UbuntuUpdates.org

Package "linux-libc-dev"

This package belongs to a PPA: Canonical Kernel Team

Name: linux-libc-dev

Description:

Linux Kernel Headers for development

Latest version: 7.0.0-37.37
Release: resolute (26.04)
Level: base
Repository: main
Head package: linux

Links


Download "linux-libc-dev"


Other versions of "linux-libc-dev" in Resolute

Repository Area Version
base main 7.0.0-14.14
security main 7.0.0-30.30
updates main 7.0.0-30.30
proposed main 7.0.0-31.31

Changelog

Version: 7.0.0-37.37 2026-09-02 14:09:15 UTC

 linux (7.0.0-37.37) resolute; urgency=medium
 .
   * resolute/linux: 7.0.0-37.37 -proposed tracker (LP: #2165979)
 .
   * #510/p sleepable raw tracepoint reject from test_verifier in ubuntu_bpf
     failed with resolute (7.0.0-33.33) generic amd64 (LP: #2165872)
     - SAUCE: Revert "bpf: Verifier support for sleepable tracepoint programs"
 .
   * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189)
     - platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug
     - selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs
     - drm/virtio: fix deadlock in display_info_cb by removing hotplug from
       dequeue worker
     - seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
     - KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN
     - crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin
     - xprtrdma: Clear receive-side ownership pointers on release
     - Input: ims-pcu - fix logic error in packet reset
     - fuse: fix writeback array overflow when max_pages is one
     - arm64: tegra: Remove fallback compatible for GPCDMA
     - arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
     - xfrm: propagate -EINPROGRESS from validate_xmit_xfrm()
     - mtd: mtdswap: remove debugfs stats file on teardown
     - mtd: nand: mtk-ecc: stop on ECC idle timeouts
     - btrfs: fallback to transaction csum tree on a commit root csum miss
     - RDMA/cma: Fix hardware address comparison length in netevent callback
     - RDMA/irdma: Remove redundant legacy_mode checks
     - RDMA/erdma: initialize ret for empty receive WR lists
     - RDMA/mana_ib: initialize err for empty send WR lists
     - RDMA/hns: Fix potential integer overflow in mhop hem cleanup
     - selftests/alsa: Fix memory leak in find_controls error path
     - RDMA/irdma: Prevent overflows in memory contiguity checks
     - wifi: cfg80211: derive S1G beacon TSF from S1G fields
     - wifi: nl80211: validate nested MBSSID IE blobs
     - wifi: nl80211: constrain MBSSID TX link ID range
     - wifi: cfg80211: validate PMSR measurement type data
     - wifi: cfg80211: reject unsupported PMSR FTM location requests
     - wifi: mac80211: avoid non-S1G AID fallback for S1G assoc
     - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on
       start/stop
     - ASoC: amd: ps: disable MSI on resume in ACP PCI driver
     - ASoC: amd: ps: fix wrong ACP version string in pci_request_regions()
     - ASoC: amd: ps: replace bitwise OR with logical OR in IRQ return check
     - ASoC: cs42l43: Correct report for forced microphone jack
     - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after
       lookup
     - firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
     - cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq
     - udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
     - ata: sata_dwc_460ex: use platform_get_irq()
     - ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending
       interrupts
     - accel/ivpu: Fix wrong register read in LNL failure diagnostics
     - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
     - drm/i915/gt: use correct selftest config symbol
     - powerpc/85xx: Add fsl,ifc to common device ids
     - powerpc/time: Prepare to stop elapsing in dynticks-idle
     - powerpc/vtime: Initialize starttime at boot for native accounting
     - drm/panthor: Check debugfs GEM lock initialization
     - riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
     - can: j1939: fix lockless local-destination check
     - drm/xe/wopcm: fix WOPCM size for LNL+
     - drm/i915/wm: clear the plane ddb_y entries on plane disable
     - drm/i915/selftests: Fix GT PM sort comparators
     - USB: storage: add NO_ATA_1X quirk for Longmai USB Key
     - usb: chipidea: fix usage_count leak when autosuspend_delay is negative
     - USB: gadget: snps-udc: fix device name leak on probe failure
     - USB: gadget: fsl-udc: fix device name leak on probe failure
     - USB: gadget: fsl-udc: fix dev_printk() device
     - USB: serial: ftdi_sio: add support for E+H FXA291
     - USB: serial: keyspan_pda: fix data loss on receive throttling
     - USB: serial: option: add TDTECH MT5710-CN
     - SAUCE: Revert "usb: typec: ucsi: Detect and skip duplicate altmodes from
       buggy firmware"
     - usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware
     - wifi: mwifiex: fix freeze for 60 seconds caused by request_firmware
     - RISC-V: KVM: Serialize virtual interrupt pending state updates
     - Revert "drm/amd/display: Add missing kdoc for ALLM parameters"
     - usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
     - selftests/bpf: Adjust verifier_map_ptr for the map's excl field
     - selftests/bpf: Keep verifier_map_ptr exercising ops pointer access
     - wifi: ath11k: Flush the posted write after writing to
       PCIE_SOC_GLOBAL_RESET
     - wifi: ath12k: Flush the posted write after writing to
       PCIE_SOC_GLOBAL_RESET
     - btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
     - btrfs: fix u32 to s64 type conversion in dirty_metadata_bytes accounting
     - ASoC: sun4i-codec: Set quirks.playback_only for H616 codec
     - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
     - ASoC: cs35l56: Don't use devres to unregister component
     - ASoC: cs35l56: Fix potential probe() deadlock
     - ASoC: cs35l56: Use complete_all() to signal init_completion
     - wifi: iwlwifi: mvm: validate SAR GEO response payload size
     - wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list
     - wifi: iwlwifi: validate payload length in iwl_pnvm_complete_fn
     - wifi: iwlwifi: mvm: fix read in wake packet notification handler
     - usb: atm: ueagle-atm: reject descriptors that confuse probe and
       disconnect
     - drivers/virt: pkvm: Fix end calculation in m

