for PerfMonV2
     - iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE
     - media: v4l2-subdev: Fix alloc failure check in
       v4l2_subdev_call_state_try()
     - asm-generic/io.h: Skip trace helpers if rwmmio events are disabled
     - clk: npcm: select CONFIG_AUXILIARY_BUS
     - clk: thead: th1520-ap: describe gate clocks with clk_gate
     - clk: thead: th1520-ap: fix parent of padctrl0 clock
     - clk: thead: Correct parent for DPU pixel clocks
     - clk: renesas: r9a08g045: Add MSTOP for GPIO
     - perf disasm: Avoid undefined behavior in incrementing NULL
     - perf test trace_btf_enum: Skip if permissions are insufficient
     - perf evsel: Avoid container_of on a NULL leader
     - libperf event: Ensure tracing data is multiple of 8 sized
     - clk: qcom: common: Fix NULL vs IS_ERR() check in qcom_cc_icc_register()
     - clk: qcom: Select the intended config in QCS_DISPCC_615
     - perf parse-events: Handle fake PMUs in CPU terms
     - clk: at91: peripheral: fix return value
     - clk: renesas: cpg-mssr: Fix memory leak in cpg_mssr_reserved_init()
     - perf: Completely remove possibility to override MAX_NR_CPUS
     - perf drm_pmu: Fix fd_dir leaks in for_each_drm_fdinfo_in_dir()
     - perf util: Fix compression checks returning -1 as bool
     - rtc: x1205: Fix Xicor X1205 vendor prefix
     - rtc: optee: fix memory leak on driver removal
     - perf arm_spe: Correct setting remote access
     - perf arm_spe: Correct memory level for remote access
     - perf vendor events arm64 AmpereOneX: Fix typo - should be
       l1d_cache_access_prefetches
     - perf test: AMD IBS swfilt skip kernel tests if paranoia is >1
     - perf test shell lbr: Avoid failures with perf event paranoia
     - perf trace: Fix IS_ERR() vs NULL check bug
     - perf session: Fix handling when buffer exceeds 2 GiB
     - perf test: Don't leak workload gopipe in PERF_RECORD_*
     - perf evsel: Fix uniquification when PMU given without suffix
     - perf test: Avoid uncore_imc/clockticks in uniquification test
     - perf evsel: Ensure the fallback message is always written to
     - perf build-id: Ensure snprintf string is empty when size is 0
     - clk: mediatek: mt8195-infra_ao: Fix parent for infra_ao_hdmi_26m
     - clk: mediatek: clk-mux: Do not pass flags to
       clk_mux_determine_rate_flags()
     - clk: nxp: lpc18xx-cgu: convert from round_rate() to determine_rate()
     - clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver
     - clk: tegra: do not overallocate memory for bpmp clocks
     - nfsd: fix assignment of ia_ctime.tv_nsec on delegated mtime update
     - nfsd: ignore ATTR_DELEG when checking ia_valid before notify_change()
     - vfs: add ATTR_CTIME_SET flag
     - nfsd: use ATTR_CTIME_SET for delegated ctime updates
     - nfsd: track original timestamps in nfs4_delegation
     - nfsd: fix SETATTR updates for delegated timestamps
     - nfsd: fix timestamp updates in CB_GETATTR
     - tracing: Fix the bug where bpf_get_stack

Source diff to previous version
2132095 The machine didn\u2019t go into suspend and got stuck
2131046 CAP_PERFMON insufficient to get perf data
2129770 kernel crash on bootup for some arm64 machines
2131136 crash when reading from /sys/kernel/tracing/rv/enabled_monitors
2130552 i40e driver is triggering VF resets on every link state change
2128792 Re-enable INTEL_SKL_INT3472 for kernels \u003e= 6.16 for Intel IPU camera
2131259 Questing update: v6.17.4 upstream stable release
2131702 Race condition in perf build causes build failure due to missing unistd_64.h header on arm64
2129610 Questing update: v6.17.3 upstream stable release
CVE-2025-40019 In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-place encryption Move the ssi
CVE-2025-40018 In the Linux kernel, the following vulnerability has been resolved: ipvs: Defer ip_vs_ftp unregister during netns cleanup On the netns cleanup path

