[ubuntu/jammy-updates] linux-gcp 5.15.0-1108.117 (Accepted)

Andy Whitcroft apw at canonical.com
Thu May 14 17:12:56 UTC 2026


linux-gcp (5.15.0-1108.117) jammy; urgency=medium

  * jammy/linux-gcp: 5.15.0-1108.117 -proposed tracker (LP: #2150974)

  [ Ubuntu: 5.15.0-179.189 ]

  * jammy/linux: 5.15.0-179.189 -proposed tracker (LP: #2151014)
  * CVE-2026-31419
    - net: bonding: fix use-after-free in bond_xmit_broadcast()
  * CVE-2026-31431
    - crypto: scatterwalk - Backport memcpy_sglist()
    - crypto: algif_aead - use memcpy_sglist() instead of null skcipher
    - crypto: algif_aead - Revert to operating out-of-place
    - crypto: algif_aead - snapshot IV for async AEAD requests
    - crypto: authenc - use memcpy_sglist() instead of null skcipher
    - crypto: authencesn - Do not place hiseq at end of dst for out-of-place
      decryption
    - crypto: authencesn - Fix src offset when decrypting in-place
    - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
    - crypto: algif_aead - Fix minimum RX size check for decryption
  * CVE-2026-31533
    - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
  * CVE-2026-31504
    - net: fix fanout UAF in packet_release() via NETDEV_UP race

linux-gcp (5.15.0-1107.116) jammy; urgency=medium

  * jammy/linux-gcp: 5.15.0-1107.116 -proposed tracker (LP: #2148415)

  * Delayed NIC initialization on AWS and GCP instances lead to first-boot
    metadata failures (LP: #2144694)
    - [Config] gcp: Make idpf built-in

  [ Ubuntu: 5.15.0-178.188 ]

  * jammy/linux: 5.15.0-178.188 -proposed tracker (LP: #2148097)
  * Canonical Kmod 2025 key rotation (LP: #2147447)
    - [Packaging] ubuntu-compatible-signing -- make Ubuntu-Compatible-Signing
      extensible
    - [Packaging] ubuntu-compatible-signing -- allow consumption of positive
      certs
    - [Packaging] ubuntu-compatible-signing -- report the livepatch:2025 key
    - [Config] prepare for Canonical Kmod key rotation
    - [Packaging] ubuntu-compatible-signing -- report the kmod:2025 key
  * ADATA SU680 causes repeated SATA resets and I/O errors on Ubuntu unless
    link power management is forced to max_performance (LP: #2144060)
    - ata: libata-core: disable LPM on ADATA SU680 SSD
  * CVE-2024-50060
    - io_uring: check if we need to reschedule during overflow flush
  * CVE-2024-35862
    - smb: client: fix potential UAF in smb2_is_network_name_deleted()
  * CVE-2026-23274
    - netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
  * CVE-2026-23351
    - netfilter: nf_tables: de-constify set commit ops function argument
    - netfilter: nft_set_pipapo: split gc into unlink and reclaim phase
  * macvlan: observe an RCU grace period in macvlan_common_newlink() error
    path (LP: #2144380) // CVE-2026-23209
    - macvlan: observe an RCU grace period in macvlan_common_newlink() error
      path
  * CVE-2023-2640 // CVE-2023-32629
    - SAUCE: overlayfs: default to userxattr when mounted from non initial
      user namespace
  * CVE-2023-2640 // CVE-2023-2640 and CVE-2023-32629. // CVE-2023-32629
    - SAUCE: Revert "UBUNTU: SAUCE: overlayfs: Skip permission checking for
      trusted.overlayfs.* xattrs"
  * CVE-2026-23112
    - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec

Date: 2026-05-07 10:57:15.203768+00:00
Changed-By: Manuel Diewald <manuel.diewald at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-gcp/5.15.0-1108.117
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list