Source diff to previous version
2165872 #510/p sleepable raw tracepoint reject from test_verifier in ubuntu_bpf failed with resolute (7.0.0-33.33) generic amd64
2165189 Resolute update: upstream stable patchset 2026-08-26
2165407 resolute: llvm-21-dev build-depends breaks cross-builds
2165040 Resolute Stable Update v6.18.40, v7.1.5 bugs
2161748 [SRU][HPE] Take Intel platform into account for old microcode checks
2163508 ice: E810 interface fails to initialize (ice_init_hw failed: -5) during NVM read
2162904 amdgpu panel self-refresh on dual-gpu laptops causes complete built-in panel freeze and severe system instability
2162045 linux 7.0: dw9719 VCM never binds, disabling all IPU3 cameras (regression, fixed upstream)
2164967 Fix TAS2783 SoundWire amp resume timeout \u003e5s
2160082 Linux, Ubuntu, 24.04, System hangs for about 10 seconds when unplug external monitor cable on non TBT dock
2156316 [TWL][Desktop] intel_dmc_wait_fw_load() merge to Ubuntu next release
2164716 Reboot machine with ext4 configured to data=journal could dump spurious call trace
2164516 [UBUNTU 22.04] s390/topology: Use zero-based numbering
2163375 Ethernet adapter unusable after suspend/resume on Advantech systems with Intel I226-V
2162803 ice: fix stale -EBUSY on resume of Intel E810
2163062 idxd: crash-kernel NULL-pointer Oops in `destroy_workqueue()` breaks kdump on Intel DSA/IAA systems
2132119 [HP][ZBook Power 16 G11] Laptop freezed after upgrading the BIOS
2163293 Fix noise of audio output on more Dell QCx1255 models after reboot
2160200 Fix no audio input/output device on Dell WCL Slate platform with CirrusLogic audio solution
2164666 Resolute update: upstream stable patchset 2026-08-20
2163121 [Regression] Laptop fails to power off completely when HDMI is connected in kernel 7.0.0-28
CVE-2026-68480 In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injectin
CVE-2026-68105 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix kernel panic during driver load failure Avoid kernel panic if M
CVE-2026-68109 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON() There's no need to crash th
CVE-2026-68114 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON() There's no need to crash th
CVE-2026-68431 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requests The receive path applie
CVE-2026-68138 In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab_list against concurrent get/put qdisc_get_rtab(
CVE-2026-68082 In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers() decode_lockers() in cl
CVE-2026-68159 In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_
CVE-2026-68163 In the Linux kernel, the following vulnerability has been resolved: mm/page_vma_mapped: fix device-private PMD handling Commit 65edfda6f3f2 ("mm/rm
CVE-2026-68166 In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfau
CVE-2026-68170 In the Linux kernel, the following vulnerability has been resolved: mptcp: fix stale skb->sk reference on subflow close The backlog list is updated
CVE-2026-68177 In the Linux kernel, the following vulnerability has been resolved: tracing: Delay module ref count for "enable_event" trigger Triggers are now del
CVE-2026-68191 In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix NULL pointer dereference in rhash table destroy When unbindin
CVE-2026-64586 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device removal brcmf_fw_crashed() and t
CVE-2026-68208 In the Linux kernel, the following vulnerability has been resolved: media: ti: vpe: Fix the error code of devm_kzalloc() in vip_probe_slice() In vi
CVE-2026-68224 In the Linux kernel, the following vulnerability has been resolved: media: mali-c55: Fix possible ERR_PTR in enable_streams The media_pad_remote_pa
CVE-2026-68237 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix indefinite fence wait during GPU reset pre_reset only for
CVE-2026-68240 In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: publish dpagemap early to avoid device mapping leak on error drm_gp
CVE-2026-68242 In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Fix NULL deref on sched_engine alloc failure Avoid using intel_con
CVE-2026-68254 In the Linux kernel, the following vulnerability has been resolved: drm/i915/vrr: require valid min/max vfreq for VRR Ensure the EDID provided min/
CVE-2026-68436 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: use kvzalloc to allocate struct dc struct dc has grown large o
CVE-2026-68447 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size CRIU checkpo
CVE-2026-68264 In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() xe_pt_update_ops_init()
CVE-2026-68265 In the Linux kernel, the following vulnerability has been resolved: drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC When prefetch regio
CVE-2026-68267 In the Linux kernel, the following vulnerability has been resolved: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists Unconditionally whi
CVE-2026-68273 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix context pstate override handling There are several problems in
CVE-2026-68274 In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Fix buffer overflow in steered register list allocation The size ca
CVE-2026-68283 In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free freeing trigger private data Commit 61d445af0a7c ("
CVE-2026-68286 In the Linux kernel, the following vulnerability has been resolved: drop_monitor: perform u64_stats updates under IRQ-disabled section In net_dm_pa
CVE-2026-68287 In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix size calculations for 64-bit attributes net_dm_packet_report_
CVE-2026-68288 In the Linux kernel, the following vulnerability has been resolved: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD net_dm_packet_report_fi
CVE-2026-68289 In the Linux kernel, the following vulnerability has been resolved: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() In tipc_recv
CVE-2026-68291 In the Linux kernel, the following vulnerability has been resolved: idpf: fix max_vport related crash on allocation error during init Set adapter->
CVE-2026-68303 In the Linux kernel, the following vulnerability has been resolved: drm/vc4: hvs/v3d: Fix null dereference in unbind The hvs and v3d drivers use de
CVE-2026-68312 In the Linux kernel, the following vulnerability has been resolved: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths In
CVE-2026-68316 In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Fix element size accounting for cmd stream validation There are
CVE-2026-68322 In the Linux kernel, the following vulnerability has been resolved: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled When booting wit
CVE-2026-68440 In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix heap overflow when reading module EEPROM txgbe_read_eeprom_host
CVE-2026-68323 In the Linux kernel, the following vulnerability has been resolved: tipc: serialize udp bearer replicast list updates tipc_udp_rcast_add() and clea
CVE-2026-68441 In the Linux kernel, the following vulnerability has been resolved: net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains When a TC filter att
CVE-2026-68337 In the Linux kernel, the following vulnerability has been resolved: bpf: Reject redirect helpers without a bpf_net_context The bpf_redirect*() help
CVE-2026-68345 In the Linux kernel, the following vulnerability has been resolved: arm_mpam: guard MBWU state before adding it to garbage __destroy_component_cfg(
CVE-2026-68347 In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix IRQ unsafe locking in gdom allocation Lockdep complains: [ 2
CVE-2026-68375 In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Handle partially initialized auxiliary devices bnxt_aux_devices_init()
CVE-2026-68382 In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Hold device ref until queue teardown completes GuC exec queue destr
CVE-2026-68383 In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Keep scheduler timeline name alive The scheduler keeps a pointer to
CVE-2026-68390 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups hci_conn_param
CVE-2026-68399 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF in sock clone early bailouts Similar to recent commit 9b51a6155d14
CVE-2026-68404 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: use wiphy work for socket owner autodisconnect nl80211_netlink_
CVE-2026-64581 In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() xfrm_user_policy() cle
CVE-2026-68093 In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotpl
CVE-2026-68367 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: synchronize delayed set_alt with teardown The f_tcm set_alt
CVE-2026-68164 In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow overlapping input ranges for damon_set_regions() damon_
CVE-2026-68165 In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: validate ranges in damon_set_regions() DAMON core logic assumes
CVE-2026-68095 In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix race between registration and connection abortion This fixes th
CVE-2026-68096 In the Linux kernel, the following vulnerability has been resolved: audit: fix recursive locking deadlock in audit_dupe_exe() A deadlock occurs in
CVE-2026-68147 In the Linux kernel, the following vulnerability has been resolved: fscrypt: Avoid dynamic allocation in fscrypt_get_devices() When a blk_crypto_ke
CVE-2026-68097 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ACE size against SID sub-authorities set_ntacl_dacl() validates
CVE-2026-68098 In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound DACL dedup walk to copied ACEs set_ntacl_dacl() can stop copying A
CVE-2026-68099 In the Linux kernel, the following vulnerability has been resolved: ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL check_a
CVE-2026-68100 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl set_ntacl_dacl()
CVE-2026-68173 In the Linux kernel, the following vulnerability has been resolved: ublk: wait on ublk_dev_ready() instead of ub->completion ub->completion is only
CVE-2026-68104 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: invoke pm_genpd_remove() before freeing genpd Call pm_genpd_remove(
CVE-2026-68106 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix division by zero with invalid uvd dimensions When width or heig
CVE-2026-68429 In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_pr
CVE-2026-68107 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param length Reuse the parameter length ret
CVE-2026-68108 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image size Fix a security vulnerability
CVE-2026-68110 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() There's no need to crash
CVE-2026-68111 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() There's no need to crash the k
CVE-2026-68112 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() There's no need to crash t
CVE-2026-68430 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx8: drop unecessary BUG_ON() There's no need to crash the kernel f
CVE-2026-68113 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() There's no need to crash the
CVE-2026-68246 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() There's no need to crash the
CVE-2026-68115 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() There's no need to crash the
CVE-2026-68116 In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix source list corruption on a failed replace When replacing the s
CVE-2026-68117 In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() When tipc_sk
CVE-2026-68118 In the Linux kernel, the following vulnerability has been resolved: tcp: challenge ACK for non-exact RST in SYN-RECEIVED The SYN-RECEIVED request-s
CVE-2026-68119 In the Linux kernel, the following vulnerability has been resolved: tcp: initialize standalone TCP-AO response padding tcp_v4_send_ack() and tcp_v6
CVE-2026-68120 In the Linux kernel, the following vulnerability has been resolved: rtase: Workaround for TX hang caused by hardware packet parsing The hardware pe
CVE-2026-68121 In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a po
CVE-2026-68122 In the Linux kernel, the following vulnerability has been resolved: ovpn: fix peer refcount leak in TCP error paths When either the TCP RX or TX er
CVE-2026-68123 In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix GSO userspace truncation underflow OVS_ACTION_ATTR_TRUNC curre
CVE-2026-68124 In the Linux kernel, the following vulnerability has been resolved: mctp: serial: handle zero-length frames to prevent rx buffer overflow The MCTP
CVE-2026-68125 In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: reject frames shorter than the authentication tag llsec_do_de
CVE-2026-68126 In the Linux kernel, the following vulnerability has been resolved: mac802154: hold an interface reference across the scan worker mac802154_scan_wo
CVE-2026-68127 In the Linux kernel, the following vulnerability has been resolved: ila: reload IPv6 header after pskb_may_pull in checksum adjust ila_csum_adjust_
CVE-2026-68128 In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype in ice_parser_profile_init set_bit(rslt->ptype,
CVE-2026-68129 In the Linux kernel, the following vulnerability has been resolved: gve: fix Rx queue stall on alloc failure When the system is under extreme memor
CVE-2026-68130 In the Linux kernel, the following vulnerability has been resolved: ksmbd: defer destroy_previous_session() until after NTLM authentication In ntlm
CVE-2026-68131 In the Linux kernel, the following vulnerability has been resolved: rbd: Reset positive result codes to zero in object map update path In a reply m
CVE-2026-68132 In the Linux kernel, the following vulnerability has been resolved: super: fix emergency thaw deadlock on frozen block devices do_thaw_all_callback
CVE-2026-68133 In the Linux kernel, the following vulnerability has been resolved: ice: fix PTP Call Trace during PTP release If a PF reset occurs when the PTP st
CVE-2026-68134 In the Linux kernel, the following vulnerability has been resolved: ptp: ptp_s390: Add missing facility check Only register the physical clock when
CVE-2026-68135 In the Linux kernel, the following vulnerability has been resolved: net: hip04: fix RX buffer leak on build_skb failure When build_skb() fails in h
CVE-2026-68136 In the Linux kernel, the following vulnerability has been resolved: net: gro: fix double aggregation of flush-marked skbs Commit 0ab03f353d36 ("net
CVE-2026-68137 In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free in x25_kill_by_neigh() x25_kill_by_neigh() walks th
CVE-2026-68139 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Use sender devcom for MPV master-up After PCIe DPC recovery, mlx5 re
CVE-2026-68140 In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix use-after-free of a severed iucv_path af_iucv queues not-yet-rece
CVE-2026-68141 In the Linux kernel, the following vulnerability has been resolved: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() afiucv_hs_callback_syn(
CVE-2026-68142 In the Linux kernel, the following vulnerability has been resolved: geneve: require CAP_NET_ADMIN in the device netns for changelink A tunnel chang
CVE-2026-68143 In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive against buffer reallocation sl_realloc_bufs() repl
CVE-2026-68432 In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns for changelink A tunnel change
CVE-2026-68144 In the Linux kernel, the following vulnerability has been resolved: phonet: pep: fix use-after-free in pep_get_sb() pep_get_sb() doesn't consider t
CVE-2026-68145 In the Linux kernel, the following vulnerability has been resolved: iomap: fix out-of-bounds bitmap_set() with zero-length range ifs_set_range_dirt
CVE-2026-68146 In the Linux kernel, the following vulnerability has been resolved: ftrace: Add global mutex to serialize trace_parser access In ftrace, the trace_
CVE-2026-68148 In the Linux kernel, the following vulnerability has been resolved: fscrypt: Add missing superblock check in find_or_insert_direct_key() The legacy
CVE-2026-68149 In the Linux kernel, the following vulnerability has been resolved: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() The ACL_DONT_CACHE sta
CVE-2026-68150 In the Linux kernel, the following vulnerability has been resolved: fs/super: fix emergency thaw double-unlock of s_umount do_thaw_all() iterates o
CVE-2026-68151 In the Linux kernel, the following vulnerability has been resolved: binfmt_elf_fdpic: only honour the first PT_INTERP The program header scan handl
CVE-2026-68152 In the Linux kernel, the following vulnerability has been resolved: amt: fix use-after-free in AMT delayed works When an AMT device is removed, pen
CVE-2026-68153 In the Linux kernel, the following vulnerability has been resolved: libceph: remove debugfs files before client teardown ceph_destroy_client() tear
CVE-2026-68154 In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode CRUSH bucket type 0 is reserv
CVE-2026-68155 In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MO
CVE-2026-68156 In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_cre
CVE-2026-68157 In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH type name lookup Localized read selection can walk
CVE-2026-68158 In the Linux kernel, the following vulnerability has been resolved: libceph: Fix multiplication overflow in decode_new_up_state_weight() If a messa
CVE-2026-68433 In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front len handle_get_version_reply()
CVE-2026-68160 In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() ceph_h
CVE-2026-68161 In the Linux kernel, the following vulnerability has been resolved: sctp: close UDP tunnel sockets during netns teardown proc_sctp_do_udp_port() st
CVE-2026-68162 In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() up
CVE-2026-64564 In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_a
CVE-2026-68168 In the Linux kernel, the following vulnerability has been resolved: afs: Fix afs_edit_dir_remove() to get, not find, block 0 Fix afs_edit_dir_remov
CVE-2026-68169 In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: userspace: fix use-after-free in get_local_id In mptcp_pm_userspace_
CVE-2026-68172 In the Linux kernel, the following vulnerability has been resolved: arm64: make huge_ptep_get handled unaligned addresses huge_ptep_get() can be ha
CVE-2026-68174 In the Linux kernel, the following vulnerability has been resolved: tracing: Fix union collision of module and refcnt for dynamic events In 'struct
CVE-2026-68175 In the Linux kernel, the following vulnerability has been resolved: tracing: Fix resource leak on mmiotrace trace_pipe close The mmiotrace tracer w
CVE-2026-68176 In the Linux kernel, the following vulnerability has been resolved: tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev If the mmio_pi
CVE-2026-68178 In the Linux kernel, the following vulnerability has been resolved: misc: nsm: pin the module while the device is open misc_open() installs a misc
CVE-2026-68179 In the Linux kernel, the following vulnerability has been resolved: misc: nsm: only unlock nsm_dev on post-lock error paths nsm_dev_ioctl() jumps t
CVE-2026-68180 In the Linux kernel, the following vulnerability has been resolved: intel_th: fix MSC output device reference leak intel_th_output_open() looks up
CVE-2026-68181 In the Linux kernel, the following vulnerability has been resolved: mei: bus: access mei_device under device_lock on cleanup Fix couple of problems
CVE-2026-68434 In the Linux kernel, the following vulnerability has been resolved: serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platfor
CVE-2026-68182 In the Linux kernel, the following vulnerability has been resolved: comedi: comedi_parport: deal with premature interrupt Syzbot reported a general
CVE-2026-68183 In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix memory leaks and list corruption bugs Fix a memory
CVE-2026-64563 In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check()
CVE-2026-68184 In the Linux kernel, the following vulnerability has been resolved: cdrom: fix stack out-of-bounds read in CDROMVOLCTRL mmc_ioctl_cdrom_volume() fi
CVE-2026-68186 In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: set have_execfd only once the interpreter is opened load_misc_bina
CVE-2026-68187 In the Linux kernel, the following vulnerability has been resolved: exec: fix unsigned loop counter wrap in transfer_args_to_stack() The stop value
CVE-2026-68188 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() test
CVE-2026-68189 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Protect UUID list traversal The hci_sync conversion moved
CVE-2026-68190 In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() rtw_get_wps_ie() iterates
CVE-2026-68192 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: make release_scratchbuffers idempotent brcmf_pcie_release_scrat
