[ubuntu/jammy-security] linux-nvidia-tegra-igx 5.15.0-1049.49 (Accepted)

Andy Whitcroft apw at canonical.com
Mon May 25 06:53:40 UTC 2026


linux-nvidia-tegra-igx (5.15.0-1049.49) jammy; urgency=medium

  * jammy/linux-nvidia-tegra-igx: 5.15.0-1049.49 -proposed tracker (LP: #2150983)

  [ Ubuntu-nvidia-tegra: 5.15.0-1060.60 ]

  * jammy/linux-nvidia-tegra: 5.15.0-1060.60 -proposed tracker (LP: #2150985)
  [ Ubuntu-realtime: 5.15.0-1107.116 ]
  * jammy/linux-realtime: 5.15.0-1107.116 -proposed tracker (LP: #2150989)
  [ Ubuntu: 5.15.0-179.189 ]
  * jammy/linux: 5.15.0-179.189 -proposed tracker (LP: #2151014)
  * CVE-2026-31419
    - net: bonding: fix use-after-free in bond_xmit_broadcast()
  * CVE-2026-31431
    - crypto: scatterwalk - Backport memcpy_sglist()
    - crypto: algif_aead - use memcpy_sglist() instead of null skcipher
    - crypto: algif_aead - Revert to operating out-of-place
    - crypto: algif_aead - snapshot IV for async AEAD requests
    - crypto: authenc - use memcpy_sglist() instead of null skcipher
    - crypto: authencesn - Do not place hiseq at end of dst for out-of-place
      decryption
    - crypto: authencesn - Fix src offset when decrypting in-place
    - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
    - crypto: algif_aead - Fix minimum RX size check for decryption
  * CVE-2026-31533
    - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
  * CVE-2026-31504
    - net: fix fanout UAF in packet_release() via NETDEV_UP race

linux-nvidia-tegra-igx (5.15.0-1048.48) jammy; urgency=medium

  * jammy/linux-nvidia-tegra-igx: 5.15.0-1048.48 -proposed tracker (LP: #2148424)

  [ Ubuntu-nvidia-tegra: 5.15.0-1059.59 ]

  * jammy/linux-nvidia-tegra: 5.15.0-1059.59 -proposed tracker (LP: #2148426)
  * apply NVIDIA patches as of April 6, 2026 (LP: #2147340)
    - NVIDIA: SAUCE: i2c: tegra: Skip reset in multimaster mode
    - NVIDIA: SAUCE: spi: tegra114: Fix CS deassertion in multi-transfer
      messages
  [ Ubuntu-realtime: 5.15.0-1106.115 ]
  * jammy/linux-realtime: 5.15.0-1106.115 -proposed tracker (LP: #2148430)
  [ Ubuntu: 5.15.0-178.188 ]
  * jammy/linux: 5.15.0-178.188 -proposed tracker (LP: #2148097)
  * Canonical Kmod 2025 key rotation (LP: #2147447)
    - [Packaging] ubuntu-compatible-signing -- make Ubuntu-Compatible-Signing
      extensible
    - [Packaging] ubuntu-compatible-signing -- allow consumption of positive
      certs
    - [Packaging] ubuntu-compatible-signing -- report the livepatch:2025 key
    - [Config] prepare for Canonical Kmod key rotation
    - [Packaging] ubuntu-compatible-signing -- report the kmod:2025 key
  * ADATA SU680 causes repeated SATA resets and I/O errors on Ubuntu unless
    link power management is forced to max_performance (LP: #2144060)
    - ata: libata-core: disable LPM on ADATA SU680 SSD
  * CVE-2024-50060
    - io_uring: check if we need to reschedule during overflow flush
  * CVE-2024-35862
    - smb: client: fix potential UAF in smb2_is_network_name_deleted()
  * CVE-2026-23274
    - netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
  * CVE-2026-23351
    - netfilter: nf_tables: de-constify set commit ops function argument
    - netfilter: nft_set_pipapo: split gc into unlink and reclaim phase
  * macvlan: observe an RCU grace period in macvlan_common_newlink() error
    path (LP: #2144380) // CVE-2026-23209
    - macvlan: observe an RCU grace period in macvlan_common_newlink() error
      path
  * CVE-2023-2640 // CVE-2023-32629
    - SAUCE: overlayfs: default to userxattr when mounted from non initial
      user namespace
  * CVE-2023-2640 // CVE-2023-2640 and CVE-2023-32629. // CVE-2023-32629
    - SAUCE: Revert "UBUNTU: SAUCE: overlayfs: Skip permission checking for
      trusted.overlayfs.* xattrs"
  * CVE-2026-23112
    - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec

Date: 2026-05-06 21:59:10.020128+00:00
Changed-By: Jacob Martin <jacob.martin at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-nvidia-tegra-igx/5.15.0-1049.49
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list