Version: 6.17.0-7.7.1 2025-10-31 07:08:11 UTC

 linux-riscv (6.17.0-7.7.1) questing; urgency=medium
 .
   * questing/linux-riscv: 6.17.0-7.7.1 -proposed tracker (LP: #2128694)
 .
   [ Ubuntu: 6.17.0-7.7 ]
 .
   * questing/linux: 6.17.0-7.7 -proposed tracker (LP: #2128695)
   * Fix incorrect bug number for CONFIG_KERNEL_ZSTD (LP: #2127676)
     - [Config] Fix bug note for CONFIG_KERNEL_ZSTD
   * support Panter Lake CPU performance preferences (LP: #2127187)
     - thermal: intel: int340x: Add support for power slider
     - thermal: intel: int340x: Enable power slider interface for Panther Lake
     - thermal: intel: int340x: Add module parameter for balanced Slider
     - thermal: intel: int340x: Add module parameter to change slider offset
     - thermal: intel: int340x: Power Slider: Validate slider_balance range
   * [SRU][Q/P/N:hwe-6.14] mt7925: Add MBSS support (LP: #2119479)
     - wifi: mt76: mt7925: add MBSSID support
   * Plucky preinstalled server fails to boot on rb3gen2 (LP: #2106681) //
     Questing preinstalled server fails to boot on sa8775p boards
     (LP: #2121347)
     - [Config] move more qcom interconnect/pinctrl/gcc options to builtin
   * Packaging resync (LP: #1786013)
     - [Packaging] update Ubuntu.md
   * r8169 can not wake on LAN via SFP moudule (LP: #2123901)
     - r8169: set EEE speed down ratio to 1
   * System hangs when running the memory stress test (LP: #2103680)
     - mm: page_alloc: avoid kswapd thrashing due to NUMA restrictions
   * Questing update: v6.17.2 upstream stable release (LP: #2128209)
     - drm/amdgpu: Enable MES lr_compute_wa by default
     - USB: serial: option: add SIMCom 8230C compositions
     - Bluetooth: btusb: Add USB ID 2001:332a for D-Link AX9U rev. A1
     - wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188
     - wifi: rtl8xxxu: Don't claim USB ID 07b8:8188
     - rust: drm: fix `srctree/` links
     - rust: block: fix `srctree/` links
     - rust: pci: fix incorrect platform reference in PCI driver probe doc
       comment
     - rust: pci: fix incorrect platform reference in PCI driver unbind doc
       comment
     - serial: qcom-geni: Fix blocked task
     - nvmem: layouts: fix automatic module loading
     - drivers/misc/amd-sbi/Kconfig: select REGMAP_I2C
     - binder: fix double-free in dbitmap
     - serial: stm32: allow selecting console when the driver is module
     - [Config] stm32: do not select console when driver is module
     - staging: axis-fifo: fix maximum TX packet length check
     - staging: axis-fifo: fix TX handling on copy_from_user() failure
     - staging: axis-fifo: flush RX FIFO on read errors
     - driver core: faux: Set power.no_pm for faux devices
     - driver core/PM: Set power.no_callbacks along with power.no_pm
     - Revert "crypto: testmgr - desupport SHA-1 for FIPS 140"
     - crypto: zstd - Fix compression bug caused by truncation
     - crypto: rng - Ensure set_ent is always present
     - net/9p: fix double req put in p9_fd_cancelled
     - KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
     - f2fs: fix to do sanity check on node footer for non inode dnode
     - ring buffer: Propagate __rb_map_vma return value to caller
     - Linux 6.17.2

2127676 Fix incorrect bug number for CONFIG_KERNEL_ZSTD
2127187 support Panter Lake CPU performance preferences
2106681 Plucky preinstalled server fails to boot on rb3gen2
2121347 Questing preinstalled server fails to boot on sa8775p boards
1786013 Packaging resync
2123901 r8169 can not wake on LAN via SFP moudule
2103680 System hangs when running the memory stress test
2128209 Questing update: v6.17.2 upstream stable release



About   -   Send Feedback to @ubuntu_updates