CVE-2026-68193 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is
CVE-2026-68194 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is
CVE-2026-68195 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses PKT_TYPE_TXRX_NOTIFY is
CVE-2026-68196 In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: validate assoc response length before subtracting header wilc_p
CVE-2026-68197 In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper mwifi
CVE-2026-68198 In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix use-after-free in aggr_reset_state() The aggr_reset_state() f
CVE-2026-68199 In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB access from firmware ADDBA window size aggr_recv_addba_re
CVE-2026-68200 In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: don't re-enter an instance callback that is still running The user
CVE-2026-68201 In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: drain a slave's callback before its master detaches it snd_timer_c
CVE-2026-68202 In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: close a re-opened queue timer in the destructor queue_delete() close
CVE-2026-68203 In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix cleanup bugs in vivid_init() When platform_device_register()
CVE-2026-68204 In the Linux kernel, the following vulnerability has been resolved: media: vivid: check for vb2_is_busy() when toggling caps The vivid_update_forma
CVE-2026-68205 In the Linux kernel, the following vulnerability has been resolved: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_s
CVE-2026-68206 In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC active reference counts HEVC slice parameters
CVE-2026-68207 In the Linux kernel, the following vulnerability has been resolved: media: ti: vpe: unwind v4l2 device registration on probe error If the vpe_top r
CVE-2026-68209 In the Linux kernel, the following vulnerability has been resolved: media: sun4i-csi: Return queued buffers on start_streaming() failure The vb2 fr
CVE-2026-68210 In the Linux kernel, the following vulnerability has been resolved: media: stm32: dcmi: unregister notifier on probe failure dcmi_graph_init() regi
CVE-2026-68211 In the Linux kernel, the following vulnerability has been resolved: media: stm32-dcmipp: Return queued buffers on start_streaming() failure The vb2
CVE-2026-68212 In the Linux kernel, the following vulnerability has been resolved: media: saa7134: Fix a possible memory leak in saa7134_video_init1 In saa7134_vi
CVE-2026-68213 In the Linux kernel, the following vulnerability has been resolved: media: rtl2832_sdr: Return queued buffers on start_streaming() failure The vb2
CVE-2026-68214 In the Linux kernel, the following vulnerability has been resolved: media: rtl2832: fix use-after-free in rtl2832_remove() cancel_delayed_work_sync
CVE-2026-68215 In the Linux kernel, the following vulnerability has been resolved: media: radio-si476x: Unregister v4l2_device on probe failure si476x_radio_probe
CVE-2026-68216 In the Linux kernel, the following vulnerability has been resolved: media: pwc: Return queued buffers on start_streaming() failure The vb2 framewor
CVE-2026-68217 In the Linux kernel, the following vulnerability has been resolved: media: pwc: Drain fill_buf on start_streaming() failure pwc_isoc_init() submits
CVE-2026-68218 In the Linux kernel, the following vulnerability has been resolved: media: pci: dm1105: Free allocated workqueue Destroy allocated workqueue in rem
CVE-2026-68219 In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: Fix potential out-of-bounds issues The maximum downscalin
CVE-2026-68220 In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe Bo
CVE-2026-68221 In the Linux kernel, the following vulnerability has been resolved: media: nuvoton: npcm-video: fix memory leaks in probe and remove npcm_video_pro
CVE-2026-68222 In the Linux kernel, the following vulnerability has been resolved: media: msi2500: Return queued buffers on start_streaming() failure The vb2 fram
CVE-2026-68223 In the Linux kernel, the following vulnerability has been resolved: media: meson: vdec: Fix memory leak in error path of vdec_open The vdec_open()
CVE-2026-68225 In the Linux kernel, the following vulnerability has been resolved: media: i2c: alvium: fix critical pointer access in alvium_ctrl_init The current
CVE-2026-68226 In the Linux kernel, the following vulnerability has been resolved: media: cx23885: add ioremap return check and cleanup Add a check for the return
CVE-2026-68227 In the Linux kernel, the following vulnerability has been resolved: media: cx231xx: fix devres lifetime USB drivers bind to USB interfaces and any
CVE-2026-68228 In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Move src_buf Removal to finish_encode During encoder
CVE-2026-68229 In the Linux kernel, the following vulnerability has been resolved: media: cedrus: skip invalid H.264 reference list entries Cedrus consumes H.264
CVE-2026-68230 In the Linux kernel, the following vulnerability has been resolved: media: amlogic-c3: Add validations for ae and awb config Avoid invalid memory a
CVE-2026-68231 In the Linux kernel, the following vulnerability has been resolved: media: airspy: Return queued buffers on start_streaming() failure The vb2 frame
CVE-2026-68232 In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict If kvmalloc_array()
CVE-2026-68445 In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Prevent shader BO mappings from becoming writable vc4_gem_object_mmap(
CVE-2026-68446 In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate vmw_surface_metadata::array_size This field comes from use
CVE-2026-68233 In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Shut down BO cache timer before teardown The BO cache timer callback s
CVE-2026-68234 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved amdgpu_bo_create_r
CVE-2026-68235 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: dce100: skip non-DP stream encoders for DP MST On DCE8-class A
CVE-2026-68236 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: set new_stream to NULL after release In dm_update_crtc_state()
CVE-2026-68238 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Release VFCT ACPI table reference amdgpu_acpi_vfct_bios() fetches t
CVE-2026-68239 In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Account for NULL and handle pages in ttm_pool_backup Pages in ttm_pool
CVE-2026-68241 In the Linux kernel, the following vulnerability has been resolved: drm/i915/mst: limit DP MST ESI service loop The loop in intel_dp_check_mst_stat
CVE-2026-68243 In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU Setting context engine
CVE-2026-68244 In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Do not leak siblings[] on proto context error After a successful
CVE-2026-68245 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() The vm pointe
CVE-2026-68247 In the Linux kernel, the following vulnerability has been resolved: drm/i915/bios: range check LFP Data Block panel_type2 While the panel_type from
CVE-2026-68248 In the Linux kernel, the following vulnerability has been resolved: drm/i915: Return NULL on error in active_instance Avoid returning &node->base w
CVE-2026-68249 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() There's no need to crash th
CVE-2026-68250 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() There's no need to crash th
CVE-2026-68251 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() There's no need to crash th
CVE-2026-68252 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() There's no need to crash th
CVE-2026-68253 In the Linux kernel, the following vulnerability has been resolved: drm/i915/hdcp: check streams[] bounds before overflow The data->streams[] overf
CVE-2026-68255 In the Linux kernel, the following vulnerability has been resolved: drm/virtio: bound EDID block reads to the response buffer virtio_get_edid_block
CVE-2026-68256 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev
CVE-2026-68257 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation total_cwsr_size
CVE-2026-68258 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds on CRIU restore queue type and mqd size We weren't che
CVE-2026-68259 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds in allocate_event_notification_slot The valid event id
CVE-2026-68260 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM The drm g
CVE-2026-68261 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: fix error checking of pvr_vm_context_lookup() Since pvr_vm_con
CVE-2026-68262 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix user array stride in pvr_set_uobj_array() pvr_set_uobj_arr
CVE-2026-68263 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix double call to drm_sched_entity_fini() Call sequence of do
CVE-2026-68266 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Hold a dma-buf reference for imported BOs An imported dma-buf BO is cre
CVE-2026-68268 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Return error on non-migratable faults requiring devmem Non-migratable f
CVE-2026-68269 In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Add missing nospec on parallel submit slot Add missing Spectre mi
CVE-2026-68270 In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: Avoid possible truncation with calculating visible size Calculating
CVE-2026-68271 In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix reversed error cleanup order in ucopy functions nouveau_uvmm_v
CVE-2026-68272 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 Add a minimum-length
CVE-2026-68275 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO The AMDGPU_GEM
CVE-2026-68276 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx: fix cleaner shader IB buffer overflow The cleaner shader sysfs
CVE-2026-68277 In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers Three side
CVE-2026-68437 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fit paired fragment job in the correct CCCB For geometry jobs
CVE-2026-68278 In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix buffer overflows in sideband chunk accumulation drm_dp_sideband
CVE-2026-68279 In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers drm_dp_side
CVE-2026-68280 In the Linux kernel, the following vulnerability has been resolved: drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() The deprecated
CVE-2026-68281 In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Count paired job fence as dependency in prepare_job() The DRM
CVE-2026-68282 In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: analogix_dp: Add missing error check for platform_get_resource()
CVE-2026-68284 In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() tcp_bpf_sendmsg() ke
CVE-2026-68290 In the Linux kernel, the following vulnerability has been resolved: rds: tcp: unregister sysctl before tearing down listen socket rds_tcp_exit_net(
CVE-2026-68292 In the Linux kernel, the following vulnerability has been resolved: ice: prevent tstamp ring allocation for non-PF VSI types The pf->txtime_txqs bi
CVE-2026-68293 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads The MCIA register
CVE-2026-68294 In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial network namespace QRTR keeps
CVE-2026-68296 In the Linux kernel, the following vulnerability has been resolved: net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM Before commit 00d06
CVE-2026-64575 In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc bpf_iter_tcp_batch() release
CVE-2026-68297 In the Linux kernel, the following vulnerability has been resolved: tipc: fix u16 MTU truncation in media and bearer MTU validation Both TIPC_NL_ME
CVE-2026-68298 In the Linux kernel, the following vulnerability has been resolved: drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create() Commit 9e97
CVE-2026-68299 In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr
CVE-2026-68300 In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_ver
CVE-2026-68301 In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix memory leak on slave unregistration by removing synced VLANs When
CVE-2026-68302 In the Linux kernel, the following vulnerability has been resolved: amt: re-read skb header pointers after every pull Several AMT receive and trans
CVE-2026-68448 In the Linux kernel, the following vulnerability has been resolved: ovl: check access to copy_file_range source with src mounter creds Commit 5dae2
CVE-2026-68304 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix 802.1X-SHA256 call trace warning Based on wpa_auth as 1x_25
CVE-2026-68306 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
CVE-2026-68307 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix crash in reset link replay During reset recovery, mt792
CVE-2026-68308 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() mt76
CVE-2026-68439 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
CVE-2026-68309 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_h
CVE-2026-68310 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: guard HE capability lookups mt7915_mcu_bss_he_tlv() and mt7
CVE-2026-68311 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: guard link STA in decap offload mt7925_sta_set_decap_offloa
CVE-2026-68313 In the Linux kernel, the following vulnerability has been resolved: tipc: fix infinite loop in __tipc_nl_compat_dumpit cmd->dumpit callback can ret
CVE-2026-64576 In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate() nh_res_bucket_migrate() p
CVE-2026-64577 In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() gtp1u_send_echo_res
CVE-2026-68314 In the Linux kernel, the following vulnerability has been resolved: net: mctp i3c: clean up notifier and buses if driver register fails mctp_i3c_mo
CVE-2026-68315 In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a
CVE-2026-68317 In the Linux kernel, the following vulnerability has been resolved: pds_core: fix auxiliary device add/del races Two paths add or delete the same s
CVE-2026-68318 In the Linux kernel, the following vulnerability has been resolved: pds_core: fix use-after-free on workqueue during remove In pdsc_remove(), the w
CVE-2026-68319 In the Linux kernel, the following vulnerability has been resolved: pds_core: fix deadlock between reset thread and remove pci_reset_function() acq
CVE-2026-68320 In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid sctp_auth_
CVE-2026-68321 In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix FDIR filter leak on remove Perfect FDIR filters can be added wh
CVE-2026-68324 In the Linux kernel, the following vulnerability has been resolved: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() dmar_latency_di
CVE-2026-68325 In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Bound the early ACPI HID map The ivrs_acpihid command-line parser ap
CVE-2026-68326 In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: bound uAP association event IEs to the event buffer mwifiex_proc
CVE-2026-68327 In the Linux kernel, the following vulnerability has been resolved: wan: wanxl: Only reset hardware after BAR mapping wanxl_pci_init_one() stores t
CVE-2026-68328 In the Linux kernel, the following vulnerability has been resolved: nfp: Check resource mutex allocation nfp_cpp_resource_find() allocates a CPP mu
CVE-2026-64574 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update error path When ieee80211_vif
CVE-2026-68329 In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Wait for completion instead of returning early in iommu_completion_wa
CVE-2026-68330 In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix DMA direction for NPU mailbox buffer airoha_npu_send_msg() alw
CVE-2026-68331 In the Linux kernel, the following vulnerability has been resolved: dpaa2-eth: put MAC endpoint device on disconnect fsl_mc_get_endpoint() returns
CVE-2026-68332 In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix potential use-after-free in airoha_ppe_deinit() airoha_ppe_dei
CVE-2026-68333 In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: put MAC endpoint device on disconnect fsl_mc_get_endpoint() retur
CVE-2026-68334 In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix io_thread race in rxrpc_wake_up_io_thread() rxrpc_wake_up_io_thread(
CVE-2026-68335 In the Linux kernel, the following vulnerability has been resolved: rds: drop incoming messages that cross network namespace boundaries rds_find_bo
CVE-2026-68336 In the Linux kernel, the following vulnerability has been resolved: bonding: fix devconf_all NULL dereference when IPv6 is disabled When booting wi
CVE-2026-68338 In the Linux kernel, the following vulnerability has been resolved: net/packet: avoid fanout hook re-registration after unregister packet_set_ring(
CVE-2026-68339 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: validate Realtek vendor event length btusb_recv_event_realtek
CVE-2026-68340 In the Linux kernel, the following vulnerability has been resolved: hwmon: occ: validate poll response sensor blocks The OCC poll response parser w
CVE-2026-68341 In the Linux kernel, the following vulnerability has been resolved: ovpn: fix use after free in unlock_ovpn() unlock_ovpn() iterates over the relea
CVE-2026-68342 In the Linux kernel, the following vulnerability has been resolved: ovpn: avoid putting unrelated P2P peer on socket release ovpn_peer_release_p2p(
CVE-2026-68343 In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed parse_dfs_referrals() validates
CVE-2026-68346 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: validate and free ACPI mute object cs35l41_get_acpi_mute_st
CVE-2026-68348 In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2781: bound firmware description string parsing The TAS2781 firmware p
CVE-2026-68450 In the Linux kernel, the following vulnerability has been resolved: btrfs: free mapping node on duplicate reloc root insert __add_reloc_root() allo
CVE-2026-68442 In the Linux kernel, the following vulnerability has been resolved: btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps When btrfs_drop
CVE-2026-68349 In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: fix buffer overflow in rx_stream failover path The failover con
CVE-2026-68350 In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: fix OOB read from off-by-two in TX status handler The bounds ch
CVE-2026-68351 In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read When th
CVE-2026-68352 In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event The firmwa
CVE-2026-68353 In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler The fir
CVE-2026-68354 In the Linux kernel, the following vulnerability has been resolved: firewire: net: Fix fragmented datagram reassembly fwnet_frag_new() keeps a sort
CVE-2026-68355 In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() W
CVE-2026-68356 In the Linux kernel, the following vulnerability has been resolved: watchdog: airoha: Prevent division by zero when clock frequency is zero clk_get
CVE-2026-68357 In the Linux kernel, the following vulnerability has been resolved: watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() When a watchdog
CVE-2026-68358 In the Linux kernel, the following vulnerability has been resolved: hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop Calling hid_hw_
CVE-2026-68359 In the Linux kernel, the following vulnerability has been resolved: hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop Calling hid_hw_s
CVE-2026-68443 In the Linux kernel, the following vulnerability has been resolved: hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop Calling
CVE-2026-68360 In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop Calling hid_hw_
CVE-2026-68361 In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop hid_hw_stop() do
CVE-2026-68362 In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin In A
CVE-2026-68363 In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
CVE-2026-68365 In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_edgeport: cap received transmit credits The interrupt-status pa
CVE-2026-68366 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer uvc_send_re
CVE-2026-64583 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown The
CVE-2026-68368 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() When unpacking
CVE-2026-68369 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: printer: fix infinite loop in printer_read() printer_read() uses t
CVE-2026-64584 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before freeing the midi object The
CVE-2026-68370 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback dummy_hcd embeds
CVE-2026-68371 In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Do not put borrowed of_node in probe omap2430_probe() stor
CVE-2026-68373 In the Linux kernel, the following vulnerability has been resolved: wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() at76_guess_freq
CVE-2026-68374 In the Linux kernel, the following vulnerability has been resolved: usb: core: sysfs: add lock to bos_descriptors_read() Add a lock to the function
CVE-2026-64569 In the Linux kernel, the following vulnerability has been resolved: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n On CONFIG_IN
CVE-2026-68376 In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_hmacs array size in struct sctp_cookie The auth_hmacs array in s
CVE-2026-68377 In the Linux kernel, the following vulnerability has been resolved: net/sched: act_tunnel_key: Defer dst_release to RCU callback Fix a race-conditi
CVE-2026-68378 In the Linux kernel, the following vulnerability has been resolved: dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() When a dpll_p
CVE-2026-68379 In the Linux kernel, the following vulnerability has been resolved: tcp: fix TIME_WAIT socket reference leak on PSP policy failure Release the TIME
CVE-2026-68380 In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix use-after-free of mm_struct in job scheduler amdxdna_cmd_sub
CVE-2026-64578 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before reading StructureSize2 When ksmbd
CVE-2026-68381 In the Linux kernel, the following vulnerability has been resolved: ksmbd: pin conn during async oplock break notification smb2_oplock_break_noti()
CVE-2026-68384 In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves xe_bo_move() a
CVE-2026-68385 In the Linux kernel, the following vulnerability has been resolved: s390/checksum: Fix csum_partial() without vector facility Currently csum_partia
CVE-2026-68386 In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Reject unhashed UDP sockets on sockmap update UDP sockets get SOC
CVE-2026-68387 In the Linux kernel, the following vulnerability has been resolved: can: raw: add locking for raw flags bitfield With commit 890e5198a6e5 ("can: ra
CVE-2026-68388 In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_falloc
CVE-2026-68389 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: Clear memdump state on invalid dump size qca_controller_mem
CVE-2026-68391 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Dereferencing
CVE-2026-68392 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync Dereferencing RCU
CVE-2026-68393 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: extend conn_hash lookup critical sections Using RCU-protec
CVE-2026-68394 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update MGMT_OP_LOAD_CONN_PAR
CVE-2026-64573 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NVM tag length underflow in TLV parser In the TLV_TYPE_NVM
CVE-2026-68449 In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning The h
CVE-2026-68395 In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
CVE-2026-68396 In the Linux kernel, the following vulnerability has been resolved: scsi: core: wake eh reliably when using scsi_schedule_eh Drivers which use the
CVE-2026-68397 In the Linux kernel, the following vulnerability has been resolved: net/iucv: take a reference on the socket found in afiucv_hs_rcv() afiucv_hs_rcv
CVE-2026-64572 In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: free fib_alias with kfree_rcu() on insert error path fib_table_inser
CVE-2026-68398 In the Linux kernel, the following vulnerability has been resolved: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF pppol2tp_
CVE-2026-68400 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation Use
CVE-2026-68401 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() Sashiko
CVE-2026-68402 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking non-inheritance cfg80211_is
CVE-2026-68403 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: initialize SDIO data work before cleanup brcmf_sdio_probe() sto
CVE-2026-68405 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock ieee80211_do_stop() r
CVE-2026-68406 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate PMSR FTM preamble range PMSR FTM request parsing accep
CVE-2026-68407 In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: free RNR data on MBSSID mismatch nl80211_parse_beacon() rejects
CVE-2026-68408 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock When a netli
CVE-2026-64571 In the Linux kernel, the following vulnerability has been resolved: wifi: p54: validate RX frame length in p54_rx_eeprom_readback() p54_rx_eeprom_r
CVE-2026-68409 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: defer link RX stats percpu free to RCU sta_remove_link() frees
CVE-2026-68410 In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix memory leak in helper_firmware_cb() helper_firmware_cb() ne
CVE-2026-64570 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on alloc failure ieee80211_set_f
CVE-2026-64568 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure ieee802
CVE-2026-68411 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: clamp virtio RX length before skb_put hwsim_virtio_rx_wor
CVE-2026-68412 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() If the te
CVE-2026-68413 In the Linux kernel, the following vulnerability has been resolved: wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() The memory a
CVE-2026-68414 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel sched scan results work on unregister cfg80211_sched_sca
CVE-2026-64579 In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert xfrm_h
CVE-2026-64580 In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() On
CVE-2026-64566 In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() When iptfs_sk
CVE-2026-68415 In the Linux kernel, the following vulnerability has been resolved: xfrm: clear mode callbacks after failed mode setup xfrm_state_gc_task can run l
CVE-2026-68416 In the Linux kernel, the following vulnerability has been resolved: mtd: fix double free and WARN_ON in add_mtd_device() error paths When device_re
CVE-2026-68417 In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: publish QP after initialization siw_create_qp() currently calls siw_q
CVE-2026-68418 In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Prevent user-triggered null deref on QP create Previously, the user
CVE-2026-68419 In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Prevent rereg_mr for non-mem regions When a QP/CQ/SRQ is created, a
CVE-2026-68420 In the Linux kernel, the following vulnerability has been resolved: xfrm: reject optional IPTFS templates in outbound policies syzbot reported a st
CVE-2026-68421 In the Linux kernel, the following vulnerability has been resolved: sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx() put_prev
CVE-2026-68444 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() ffa_partiti
CVE-2026-68422 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() If
CVE-2026-64567 In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries than pages When loading a v1 f
CVE-2026-68425 In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reassembly Kernel-handled RMPP rec
CVE-2026-68426 In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals a GSO segment skb_gso_segme
CVE-2026-64565 In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() The `ims_pc
CVE-2026-68427 In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings __host1x_bo_
CVE-2026-68428 In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Fix use-after-free on vendor module reload mmu_destroy_caches() d
CVE-2026-64562 In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow
CVE-2026-64561 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Ch
CVE-2023-20585 Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of
CVE-2026-68364 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix ISM dc_lock deadlock during suspend [Why] System hang obse
CVE-2026-72064 In the Linux kernel, the following vulnerability has been resolved: net: mana: Sync page pool RX frags for CPU MANA allocates RX buffers from page
CVE-2026-72065 In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by the NIC Validate the packet l
CVE-2026-72098 In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation There's a buffer overflow in
CVE-2026-72248 In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: support IPIP tunnel with direct xmit The combination of I
CVE-2026-72249 In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: use dst in this direction when pushing IPIP header When p
CVE-2026-72287 In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks M
CVE-2026-72329 In the Linux kernel, the following vulnerability has been resolved: net/liquidio: drop cached VF pci_dev LUT The PF SR-IOV enable path caches VF pc
CVE-2026-72355 In the Linux kernel, the following vulnerability has been resolved: netfs: Fix barriering when walking subrequest list Fix the barriering used when
CVE-2026-72412 In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix handling of _PAGE_UNUSED pte bit The _PAGE_UNUSED softbit should n
CVE-2026-72417 In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() Add sanit
CVE-2026-72442 In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: fix and simplify IP6IP6 tunnel handling Fix nf_flow_ip6_t
CVE-2026-72463 In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix dev use-after-free in xfrm async resumption xfrm async resumption hol
CVE-2026-72477 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: call _ntfs_bad_inode() when failing to rename It is safe to call _ntf
CVE-2026-72493 In the Linux kernel, the following vulnerability has been resolved: net: serialize netif_running() check in enqueue_to_backlog() Syzbot reported a
CVE-2026-72494 In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Replace waitqueue and flag with completion The driver previously us
CVE-2026-72496 In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Proper rollback if the ioremap fails bnxt_qplib_alloc_dpi returns
CVE-2026-74269 In the Linux kernel, the following vulnerability has been resolved: bnxt: fix head underflow on XDP head-grow The xdp.py test test_xdp_native_adjst
CVE-2026-74350 In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate fast symlink target during inode read ocfs2_validate_inode_bloc
CVE-2026-72495 In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages Applications can req
CVE-2026-72501 In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Initialize dpi variable to zero dpi is initialized only for BNXT_
CVE-2026-72278 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Re-translate VNCR before injecting abort KVM faults in the VNCR
CVE-2026-68083 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_create The SMB2 open lookup i
CVE-2026-68457 In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for FSCTL mutations SET_SPARSE, SET_ZERO_DATA and
CVE-2026-68476 In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after head reallocation __ip_vs_get_out_rt() calls skb_e
CVE-2026-68477 In the Linux kernel, the following vulnerability has been resolved: ipvs: fix more places with wrong ipv6 transport offsets Sashiko reports for mor
CVE-2026-72014 In the Linux kernel, the following vulnerability has been resolved: drbd: reject data replies with an out-of-range payload size recv_dless_read() r
CVE-2026-72020 In the Linux kernel, the following vulnerability has been resolved: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new Commit 9a05475cebdd ("ipvs
CVE-2026-72033 In the Linux kernel, the following vulnerability has been resolved: orangefs: keep the readdir entry size 64-bit in fill_from_part() fill_from_part
CVE-2026-72041 In the Linux kernel, the following vulnerability has been resolved: espintcp: use sk_msg_free_partial to fix partial send sk_msg_free_partial() ens
CVE-2026-72046 In the Linux kernel, the following vulnerability has been resolved: gve: fix header buffer corruption with header-split and HW-GRO The DQO RX datap
CVE-2026-72069 In the Linux kernel, the following vulnerability has been resolved: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() rt_spin_unlock
CVE-2026-72083 In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE core_scs
CVE-2026-72084 In the Linux kernel, the following vulnerability has been resolved: scsi: target: Bound PR-OUT TransportID parsing to the received buffer core_scsi
CVE-2026-72085 In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free unsubmitted command instead of double-putting it scsi
CVE-2026-72129 In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data with a nonzero offset nvmet_rdma_use_inline_sg()
CVE-2026-72130 In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject short AUTH_RECEIVE buffers nvmet_execute_auth_receive() trus
CVE-2026-64551 In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cause length before reading staleness When an ERROR
CVE-2026-72137 In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_keepalive: avoid double free on send error nat_keepalive_send() frees
CVE-2026-72139 In the Linux kernel, the following vulnerability has been resolved: tcp: defer md5sig_info kfree past RCU grace period in tcp_connect The md5+ao re
CVE-2026-72191 In the Linux kernel, the following vulnerability has been resolved: ntfs3: validate split-point offset in indx_insert_into_buffer indx_insert_into_
CVE-2026-72192 In the Linux kernel, the following vulnerability has been resolved: ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head indx_inser
CVE-2026-72194 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow indx_fi
CVE-2026-72217 In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing xdr_buf_to_bvec() w
CVE-2026-72220 In the Linux kernel, the following vulnerability has been resolved: sunrpc: harden rq_procinfo lifecycle to prevent double-free The svc_release_rqs
CVE-2026-72221 In the Linux kernel, the following vulnerability has been resolved: sunrpc: wait for in-flight TLS handshake callback when cancel loses race When w
CVE-2026-72222 In the Linux kernel, the following vulnerability has been resolved: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback svc_tcp_han
CVE-2026-72226 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: prevent TVLV OOB check overflow A TT unicast TVLV contains the
CVE-2026-72234 In the Linux kernel, the following vulnerability has been resolved: batman-adv: access unicast_ttvn skb->data only after skb realloc The pskb_may_p
CVE-2026-72251 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: reload possible stale data pointer quoting sashiko: ---
CVE-2026-72277 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory When constructing
CVE-2026-72279 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR KVM currently maps t
CVE-2026-72288 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disablin
CVE-2026-72289 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Check the interrupt is still ours before migrating it vgic_pr
CVE-2026-72296 In the Linux kernel, the following vulnerability has been resolved: net: ife: require ETH_HLEN to be pullable in ife_decode() ife decode may return
CVE-2026-72299 In the Linux kernel, the following vulnerability has been resolved: tipc: restrict socket queue dumps in enqueue tracepoints tipc_sk_enqueue() runs
CVE-2026-72317 In the Linux kernel, the following vulnerability has been resolved: SUNRPC: pin upper rpc_clnt across the TLS connect_worker The TLS connect path h
CVE-2026-72318 In the Linux kernel, the following vulnerability has been resolved: cifs: validate DFS referral string offsets parse_dfs_referrals() validates that
CVE-2026-72319 In the Linux kernel, the following vulnerability has been resolved: ipvs: ensure inner headers in ICMP errors are in headroom Sashiko points out th
CVE-2026-72320 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_lookup: fix catchall element handling with inverted lookups nft_
CVE-2026-72322 In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix potential UAF in MLD delayed work A race condition exists betw
CVE-2026-72323 In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() A race condition exists
CVE-2026-64541 In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket smc_cdc_rx_handl
CVE-2026-72339 In the Linux kernel, the following vulnerability has been resolved: qede: fix off-by-one in BD ring consumption on build_skb failure qede_rx_build_
CVE-2026-72348 In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop The ah,
CVE-2026-72351 In the Linux kernel, the following vulnerability has been resolved: gue: validate REMCSUM private option length GUE private flags can indicate that
CVE-2026-72366 In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_create_write_req() to handle async cache object creation netfs
CVE-2026-72381 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of fp->owner.name in durable handle owner check Two c
CVE-2026-72393 In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: don't cache shinfo across skb realloc fbnic_tx_lso() calls skb_cow_
CVE-2026-72398 In the Linux kernel, the following vulnerability has been resolved: sctp: add INIT verification after cookie unpacking In SCTP handshake, the INIT
CVE-2026-72399 In the Linux kernel, the following vulnerability has been resolved: net: enetc: check the number of BDs needed for xdp_frame The size of xdp_redire
CVE-2026-64530 In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify()
CVE-2026-72422 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE co
CVE-2026-72429 In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix type confusion of dst_entry IOAM uses a dummy dst_entry(null_ds
CVE-2026-72436 In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types Sa
CVE-2026-72451 In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix xfrm state cache insertion race The xfrm input state cache insertion
CVE-2026-72466 In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix bcall rep leak and unbounded peek rpcrdma_is_bcall() decodes a re
CVE-2026-72472 In the Linux kernel, the following vulnerability has been resolved: nfs: use nfsi->rwsem to protect traversal of the file lock list Lingfeng identi
CVE-2026-72473 In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Decouple req recycling from RPC completion rl_kref formerly served tw
CVE-2026-72491 In the Linux kernel, the following vulnerability has been resolved: net/9p: fix race condition on rdma->state in trans_rdma.c The rdma->state field
CVE-2026-74255 In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in tipc_l2_send_msg() Syzbot reported a slab-use-after-free in ip
CVE-2026-74267 In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before r
CVE-2026-74268 In the Linux kernel, the following vulnerability has been resolved: tcp: clear sock_ops cb flags before force-closing a child socket A child socket
CVE-2026-74287 In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded address parameter length sctp_verify_asconf() and sctp_
CVE-2026-74310 In the Linux kernel, the following vulnerability has been resolved: vhost/net: complete zerocopy ubufs only once vhost-net initializes one ubuf_inf
CVE-2026-74345 In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix endpoint/socket association handling Disassociating a socket from
CVE-2026-74361 In the Linux kernel, the following vulnerability has been resolved: nvme: fix FDP fdpcidx bounds check The fdpcidx bounds check sets n = NUMFDPC +
CVE-2026-74376 In the Linux kernel, the following vulnerability has been resolved: md/raid10: reset read_slot when reusing r10bio for discard put_all_bios() alway
CVE-2026-74384 In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix flex array size in struct nvme_ns_head struct nvme_ns_head
CVE-2026-74394 In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: fix integer overflow in immediate data length check imm_buf->len is
CVE-2026-74398 In the Linux kernel, the following vulnerability has been resolved: ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD addrcon
CVE-2026-74401 In the Linux kernel, the following vulnerability has been resolved: dlm: fix add msg handle in send_queue ordered In a benchmark scenario triggerin
CVE-2026-74406 In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). udp_tunnel_
CVE-2026-74427 In the Linux kernel, the following vulnerability has been resolved: afs: Fix netns teardown to cancel the preallocation charger Fix the teardown of
CVE-2026-74428 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix double unlock in rxrpc_recvmsg() Fix a double unlock in rxrpc_recvms
CVE-2026-74433 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix UAF in rxgk_issue_challenge() Fix rxgk_issue_challenge() to free the
CVE-2026-74434 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Don't move a peeked OOB message onto the pending queue rxrpc_recvmsg_oob
CVE-2026-74436 In the Linux kernel, the following vulnerability has been resolved: rxrpc: serialize kernel accept preallocation with socket teardown rxrpc_kernel_
CVE-2026-64535 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnera
CVE-2026-74439 In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry d
CVE-2026-64534 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nv

Version: 7.0.0-33.33 2026-08-29 12:08:38 UTC

 linux (7.0.0-33.33) resolute; urgency=medium
 .
   * resolute/linux: 7.0.0-33.33 -proposed tracker (LP: #2165488)
 .
   * resolute: llvm-21-dev build-depends breaks cross-builds (LP: #2165407)
     - [Packaging] Fix cross-builds
 .
   * Resolute Stable Update v6.18.40, v7.1.5 bugs (LP: #2165040)
     - accel/amdxdna: Allow forcing IOVA-based DMA via module parameter
     - SAUCE: bpf: Add missing NULL argument to zap_page_range_single
     - accel/amdxdna: Return ERR_PTR on dma_alloc_noncoherent failure
     - accel/amdxdna: Fix memory leak in amdxdna_iommu_alloc()
 .
   * [SRU][HPE] Take Intel platform into account for old microcode checks
     (LP: #2161748)
     - x86/microcode: Refactor platform ID enumeration into a helper
     - x86/cpu: Add platform ID to CPU info structure
     - x86/cpu: Add platform ID to CPU matching structure
     - x86/microcode: Add platform mask to Intel microcode "old" list
     - x86/microcode: Do not access MSR_IA32_PLATFORM_ID when running as a
       guest
 .
   * ice: E810 interface fails to initialize (ice_init_hw failed: -5) during
     NVM read (LP: #2163508)
     - ice: acquire NVM lock around each flash read
 .
   * WWAN modem unresponsive after freeze on Dell systems with DW5826e
     (LP: #2163214)
     - platform/x86: dell-dw5826e: Add reset driver for DW5826e
     - platform/x86: dell-dw5826e: fix ACPI _DSM function index and bitmask
       usage
     - [Config] Add CONFIG_DELL_DW5826E_RESET=m
 .
   * amdgpu panel self-refresh on dual-gpu laptops causes complete built-in
     panel freeze and severe system instability (LP: #2162904)
     - SAUCE: drm/amdgpu: Do not enter PSR if multiple displays are active
 .
   * linux 7.0: dw9719 VCM never binds, disabling all IPU3 cameras (regression,
     fixed upstream) (LP: #2162045)
     - media: dw9719: Add back the I��C device id table
 .
   * Fix TAS2783 SoundWire amp resume timeout >5s (LP: #2164967)
     - soundwire: Add a helper function to wait for device initialisation
     - ASoC: tas2783: Use new SoundWire enumeration helper
     - soundwire: Move wait for initialisation helper to header
     - ASoC: codecs: tas2783-sdw: Propagate regcache_sync() errors
     - ASoC: tas2783-sdw: drop stale regcache on uninitialized re-attach
 .
   * Linux, Ubuntu, 24.04, System hangs for about 10 seconds when unplug
     external monitor cable on non TBT dock (LP: #2160082)
     - SAUCE: drm/i915/tc: Revert forced DP-alt connected workaround
 .
   * Speakers not detected on HP systems with TI TAS2783 SoundWire amps
     (LP: #2164504)
     - ASoC: sdw_utils: Add missed component_name strings for TI amps
 .
   * [TWL][Desktop] intel_dmc_wait_fw_load() merge to Ubuntu next release
     (LP: #2156316)
     - SAUCE: drm/i915/dmc: fix assert_dmc_loaded WARN during async firmware
       load
 .
   * Reboot machine with ext4 configured to data=journal could dump spurious
     call trace (LP: #2164716)
     - ext4: clear stale xarray tags on folios skipped during writeback
 .
   * [UBUNTU 22.04] s390/topology: Use zero-based numbering (LP: #2164516)
     - s390/topology: Use zero-based numbering for containing entities
 .
   * Ethernet adapter unusable after suspend/resume on Advantech systems with
     Intel I226-V (LP: #2163375)
     - igc: fix netdev not re-attached after resume if interface is down
 .
   * ice: fix stale -EBUSY on resume of Intel E810 (LP: #2162803)
     - ice: wait for reset completion in ice_resume()
 .
   * idxd: crash-kernel NULL-pointer Oops in `destroy_workqueue()` breaks kdump
     on Intel DSA/IAA systems (LP: #2163062)
     - SAUCE: dmaengine: idxd: Do not call destroy_workqueue with null idxd->wq
     - SAUCE: dmaengine: idxd: fix duplicate memory frees on initialization
       error path.
 .
   * [HP][ZBook Power 16 G11] Laptop freezed after upgrading the BIOS
     (LP: #2132119)
     - PCI/ASPM: Avoid L0s for Realtek RTS525A
 .
   * Fix noise of audio output on more Dell QCx1255 models after reboot
     (LP: #2163293)
     - ALSA: hda/realtek - Add quirk for Dell Pro QC1255
 .
   * Fix no audio input/output device on Dell WCL Slate platform with
     CirrusLogic audio solution (LP: #2160200)
     - ASoC: SDCA: fix the register to ctl value conversion for Q7.8 format
     - ASoC: SOF: ipc4-control: Use local copy of IPC message for sending
 .
   * Fix no audio output and mute hotkey not working on HP ZBook 8 G2a
     (LP: #2158858)
     - ALSA: hda/realtek: Add inverted LED quirk for HP ZBook 8 G2a
 .
   * Dock ethernet stops working after Thunderbolt dock unplug on Dell systems
     (LP: #2162704)
     - usb: core: port: Deattach Type-C connector on component unbind
 .
   * USB-C alt mode dropped with false firmware bug warning on Dell systems
     (LP: #2162695)
     - Revert "usb: typec: ucsi: Detect and skip duplicate altmodes from buggy
       firmware"
     - Revert "usb: typec: ucsi: Add duplicate detection to nvidia registration
       path"
     - Revert "usb: typec: ucsi: yoga_c630: Remove redundant duplicate altmode
       handling"
     - usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware
     - usb: typec: ucsi: Add duplicate detection to nvidia registration path
     - usb: typec: ucsi: yoga_c630: Remove redundant duplicate altmode handling
 .
   * Resolute update: upstream stable patchset 2026-08-20 (LP: #2164666)
     - crypto: algif_skcipher - force synchronous processing
     - crypto: sun4i-ss - Remove insecure and unused rng_alg
     - [Config] Remove unused CRYPTO_DEV_SUN4I_SS_PRNG
     - media: uvcvideo: Fix deadlock if uvc_status_stop is called from
       async_ctrl.work
     - bpf: Clear delta when clearing reg id for non-{add,sub} ops
     - selftests/bpf: Add tests for delta tracking when src_reg == dst_reg
     - selftests/bpf: Add tests for stale delta leaking through id reassignment
     - ALSA: hda/realtek: Add quirk for TongFang X6xx45xU
     - ALSA: hda: conexant: Remove mic bias threshold override
     - ALSA: hda: Fix cached

Source diff to previous version
2165407 resolute: llvm-21-dev build-depends breaks cross-builds
2165040 Resolute Stable Update v6.18.40, v7.1.5 bugs
2161748 [SRU][HPE] Take Intel platform into account for old microcode checks
2163508 ice: E810 interface fails to initialize (ice_init_hw failed: -5) during NVM read
2162904 amdgpu panel self-refresh on dual-gpu laptops causes complete built-in panel freeze and severe system instability
2162045 linux 7.0: dw9719 VCM never binds, disabling all IPU3 cameras (regression, fixed upstream)
2164967 Fix TAS2783 SoundWire amp resume timeout \u003e5s
2160082 Linux, Ubuntu, 24.04, System hangs for about 10 seconds when unplug external monitor cable on non TBT dock
2156316 [TWL][Desktop] intel_dmc_wait_fw_load() merge to Ubuntu next release
2164716 Reboot machine with ext4 configured to data=journal could dump spurious call trace
2164516 [UBUNTU 22.04] s390/topology: Use zero-based numbering
2163375 Ethernet adapter unusable after suspend/resume on Advantech systems with Intel I226-V
2162803 ice: fix stale -EBUSY on resume of Intel E810
2163062 idxd: crash-kernel NULL-pointer Oops in `destroy_workqueue()` breaks kdump on Intel DSA/IAA systems
2132119 [HP][ZBook Power 16 G11] Laptop freezed after upgrading the BIOS
2163293 Fix noise of audio output on more Dell QCx1255 models after reboot
2160200 Fix no audio input/output device on Dell WCL Slate platform with CirrusLogic audio solution
2164666 Resolute update: upstream stable patchset 2026-08-20
2163121 [Regression] Laptop fails to power off completely when HDMI is connected in kernel 7.0.0-28
CVE-2023-20585 Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of
CVE-2026-68364 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix ISM dc_lock deadlock during suspend [Why] System hang obse
CVE-2026-72064 In the Linux kernel, the following vulnerability has been resolved: net: mana: Sync page pool RX frags for CPU MANA allocates RX buffers from page
CVE-2026-72065 In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by the NIC Validate the packet l
CVE-2026-72098 In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation There's a buffer overflow in
CVE-2026-72248 In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: support IPIP tunnel with direct xmit The combination of I
CVE-2026-72249 In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: use dst in this direction when pushing IPIP header When p
CVE-2026-72287 In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks M
CVE-2026-72329 In the Linux kernel, the following vulnerability has been resolved: net/liquidio: drop cached VF pci_dev LUT The PF SR-IOV enable path caches VF pc
CVE-2026-72355 In the Linux kernel, the following vulnerability has been resolved: netfs: Fix barriering when walking subrequest list Fix the barriering used when
CVE-2026-72412 In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix handling of _PAGE_UNUSED pte bit The _PAGE_UNUSED softbit should n
CVE-2026-72417 In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() Add sanit
CVE-2026-72442 In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: fix and simplify IP6IP6 tunnel handling Fix nf_flow_ip6_t
CVE-2026-72463 In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix dev use-after-free in xfrm async resumption xfrm async resumption hol
CVE-2026-72477 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: call _ntfs_bad_inode() when failing to rename It is safe to call _ntf
CVE-2026-72493 In the Linux kernel, the following vulnerability has been resolved: net: serialize netif_running() check in enqueue_to_backlog() Syzbot reported a
CVE-2026-72494 In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Replace waitqueue and flag with completion The driver previously us
CVE-2026-72496 In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Proper rollback if the ioremap fails bnxt_qplib_alloc_dpi returns
CVE-2026-74269 In the Linux kernel, the following vulnerability has been resolved: bnxt: fix head underflow on XDP head-grow The xdp.py test test_xdp_native_adjst
CVE-2026-74350 In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate fast symlink target during inode read ocfs2_validate_inode_bloc
CVE-2026-72495 In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages Applications can req
CVE-2026-72501 In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Initialize dpi variable to zero dpi is initialized only for BNXT_
CVE-2026-72278 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Re-translate VNCR before injecting abort KVM faults in the VNCR
CVE-2026-68083 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_create The SMB2 open lookup i
CVE-2026-68457 In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for FSCTL mutations SET_SPARSE, SET_ZERO_DATA and
CVE-2026-68476 In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after head reallocation __ip_vs_get_out_rt() calls skb_e
CVE-2026-68477 In the Linux kernel, the following vulnerability has been resolved: ipvs: fix more places with wrong ipv6 transport offsets Sashiko reports for mor
CVE-2026-72014 In the Linux kernel, the following vulnerability has been resolved: drbd: reject data replies with an out-of-range payload size recv_dless_read() r
CVE-2026-72020 In the Linux kernel, the following vulnerability has been resolved: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new Commit 9a05475cebdd ("ipvs
CVE-2026-72033 In the Linux kernel, the following vulnerability has been resolved: orangefs: keep the readdir entry size 64-bit in fill_from_part() fill_from_part
CVE-2026-72041 In the Linux kernel, the following vulnerability has been resolved: espintcp: use sk_msg_free_partial to fix partial send sk_msg_free_partial() ens
CVE-2026-72046 In the Linux kernel, the following vulnerability has been resolved: gve: fix header buffer corruption with header-split and HW-GRO The DQO RX datap
CVE-2026-72069 In the Linux kernel, the following vulnerability has been resolved: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() rt_spin_unlock
CVE-2026-72083 In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE core_scs
CVE-2026-72084 In the Linux kernel, the following vulnerability has been resolved: scsi: target: Bound PR-OUT TransportID parsing to the received buffer core_scsi
CVE-2026-72085 In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free unsubmitted command instead of double-putting it scsi
CVE-2026-72129 In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data with a nonzero offset nvmet_rdma_use_inline_sg()
CVE-2026-72130 In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject short AUTH_RECEIVE buffers nvmet_execute_auth_receive() trus
CVE-2026-64551 In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cause length before reading staleness When an ERROR
CVE-2026-72137 In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_keepalive: avoid double free on send error nat_keepalive_send() frees
CVE-2026-72139 In the Linux kernel, the following vulnerability has been resolved: tcp: defer md5sig_info kfree past RCU grace period in tcp_connect The md5+ao re
CVE-2026-72191 In the Linux kernel, the following vulnerability has been resolved: ntfs3: validate split-point offset in indx_insert_into_buffer indx_insert_into_
CVE-2026-72192 In the Linux kernel, the following vulnerability has been resolved: ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head indx_inser
CVE-2026-72194 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow indx_fi
CVE-2026-72217 In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing xdr_buf_to_bvec() w
CVE-2026-72220 In the Linux kernel, the following vulnerability has been resolved: sunrpc: harden rq_procinfo lifecycle to prevent double-free The svc_release_rqs
CVE-2026-72221 In the Linux kernel, the following vulnerability has been resolved: sunrpc: wait for in-flight TLS handshake callback when cancel loses race When w
CVE-2026-72222 In the Linux kernel, the following vulnerability has been resolved: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback svc_tcp_han
CVE-2026-72226 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: prevent TVLV OOB check overflow A TT unicast TVLV contains the
CVE-2026-72234 In the Linux kernel, the following vulnerability has been resolved: batman-adv: access unicast_ttvn skb->data only after skb realloc The pskb_may_p
CVE-2026-72251 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: reload possible stale data pointer quoting sashiko: ---
CVE-2026-72277 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory When constructing
CVE-2026-72279 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR KVM currently maps t
CVE-2026-72288 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disablin
CVE-2026-72289 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Check the interrupt is still ours before migrating it vgic_pr
CVE-2026-72296 In the Linux kernel, the following vulnerability has been resolved: net: ife: require ETH_HLEN to be pullable in ife_decode() ife decode may return
CVE-2026-72299 In the Linux kernel, the following vulnerability has been resolved: tipc: restrict socket queue dumps in enqueue tracepoints tipc_sk_enqueue() runs
CVE-2026-72317 In the Linux kernel, the following vulnerability has been resolved: SUNRPC: pin upper rpc_clnt across the TLS connect_worker The TLS connect path h
CVE-2026-72318 In the Linux kernel, the following vulnerability has been resolved: cifs: validate DFS referral string offsets parse_dfs_referrals() validates that
CVE-2026-72319 In the Linux kernel, the following vulnerability has been resolved: ipvs: ensure inner headers in ICMP errors are in headroom Sashiko points out th
CVE-2026-72320 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_lookup: fix catchall element handling with inverted lookups nft_
CVE-2026-72322 In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix potential UAF in MLD delayed work A race condition exists betw
CVE-2026-72323 In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() A race condition exists
CVE-2026-64541 In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket smc_cdc_rx_handl
CVE-2026-72339 In the Linux kernel, the following vulnerability has been resolved: qede: fix off-by-one in BD ring consumption on build_skb failure qede_rx_build_
CVE-2026-72348 In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop The ah,
CVE-2026-72351 In the Linux kernel, the following vulnerability has been resolved: gue: validate REMCSUM private option length GUE private flags can indicate that
CVE-2026-72366 In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_create_write_req() to handle async cache object creation netfs
CVE-2026-72381 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of fp->owner.name in durable handle owner check Two c
CVE-2026-72393 In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: don't cache shinfo across skb realloc fbnic_tx_lso() calls skb_cow_
CVE-2026-72398 In the Linux kernel, the following vulnerability has been resolved: sctp: add INIT verification after cookie unpacking In SCTP handshake, the INIT
CVE-2026-72399 In the Linux kernel, the following vulnerability has been resolved: net: enetc: check the number of BDs needed for xdp_frame The size of xdp_redire
CVE-2026-64530 In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify()
CVE-2026-72422 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE co
CVE-2026-72429 In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix type confusion of dst_entry IOAM uses a dummy dst_entry(null_ds
CVE-2026-72436 In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types Sa
CVE-2026-72451 In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix xfrm state cache insertion race The xfrm input state cache insertion
CVE-2026-72466 In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix bcall rep leak and unbounded peek rpcrdma_is_bcall() decodes a re
CVE-2026-72472 In the Linux kernel, the following vulnerability has been resolved: nfs: use nfsi->rwsem to protect traversal of the file lock list Lingfeng identi
CVE-2026-72473 In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Decouple req recycling from RPC completion rl_kref formerly served tw
CVE-2026-72491 In the Linux kernel, the following vulnerability has been resolved: net/9p: fix race condition on rdma->state in trans_rdma.c The rdma->state field
CVE-2026-74255 In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in tipc_l2_send_msg() Syzbot reported a slab-use-after-free in ip
CVE-2026-74267 In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before r
CVE-2026-74268 In the Linux kernel, the following vulnerability has been resolved: tcp: clear sock_ops cb flags before force-closing a child socket A child socket
CVE-2026-74287 In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded address parameter length sctp_verify_asconf() and sctp_
CVE-2026-74310 In the Linux kernel, the following vulnerability has been resolved: vhost/net: complete zerocopy ubufs only once vhost-net initializes one ubuf_inf
CVE-2026-74345 In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix endpoint/socket association handling Disassociating a socket from
CVE-2026-74361 In the Linux kernel, the following vulnerability has been resolved: nvme: fix FDP fdpcidx bounds check The fdpcidx bounds check sets n = NUMFDPC +
CVE-2026-74376 In the Linux kernel, the following vulnerability has been resolved: md/raid10: reset read_slot when reusing r10bio for discard put_all_bios() alway
CVE-2026-74384 In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix flex array size in struct nvme_ns_head struct nvme_ns_head
CVE-2026-74394 In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: fix integer overflow in immediate data length check imm_buf->len is
CVE-2026-74398 In the Linux kernel, the following vulnerability has been resolved: ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD addrcon
CVE-2026-74401 In the Linux kernel, the following vulnerability has been resolved: dlm: fix add msg handle in send_queue ordered In a benchmark scenario triggerin
CVE-2026-74406 In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). udp_tunnel_
CVE-2026-74427 In the Linux kernel, the following vulnerability has been resolved: afs: Fix netns teardown to cancel the preallocation charger Fix the teardown of
CVE-2026-74428 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix double unlock in rxrpc_recvmsg() Fix a double unlock in rxrpc_recvms
CVE-2026-74433 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix UAF in rxgk_issue_challenge() Fix rxgk_issue_challenge() to free the
CVE-2026-74434 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Don't move a peeked OOB message onto the pending queue rxrpc_recvmsg_oob
CVE-2026-74436 In the Linux kernel, the following vulnerability has been resolved: rxrpc: serialize kernel accept preallocation with socket teardown rxrpc_kernel_
CVE-2026-64535 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnera
CVE-2026-74439 In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry d
CVE-2026-64534 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nv

Version: 7.0.0-31.31 2026-08-01 07:10:19 UTC

 linux (7.0.0-31.31) resolute; urgency=medium
 .
   * resolute/linux: 7.0.0-31.31 -proposed tracker (LP: #2162413)
 .
   * Backport: "firmware: arm_ffa: Respect firmware advertised RX/TX buffer
     size limits" (LP: #2162012)
     - firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits
 .
   * Backlight regression (LP: #2161309)
     - Revert "drm/i915/backlight: Remove try_vesa_interface"
 .
   * Resolute real-time patchset: 7.0.1-rt2 (LP: #2161757)
     - SAUCE: Reapply "serial: 8250: Switch to nbcon console"
     - SAUCE: Reapply "serial: 8250: Revert "drop lockdep annotation from
       serial8250_clear_IER()""
     - Real-time patchset 7.0.1-rt2
 .
   * Delta_Ubuntu24.04_Ubuntu (Waston)_Suspend(S3) Stress Test Fail when the
     A400 is on by remote controller . (LP: #2161385)
     - SAUCE: drm/amd/display: Tear down dangling pipe on boot to fix s0i3
 .
   * Camera output is vague and color is abnormal (LP: #2156972)
     - media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for
       overlapping ranges
 .
   * [SRU] Fix incorrect boot_display reporting on multi-GPU systems
     (LP: #2161036)
     - x86/video: Only fall back to vga_default_device() without screen info
 .
   * Backport: complete perf_allow_* trio and use in drm/xe (LP: #2160654)
     - perf/core: out-of-line and export perf_allow_cpu/tracepoint()
     - drm/xe: gate observation streams with perf_allow_cpu()
 .
   * Fix noise of audio output on Dell Pro QCM1255 after reboot (LP: #2160666)
     - ALSA: hda/realtek - Fixed Headphone noise issue for Dell QCM1255
 .
   * Drop DEP-8 tests from kernel packages (LP: #2160302)
     - [Packaging] Drop DEP-8 tests from kernel source
 .
   * The screen will show garbages by running glxgears fullscreen.
     (LP: #2158605)
     - SAUCE: drm/xe/display: skip FORCE_WC and vm_bound check for external
       dma-bufs
 .
   * Audio shows Dummy Output on systems with Cirrus Logic cs42l43 codec
     (LP: #2156313)
     - ASoC: sdw_utils: fix missing component_name for cs42l43 part_id 0x2A3B
 .
   * TPM2 key creation commands time out on some Infineon modules
     (LP: #2158883)
     - tpm: restore timeout for key creation commands
 .
   * Fix Mic Mute LED no function on HP EliteBook (LP: #2158860)
     - ALSA: hda/realtek: Add LED fixup for HP EliteBook 6 G2i Laptops
 .
   * Malformed HV_LINUX_VENDOR_ID breaks VM Availability Metric on Azure
     (LP: #2158462)
     - SAUCE: (no-up) hv: Fix supplied vendor ID
 .
   * [SRU]Enable Realtek ALC287 + Cirrus CS35L56 Audio for Lenovo Yoga Pro 7
     (LP: #2156867)
     - ALSA: hda/realtek: ALC269 fixup for Lenovo Yoga Pro 7 15ASH111 audio
     - ALSA: hda/realtek:ALC269 fixup for Yoga Pro 7 15ASH11 mic mute LED
     - ASoC: amd: acp: Add DMI quirk for Lenovo Yoga Pro 7 15ASH11
 .
   * iwlwifi failed to handle oversized command 0xC05 (LP: #2152688)
     - wifi: iwlwifi: mld: add support for iwl_mcc_allowed_ap_type_cmd v2
     - wifi: iwlwifi: mvm: avoid oversized UATS command copy
 .
   * MT7925 wifi is hard blocked on Dell's machine (LP: #2158229)
     - SAUCE: Revert "wifi: mt76: mt7925: add rfkill_poll for hardware rfkill"
 .
   * Resolute update: upstream stable patchset 2026-07-21 (LP: #2161462)
     - rust: str: use the "kernel vertical" imports style
     - rust: str: clean unused import for Rust >= 1.98
     - userfaultfd: gate must_wait writability check on pte_present()
     - device property: initialize the remaining fields of fwnode_handle in
       fwnode_init()
     - f2fs: fix potential deadlock in f2fs_balance_fs()
     - f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()
     - f2fs: fix listxattr handling of corrupted xattr entries
     - net/sched: dualpi2: fix GSO backlog accounting
     - mm/khugepaged: write all dirty file folios when collapsing
     - slab: recognize @GFP parameter as optional in kernel-doc
     - perf trace beauty fcntl: Fix build with older kernel headers
     - KVM: x86: Move update_cr8_intercept() to lapic.c
     - KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest
       mode
     - KVM: x86: Unconditionally recompute CR8 intercept on PPR update
     - ACPI: CPPC: Suppress UBSAN warning caused by field misuse
     - ACPI: NFIT: core: Fix possible NULL pointer dereference
     - platform/x86: intel-hid: Protect ACPI notify handler against recursion
     - LoongArch: Add PIO for early access before ACPI PCI root register
     - rust: cpufreq: clean new `clippy::map_or_identity` lint for Rust 1.98.0
     - rust: block: fix GenDisk cleanup paths
     - rust: doctest: fix incorrect pattern in replacement
     - rust: Kbuild: set frame-pointer llvm module flag for
       CONFIG_FRAME_POINTER
     - futex/requeue: Revert "Prevent NULL pointer dereference in
       remove_waiter() on self-deadlock""
     - perf/core: Detach event groups during remove_on_exec
     - rust: kasan: KASAN+RUST requires clang
     - fscrypt: Replace mk_users keyring with simple list
     - usb: gadget: function: rndis: add length check to response query
     - usb: gadget: function: rndis: add length check for header
     - iio: accel: bmc150: clamp the device-reported FIFO frame count
     - iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
     - iio: adc: ad7380: select REGMAP
     - iio: adc: ad7768-1: Select GPIOLIB
     - iio: adc: ad7779: add missing 'select IIO_TRIGGERED_BUFFER' to Kconfig
     - iio: adc: ad_sigma_delta: fix clear_pending_event for registerless
       devices
     - iio: adc: ad_sigma_delta: fix CS held asserted and state leaks
     - iio: adc: lpc32xx: Initialize completion before requesting IRQ
     - iio: adc: spear: Initialize completion before requesting IRQ
     - iio: adc: ti-ads1119: fix PM reference leak in buffer preenable
     - iio: adc: ti-ads124s08: Return reset GPIO lookup errors
     - iio: backend: fix uninitialized data in debugfs
     - iio: chemical: scd30: Cleanup initializations and fix sign-extension bu

Source diff to previous version
2161309 Backlight regression
2161757 Resolute real-time patchset: 7.0.1-rt2
2161385 Delta_Ubuntu24.04_Ubuntu (Waston)_Suspend(S3) Stress Test Fail when the A400 is on by remote controller .
2160654 Backport: complete perf_allow_* trio and use in drm/xe
2160666 Fix noise of audio output on Dell Pro QCM1255 after reboot
2160302 Drop DEP-8 tests from kernel packages
2158605 The screen will show garbages by running glxgears fullscreen.
2156313 Audio shows Dummy Output on systems with Cirrus Logic cs42l43 codec
2158883 TPM2 key creation commands time out on some Infineon modules
2158860 Fix Mic Mute LED no function on HP EliteBook
2158462 Malformed HV_LINUX_VENDOR_ID breaks VM Availability Metric on Azure
2161462 Resolute update: upstream stable patchset 2026-07-21
2160733 Resolute update: upstream stable patchset 2026-07-15
2158815 Resolute update: v7.0.14 upstream stable release
2158003 Resolute update: v7.0.13 upstream stable release
1786013 Packaging resync
CVE-2026-53361 In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that un
CVE-2026-53362 In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(),
CVE-2026-53325 In the Linux kernel, the following vulnerability has been resolved: agp/amd64: Fix broken error propagation in agp_amd64_probe() A NULL pointer der
CVE-2026-52938 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix NULL pointer dereference in bpf_sk_storage_clone and diag paths bpf_se
CVE-2025-10263 Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Corte
CVE-2026-46300 In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() c
CVE-2026-64531 In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores gene
CVE-2026-46331 In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act
CVE-2026-53212 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix use-after-free on object destroy nft_tunnel_obj_dest
CVE-2026-53359 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af
CVE-2026-53131 In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt
CVE-2026-53151 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table for parsing Fix modificatio
CVE-2026-53175 In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush On netns t
CVE-2026-53176 In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband
CVE-2026-53186 In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received length srp_process_rsp() cop
CVE-2026-53215 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns t
CVE-2026-53216 In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM p
CVE-2026-53221 In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() In vti6_tnl_lookup(
CVE-2026-53224 In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpa
CVE-2026-53225 In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup()
CVE-2026-53228 In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offloads ipip6_tunnel_xmit() cach
CVE-2026-52924 In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only
CVE-2026-53246 In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing When a l
CVE-2026-53247 In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown mtk_fre
CVE-2026-53260 In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). syzbot re

Version: 7.0.0-28.28 2026-06-21 03:09:32 UTC

 linux (7.0.0-28.28) resolute; urgency=medium
 .
   * resolute/linux: 7.0.0-28.28 -proposed tracker (LP: #2157520)
 .
   * Backport ASoC SDCA, AMD SoundWire, and RT722 audio fixes (LP: #2154418)
     - ASoC: amd: acp-sdw-legacy: rename the dmic component name
     - SAUCE: ASoC: rt722-sdca: add FU06 Playback Switch for speaker mute
       control
 .
   * MIPI camera of a BBG809N3A_B sensor SKU of the DELL Pro 14 Premium PA14260
     renders upside-down (LP: #2155837)
     - SAUCE: media: ipu-bridge: correct platform handling for DELL Pro 14
       Premium PA14260
 .
   * resolute ubuntu_kernel_selftests:seccomp_build test compilation issue
     (LP: #2154174)
     - SAUCE: selftests/seccomp fix compilation issue for amd64
 .
   * [Ubuntu 26.04] Severe Performance Degradation on kernel 7.0.0-15
     (LP: #2154748)
     - s390: Remove GENERIC_LOCKBREAK Kconfig option
     - UBUNTU [Config]: Remove GENERIC_LOCKBREAK in s390x
 .
   * Fix no sound output device on Dell GhostRider PTL no camera SKU
     (LP: #2156559)
     - ASoC: Intel: sof_sdw: append dai type to dai link name unconditionally
 .
   * Fix no audio from right built-in speaker on HP ZBook with TAS2781
     amplifier (LP: #2156556)
     - ALSA: hda/tas2781: Fix device-0 reset issue and handle -EXDEV in block
       data processing
 .
   * Installer fails internally with a RSync error due to page fault
     (LP: #2150640)
     - ovl: keep err zero after successful ovl_cache_get()
 .
   * Internal display black screen on Intel Lunar Lake with eDP panel
     (LP: #2156312)
     - drm/i915/alpm: Allow LOBF only for platform that have Always on VRR TG
 .
   * Thunderbolt DP tunnel torn down during boot with LUKS Full Disk Encryption
     (LP: #2155096)
     - SAUCE: thunderbolt: Defer DP tunnel teardown until display driver is
       ready
 .
   * watchdog: lenovo_se10_wdt: Add SE10 Gen 2 support (LP: #2154715)
     - watchdog: lenovo_se10_wdt: Add support for SE10 Gen 2 platform
     - watchdog: lenovo_se10_wdt: Fix use-after-free and resource leak risk
 .
   * [Ubuntu 26.04] KVM: IBM Test Accelerator for Z (TAZ) not working properly
     (LP: #2153159)
     - KVM: s390: only deliver service interrupt with payload
     - KVM: s390: vsie: Allow non-zarch guests
     - KVM: s390: vsie: Disable some bits when in ESA mode
     - KVM: s390: vsie: Accommodate ESA prefix pages
     - KVM: s390: Add KVM capability for ESA mode guests
 .
   * ubuntu_bpf failed to build on Resolute (error: expected ‘:’, ‘,’, ‘;’, ‘}’
     or ‘__attribute__’ before ‘__counted_by’) (LP: #2150071)
     - tools/headers: Regenerate stddef.h to fix BPF selftests
 .
   * ubuntu_bpf: FTBFS with clang 23 / gcc 15 (LP: #2154343)
     - selftests/bpf: Fix const qualifier warning in fexit_bpf2bpf.c
 .
   * ALSA: hda/tas2781 Audio Fix for the front-right speacker (LP: #2149770)
     - ALSA: hda/tas2781: Fix sound abnormal issue on some SPI device
 .
   * Fix bad audio record quality when volume above 50% on Framework PTL
     (LP: #2153155)
     - ALSA: hda/realtek: fix mic boost on Framework PTL
 .
   * Patchset for TUXEDO devices (LP: #2152570)
     - drm/i915/vbt: Add edp pipe joiner enable/disable bits
     - drm/i915/dp: Avoid joiner for eDP if not enabled in VBT
     - drm/amd/display: Add Idle state manager(ISM)
     - drm/i915/backlight: Remove try_vesa_interface
     - drm/i915/backlight: Use intel_panel variable instead of intel_connector
     - drm/i915/backlight: Take luminance_set into account for VESA backlight
     - drm/i915/backlight: Check luminance_set when disabling PWM via AUX VESA
       backlight
     - drm/i915/backlight: Short circuit intel_dp_aux_supports_hdr_backlight
     - drm/i915/backlight: Update debug log during backlight setup
     - drm/i915/backlight: Check if VESA backlight is possible
     - drm/i915/backlight: Provide clear description on how backlight level is
       controlled
     - drm/i915/backlight: Fix VESA backlight possible check condition
 .
   * Resolute update: v7.0.12 upstream stable release (LP: #2156636)
     - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size
     - ACPI: button: Fix ACPI GPE handler leak during removal
     - ACPI: button: Enable wakeup GPEs for ACPI buttons at probe time
     - xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
     - net/sched: sch_sfb: Replace direct dequeue call with peek and
       qdisc_dequeue_peeked
     - bcache: fix uninitialized closure object
     - nfc: llcp: Fix use-after-free in llcp_sock_release()
     - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()
     - xfrm: Check for underflow in xfrm_state_mtu
     - nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems
     - tools/bootconfig: Fix buf leaks in apply_xbc
     - HID: remove duplicate hid_warn_ratelimited definition
     - kunit: fix use-after-free in debugfs when using kunit.filter
     - accel/rocket: fix UAF via dangling GEM handle in create_bo
     - netfilter: synproxy: refresh tcphdr after skb_ensure_writable
     - netfilter: xt_cpu: prefer raw_smp_processor_id
     - netfilter: ebtables: fix OOB read in compat_mtw_from_user
     - netfilter: nf_tables: fix dst corruption in same register operation
     - vsock: keep poll shutdown state consistent
     - net: netlink: fix sending unassigned nsid after assigned one
     - net: netlink: don't set nsid on local notifications
     - net/smc: Do not re-initialize smc hashtables
     - net/iucv: fix locking in .getsockopt
     - scsi: core: Run queues for all non-SDEV_DEL devices from
       scsi_run_host_queues
     - scsi: scsi_debug: Add missing newline in scsi_debug_device_reset()
     - ipv4: free net->ipv4.sysctl_local_reserved_ports after
       unregister_net_sysctl_table()
     - ALSA: hda: cs35l56: Fix system name string leaks
     - ALSA: pcm: oss: Fix setup list UAF on proc write error
     - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors
     - net/mlx5: HWS: Reject

Source diff to previous version
2154174 resolute ubuntu_kernel_selftests:seccomp_build test compilation issue
2154748 [Ubuntu 26.04] Severe Performance Degradation on kernel 7.0.0-15
2156559 Fix no sound output device on Dell GhostRider PTL no camera SKU
2156556 Fix no audio from right built-in speaker on HP ZBook with TAS2781 amplifier
2150640 Installer fails internally with a RSync error due to page fault
2156312 Internal display black screen on Intel Lunar Lake with eDP panel
2155096 Thunderbolt DP tunnel torn down during boot with LUKS Full Disk Encryption
2154715 watchdog: lenovo_se10_wdt: Add SE10 Gen 2 support
2153159 [Ubuntu 26.04] KVM: IBM Test Accelerator for Z (TAZ) not working properly
2150071 ubuntu_bpf failed to build on Resolute (error: expected \u2018:\u2019, \u2018,\u2019, \u2018;\u2019, \u2018}\u2019 or \u2018__attribute__\u2019 befor
2154343 ubuntu_bpf: FTBFS with clang 23 / gcc 15
2149770 ALSA: hda/tas2781 Audio Fix for the front-right speacker
2153155 Fix bad audio record quality when volume above 50% on Framework PTL
2152570 Patchset for TUXEDO devices
2156636 Resolute update: v7.0.12 upstream stable release
2156390 Resolute update: v7.0.11 upstream stable release
2156385 Resolute update: v7.0.10 upstream stable release
2156006 Resolute update: v7.0.9 upstream stable release
2155988 Resolute update: v7.0.7 upstream stable release
2150845 Ubuntu 26.04 linux kernel has non-functional nova-core GPU driver enabled, conflicting with nouveau
CVE-2026-46318 In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hugetlbfs to use mmap_prepare" This reverts commit
CVE-2026-46322 In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one() When build_skb() fails in
CVE-2026-46320 In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects
CVE-2026-46321 In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns
CVE-2026-46316 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased e
CVE-2026-46317 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_lock kvm->arch.nested_mmus[]
CVE-2026-45846 In the Linux kernel, the following vulnerability has been resolved: bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() bareudp_fi
CVE-2026-45845 In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: fix NULL pointer dereference in class dump When a TAPRIO chi
CVE-2026-45844 In the Linux kernel, the following vulnerability has been resolved: netfilter: arp_tables: fix IEEE1394 ARP payload parsing Weiming Shi says: "arp
CVE-2026-46242 In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep
CVE-2026-45843 In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed packet length slhc_uncompress
CVE-2026-45842 In the Linux kernel, the following vulnerability has been resolved: slip: reject VJ receive packets on instances with no rstate array slhc_init() a
CVE-2026-45841 In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO nf_osf_match_one
CVE-2026-45840 In the Linux kernel, the following vulnerability has been resolved: openvswitch: cap upcall PID array size and pre-size vport replies The vport net
CVE-2026-45839 In the Linux kernel, the following vulnerability has been resolved: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() CO-RE acce
CVE-2026-45838 In the Linux kernel, the following vulnerability has been resolved: bpf: fix end-of-list detection in cgroup_storage_get_next_key() list_next_entry
CVE-2026-46214 In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix accept queue count leak on transport mismatch virtio_transpor
CVE-2026-46207 In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix empty payload in tap skb for non-linear buffers For non-linea
CVE-2026-46234 In the Linux kernel, the following vulnerability has been resolved: vsock: fix buffer size clamping order In vsock_update_buffer_size(), the buffer
CVE-2026-46223 In the Linux kernel, the following vulnerability has been resolved: cgroup: Defer css percpu_ref kill on rmdir until cgroup is depopulated A chain
CVE-2026-46221 In the Linux kernel, the following vulnerability has been resolved: EDAC/versalnet: Fix device name memory leak The device name allocated via kzall
CVE-2026-46231 In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: put backbone reference on failed claim hash insert When batadv
CVE-2026-46233 In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: only purge non-released claims When batadv_bla_purge_claims()
CVE-2026-46212 In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: prevent use-after-free when deleting claims When batadv_bla_de
CVE-2026-46238 In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop caching unowned originator pointers in BAT IV BAT IV keeps the
CVE-2026-46208 In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop tp_meter sessions during mesh teardown TP meter sessions remai
CVE-2026-46206 In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject new tp_meter sessions during teardown Prevent tp_meter from
CVE-2026-46198 In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix integer overflow on buff_pos Fixing an integer overflow present
CVE-2026-46227 In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL The S
CVE-2026-46220 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission sdma_v4_0_ring_
CVE-2026-46215 In the Linux kernel, the following vulnerability has been resolved: drm: Set old handle to NULL before prime swap in change_handle There was a pote
CVE-2026-46201 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() When xe_dma_buf_in
CVE-2026-46224 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix bo leak in xe_dma_buf_init_obj() on allocation failure When drm_gpu
CVE-2026-46197 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: validate SVM ioctl nattr against buffer size Validate nattr field a
CVE-2026-46209 In the Linux kernel, the following vulnerability has been resolved: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_fu
CVE-2026-46230 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg Check bounds against th
CVE-2026-46199 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg Check bounds against th
CVE-2026-46204 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB Rewrite the IB parsing to us
CVE-2026-46218 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Add bounds checking to ib_{get,set}_value The uvd/vce/vcn code acce
CVE-2026-46229 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure KFD VRAM al
CVE-2026-46211 In the Linux kernel, the following vulnerability has been resolved: drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata() msm_ioctl_
CVE-2026-46203 In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: fix unclocked access on unbind Make sure that the control
CVE-2026-46219 In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-free on unbind The state machine work is scheduled
CVE-2026-46200 In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix controller deregistration Make sure to deregister the control
CVE-2026-46241 In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-free on registration failure Make sure to disable a
CVE-2026-46225 In the Linux kernel, the following vulnerability has been resolved: spi: rspi: fix controller deregistration Make sure to deregister the controller
CVE-2026-46226 In the Linux kernel, the following vulnerability has been resolved: spi: fsl: fix controller deregistration Make sure to deregister the controller
CVE-2026-46228 In the Linux kernel, the following vulnerability has been resolved: spi: ch341: fix devres lifetime USB drivers bind to USB interfaces and any devi
CVE-2026-46216 In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status() When
CVE-2026-46210 In the Linux kernel, the following vulnerability has been resolved: media: iris: fix use-after-free of fmt_src during MBPF check During concurrency
CVE-2026-46240 In the Linux kernel, the following vulnerability has been resolved: media: iris: Fix use-after-free in iris_release_internal_buffers() The recent c
CVE-2026-46235 In the Linux kernel, the following vulnerability has been resolved: media: saa7164: add ioremap return checks and cleanups Add checks for ioremap r
CVE-2026-46222 In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: Add missing MUST_CONNECT flag to pads The pads missed c
CVE-2026-46239 In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov5647: Fix runtime PM refcount leak in s_ctrl Three control cases
CVE-2026-46236 In the Linux kernel, the following vulnerability has been resolved: media: rc: xbox_remote: heed DMA restrictions The buffer for IO must not be par
CVE-2026-46205 In the Linux kernel, the following vulnerability has been resolved: staging: media: atomisp: Disallow all private IOCTLs Disallow all private IOCTL
CVE-2026-46202 In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: run inactivity autodim from workqueues The autodim code in hi
CVE-2026-46213 In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: fix UAF in inactivity-timer cleanup path Commit 38224c472a03
CVE-2026-46232 In the Linux kernel, the following vulnerability has been resolved: HID: playstation: Clamp num_touch_reports A device would never lie about the nu
CVE-2026-43490 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inherit_dacl() walks the parent di
CVE-2026-46174 In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache
CVE-2026-46110 In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Prevent NULL deref when RX memory exhausted The CPU receives frame
CVE-2026-46153 In the Linux kernel, the following vulnerability has been resolved: 8021q: delete cleared egress QoS mappings vlan_dev_set_egress_priority() curren
CVE-2026-46169 In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix uninit-value by validating catalog record size Syzbot reported a K
CVE-2026-46188 In the Linux kernel, the following vulnerability has been resolved: octeon_ep_vf: add NULL check for napi_build_skb() napi_build_skb() can return N
CVE-2026-45837 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free in arena_vm_close on fork arena_vm_open() only bumps vm
CVE-2026-46156 In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang() The switch case i
CVE-2026-46147 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu() Two bug
CVE-2026-46175 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix fsck inconsistency caused by FGGC of node block During FGGC node bloc
CVE-2026-46194 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix node_cnt race between extent node destroy and writeback f2fs_destroy_
CVE-2026-46170 In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: free sk if last When an ADD_ADDR is retransmitted, the
CVE-2026-46158 In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount When an ADD_ADDR is retran
CVE-2026-46168 In the Linux kernel, the following vulnerability has been resolved: mptcp: fix scheduling with atomic in timestamp sockopt Using lock_sock_fast() (
CVE-2026-46189 In the Linux kernel, the following vulnerability has been resolved: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path Sashiko
CVE-2026-46133 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Reject unknown opcodes before ICRC processing Even after applying com
CVE-2026-46114 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads atomic_write_reply() at drive
CVE-2026-46127 In the Linux kernel, the following vulnerability has been resolved: RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() Sashiko
CVE-2026-46176 In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() mlx5_ib_de
CVE-2026-46178 In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() Sashiko points ou
CVE-2026-46181 In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() Sashiko points out the radix_
CVE-2026-46145 In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Validate rx_hash_key_len Sashiko points out that rx_hash_key_len com
CVE-2026-46117 In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() Sashiko
CVE-2026-46126 In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() Sashiko
CVE-2026-46144 In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() Sashiko points out that
CVE-2026-46141 In the Linux kernel, the following vulnerability has been resolved: powerpc/xive: fix kmemleak caused by incorrect chip_data lookup The kmemleak re
CVE-2026-46183 In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: protect path kfree() with damon_sysfs_lock damon_sysfs_
CVE-2026-46121 In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock Patch
CVE-2026-46131 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: check for nEPT/nNPT in slow flush hypercalls Checking is_guest_mode(v
CVE-2026-46139 In the Linux kernel, the following vulnerability has been resolved: smb: client: use kzalloc to zero-initialize security descriptor buffer Commit 6
CVE-2026-46105 In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Limit NVMe request size to 2 MiB The HBA firmware reports NVMe M
CVE-2026-46171 In the Linux kernel, the following vulnerability has been resolved: riscv: kvm: fix vector context allocation leak When the second kzalloc (host_co
CVE-2026-46112 In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() Sashiko points out that hns
CVE-2026-46165 In the Linux kernel, the following vulnerability has been resolved: openvswitch: vport: fix self-deadlock on release of tunnel ports vports are use
CVE-2026-46161 In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies setup_geo() e
CVE-2026-43492 In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming report
CVE-2026-46124 In the Linux kernel, the following vulnerability has been resolved: isofs: validate block number from NFS file handle in isofs_export_iget isofs_fh
CVE-2026-46130 In the Linux kernel, the following vulnerability has been resolved: dm-verity-fec: fix reading parity bytes split across blocks (take 3) fec_decode
CVE-2026-46106 In the Linux kernel, the following vulnerability has been resolved: eventfs: Hold eventfs_mutex and SRCU when remount walks events Commit 340f0c706
CVE-2026-46107 In the Linux kernel, the following vulnerability has been resolved: dm-thin: fix metadata refcount underflow There's a bug in dm-thin in the functi
CVE-2026-46160 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix missing last_unlink_trans update when removing a directory When remo
CVE-2026-46164 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free in create_space_info_sub_group() error path When kobject
CVE-2026-46129 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free in create_space_info() error path When kobject_init_and_
CVE-2026-46159 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-lea
CVE-2026-46143 In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens As prepare can be called
CVE-2026-46148 In the Linux kernel, the following vulnerability has been resolved: spi: microchip-core-qspi: control built-in cs manually The coreQSPI IP supports
CVE-2026-46192 In the Linux kernel, the following vulnerability has been resolved: spi: microchip-core-qspi: don't attempt to transmit during emulated read-only du
CVE-2026-46162 In the Linux kernel, the following vulnerability has been resolved: ice: fix double free in ice_sf_eth_activate() error path When auxiliary_device_
CVE-2026-46273 In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power
CVE-2026-46191 In the Linux kernel, the following vulnerability has been resolved: fbcon: Avoid OOB font access if console rotation fails Clear the font buffer if
CVE-2026-46134 In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: Init mutex in Thunderbolt registration cros_typ
CVE-2026-43495 In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_ms
CVE-2026-43502 In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy s
CVE-2026-46120 In the Linux kernel, the following vulnerability has been resolved: ip6_gre: Use cached t->net in ip6erspan_changelink(). After commit 5e72ce3e3980
CVE-2026-46142 In the Linux kernel, the following vulnerability has been resolved: net: libwx: fix VF illegal register access Register WX_CFG_PORT_ST is a PF rest
CVE-2026-46118 In the Linux kernel, the following vulnerability has been resolved: pseries/papr-hvpipe: Fix null ptr deref in papr_hvpipe_dev_create_handle() comm
CVE-2026-46182 In the Linux kernel, the following vulnerability has been resolved: pseries/papr-hvpipe: Prevent kernel stack memory leak to userspace The hdr vari
CVE-2026-46184 In the Linux kernel, the following vulnerability has been resolved: sound: ua101: fix division by zero at probe Add a missing sanity check for bNrC
CVE-2026-43498 In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Disallow re-exporting imported GEM objects Prevent re-exporting of
CVE-2026-46132 In the Linux kernel, the following vulnerability has been resolved: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfin
CVE-2026-46190 In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() Sashiko
CVE-2026-46150 In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may
CVE-2026-45836 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() Add the sa
CVE-2026-45834 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() Add the sa
CVE-2026-45835 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() Add the
CVE-2026-46138 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_comple
CVE-2026-46111 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potential UAF in create_big_sync Add hci_conn_valid()
CVE-2026-46140 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: validate WMT event SKB length before struct access btmtk_usb_
CVE-2026-46186 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: validate rx pkt_type header length virtbt_rx_handle() rea
CVE-2026-46123 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: clamp rx length before skb_put virtbt_rx_work() calls skb
CVE-2026-46104 In the Linux kernel, the following vulnerability has been resolved: selinux: use sk blob accessor in socket permission helpers SELinux socket state
CVE-2026-46193 In the Linux kernel, the following vulnerability has been resolved: xfrm: ah: account for ESN high bits in async callbacks AH allocates its tempora
CVE-2026-46172 In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() xfrm6_rcv_encap() perfor
CVE-2026-46116 In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete KASAN reproduc
CVE-2026-46154 In the Linux kernel, the following vulnerability has been resolved: sched_ext: Read scx_root under scx_cgroup_ops_rwsem in cgroup setters scx_group
CVE-2026-46157 In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger Currently the ru
CVE-2026-46109 In the Linux kernel, the following vulnerability has been resolved: usb: ulpi: fix memory leak on ulpi_register() error paths Commit 01af542392b5 (
CVE-2026-46146 In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() The convert
CVE-2026-46167 In the Linux kernel, the following vulnerability has been resolved: usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl Just like in a pr
CVE-2026-46151 In the Linux kernel, the following vulnerability has been resolved: usb: usblp: fix heap leak in IEEE 1284 device ID via short response usblp_ctrl_
CVE-2026-46180 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task
CVE-2026-46122 In the Linux kernel, the following vulnerability has been resolved: wifi: b43: enforce bounds check on firmware key index in b43_rx() The firmware-
CVE-2026-46125 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: remove station if connection prep fails If connection preparati
CVE-2026-46166 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: use safe list iteration in radar detect work The call to ieee80
CVE-2026-46187 In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: fix kthread lifetime race between self-exit and external-stop RSI dr
CVE-2026-46152 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: drop stray 'static' from fast-RX rx_result ieee80211_invoke_fas
CVE-2026-46163 In the Linux kernel, the following vulnerability has been resolved: wifi: b43legacy: enforce bounds check on firmware key index in RX path Same fix
CVE-2026-46136 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix a potential clc buffer length underflow The buf_len is
CVE-2026-46173 In the Linux kernel, the following vulnerability has been resolved: exit: prevent preemption of oopsing TASK_DEAD task When an already-exiting task
CVE-2026-43496 In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peek
CVE-2026-46113 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN The shadow MMU
CVE-2026-46179 In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Don't allow pointer operations on unconfigured streams When reportin
CVE-2026-46196 In the Linux kernel, the following vulnerability has been resolved: tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() Wh
CVE-2026-43497 In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free dlfb_ops_mm
CVE-2026-46108 In the Linux kernel, the following vulnerability has been resolved: ipmi:si: Return state to normal if message allocation fails There were places w
CVE-2026-46128 In the Linux kernel, the following vulnerability has been resolved: ipmi: Check event message buffer response for bad data The event message buffer
CVE-2026-46177 In the Linux kernel, the following vulnerability has been resolved: ipmi: Add limits to event and receive message requests The driver would just fe
CVE-2026-46149 In the Linux kernel, the following vulnerability has been resolved: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() targ
CVE-2026-46244 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), wh
CVE-2026-46137 In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race This mptcp_pm_add_timer() help
CVE-2026-46185 In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data() Since smb2_check_message()
CVE-2026-46195 In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DACL pointers parse_sec_desc()
CVE-2026-46289 In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract_kvec_to_sg Patch series "Fi
CVE-2026-46119 In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth message processing If a (potenti
CVE-2026-46135 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_
CVE-2026-46155 In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a tr
CVE-2026-46115 In the Linux kernel, the following vulnerability has been resolved: block: add pgmap check to biovec_phys_mergeable biovec_phys_mergeable() is used
CVE-2026-46243 In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descript

Version: 7.0.0-26.26 2026-05-29 05:09:00 UTC

 linux (7.0.0-26.26) resolute; urgency=medium
 .
   * resolute/linux: 7.0.0-26.26 -proposed tracker (LP: #2154530)
 .
   * Packaging resync (LP: #1786013)
     - Revert "UBUNTU: SAUCE: import Huawei ES3000_V2 (2.1.0.23)"
     - [Packaging] debian.master/dkms-versions -- remove dkms-versions
       (main/2026.05.18)
 .
   * Fix mic mute led on a HP EliteBook 6 G2a platform (LP: #2150065)
     - ALSA: hda/realtek: Add LED fixup for HP EliteBook 6 G2a Laptops
 .
   * ov08x40 module mounted upside down on a certain DELL platforms
     (LP: #2146517)
     - SAUCE: media: ipu-bridge: Add DMI quirk for new Dell XPS laptops with
       upside down sensors
     - SAUCE: media: ipu-bridge: Add DMI quirk for Dell 14 laptops with upside
       down sensors
 .
   * Support additional 2888x1808@30fps 900MHz for OVTI05C1 camera sensor
     (LP: #2147409)
     - SAUCE: media: ipu-bridge: Add 900MHz for OV05C10
     - SAUCE: platform/x86: int3472: increase handshake delay to 50ms for
       OV05C10
 .
   * Support Samsung S5K3J1 sensor for Intel MIPI camera (LP: #2121852)
     - SAUCE: media: ipu-bridge: Support s5k3j1 sensor
 .
   * [SRU] ASoC: enable rt1320 speaker amp and DMIC on PTL SoundWire platforms
     (LP: #2150196)
     - ASoC: Intel: soc-acpi-intel-ptl-match: drop rt722 monolithic match
       tables
     - ASoC: SOF: Intel: Add a is_amp flag to fix the wrong name prefix
     - ASoC: sdw_utils: add rt1320 and rt1321 dmic dai in codec_info_list
 .
   * powerpc-build in ubuntu_kernel_selftests fails to build due to
     uninitialized value (LP: #2129844)
     - selftests/powerpc: Suppress -Wmaybe-uninitialized with GCC 15
 .
   * Ubuntu 26.04 linux kernel has non-functional nova-core GPU driver enabled,
     conflicting with nouveau (LP: #2150845)
     - [Config] Disable DRM_NOVA
 .
   * Resolute update: v7.0.6 upstream stable release (LP: #2152558)
     - Linux 7.0.6
     - Upstream stable to v7.0.6
 .
   * Resolute update: v7.0.5 upstream stable release (LP: #2152556)
     - Linux 7.0.5
     - Upstream stable to v7.0.5
 .
   * Resolute update: v7.0.4 upstream stable release (LP: #2152552)
     - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES
     - ALSA: usb-audio: Avoid false E-MU sample-rate notifications
     - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch
     - usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable()
     - usb: chipidea: otg: not wait vbus drop if use role_switch
     - usb: chipidea: core: allow ci_irq_handler() handle both ID and VBUS
       change
     - ALSA: usb-audio: Evaluate packsize caps at the right place
     - LoongArch: Add spectre boundry for syscall dispatch table
     - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check
     - leds: qcom-lpg: Check for array overflow when selecting the high
       resolution
     - greybus: gb-beagleplay: bound bootloader receive buffering
     - greybus: gb-beagleplay: fix sleep in atomic context in hdlc_tx_frames()
     - misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()
     - ibmasm: fix OOB reads in command_file_write due to missing size checks
     - ibmasm: fix heap over-read in ibmasm_send_i2o_message()
     - sysfs: attribute_group: Respect is_visible_const() when changing owner
     - driver core: Don't let a device probe until it's ready
     - device property: Make modifications of fwnode "flags" thread safe
     - drm/nouveau: fix nvkm_device leak on aperture removal failure
     - rust: dma: remove DMA_ATTR_NO_KERNEL_MAPPING from public attrs
     - kbuild: rust: allow `clippy::uninlined_format_args`
     - fs: afs: revert mmap_prepare() change
     - firmware: google: framebuffer: Do not mark framebuffer as busy
     - lib: test_hmm: evict device pages on file close to avoid use-after-free
     - arm64/mm: Enable batched TLB flush in unmap_hotplug_range()
     - arm64: mm: Fix rodata=full block mapping support for realm guests
     - mm: migrate: requeue destination folio on deferred split queue
     - mm: prevent droppable mappings from being locked
     - mm: fix deferred split queue races during migration
     - ocfs2: split transactions in dio completion to avoid credit exhaustion
     - Input: edt-ft5x06 - fix use-after-free in debugfs teardown
     - zram: do not forget to endio for partial discard requests
     - wifi: rtw88: check for PCI upstream bridge existence
     - wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()
     - vfio: selftests: Fix VLA initialisation in vfio_pci_irq_set()
     - vfio/xe: Add a missing vfio_pci_core_release_dev()
     - vfio/virtio: Convert list_lock from spinlock to mutex
     - vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex
     - vfio/cdx: Fix NULL pointer dereference in interrupt trigger path
     - um: drivers: call kernel_strrchr() explicitly in cow_user.c
     - thermal: core: Fix thermal zone governor cleanup issues
     - spi: imx: fix use-after-free on unbind
     - spi: ch341: fix memory leaks on probe failures
     - crypto: algif_aead - snapshot IV for async AEAD requests
     - crypto: pcrypt - Fix handling of MAY_BACKLOG requests
     - dt-bindings: display: ti, am65x-dss: Fix AM62L DSS reg and clock
       constraints
     - of: unittest: fix use-after-free in of_unittest_changeset()
     - of: unittest: fix use-after-free in testdrv_probe()
     - hwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt
     - EDAC/versalnet: Fix device_node leak in mc_probe()
     - PCI: imx6: Skip waiting for L2/L3 Ready on i.MX6SX
     - media: amphion: Fix race between m2m job_abort and device_run
     - ALSA: control: Validate buf_len before strnlen() in
       snd_ctl_elem_init_enum_names()
     - net: caif: clear client service pointer on teardown
     - net: strparser: fix skb_head leak in strp_abort_strp()
     - media: mtk-jpeg: fix use-after-free in release path due to uncancelled
       work
     - crypto: atmel-sha204a - Fix OTP sysfs read and error handling

1786013 Packaging resync
2150065 Fix mic mute led on a HP EliteBook 6 G2a platform
2129844 powerpc-build in ubuntu_kernel_selftests fails to build due to uninitialized value
2150845 Ubuntu 26.04 linux kernel has non-functional nova-core GPU driver enabled, conflicting with nouveau
2152558 Resolute update: v7.0.6 upstream stable release
2152556 Resolute update: v7.0.5 upstream stable release
2152552 Resolute update: v7.0.4 upstream stable release
2152550 Resolute update: v7.0.3 upstream stable release
2150553 Resolute update: v7.0.2 upstream stable release
2150547 Resolute update: v7.0.1 upstream stable release
2154172 GRO managed-frag use-after-free leading to local privilege escalation
2151747 AppArmor Vulnerabilities
2148809 apparmor: LLVM/clang build failure due to uninitialized variable in notify.c
2153962 net/rds: reset op_nents when zerocopy page pin fails
CVE-2026-47337 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible N ...
CVE-2026-47334 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which in ...
CVE-2026-47333 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which ca ...
CVE-2026-47332 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which in ...
CVE-2026-47330 Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which ca ...
CVE-2026-47329 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to val ...
CVE-2026-47327 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible N ...
CVE-2026-47328 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which in ...
CVE-2026-47326 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory lea ...
CVE-2026-46300 In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() c
CVE-2026-46333 In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fu
CVE-2026-43500 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA
CVE-2026-43284 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can atta



About   -   Send Feedback to @ubuntu_updates