[ubuntu/jammy-proposed] linux 5.15.0-184.194 (Accepted)
Timo Aaltonen
tjaalton at ubuntu.com
Wed May 27 11:56:33 UTC 2026
linux (5.15.0-184.194) jammy; urgency=medium
* jammy/linux: 5.15.0-184.194 -proposed tracker (LP: #2154219)
* Kernel regression (6.8.0-117.generic) (LP: #2153556)
- net: bonding: update the slave array for broadcast mode
- bonding: do not set usable_slaves for broadcast mode
* kernel null pointer BUG in 5.15 when disconnecting from cifs share
(LP: #2150730)
- SAUCE: cifs: fix null pointer dereference in find_ipc_from_server_path
* SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
(LP: #2149767)
- SUNRPC: Check if the xprt is connected before handling sysfs reads
- SUNRPC: Do not dereference non-socket transports in sysfs
* SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
(LP: #2149767) // CVE-2022-48816
- SUNRPC: lock against ->sock changing during sysfs read
* iptables connlimit traffic loss (LP: #2149872)
- netfilter: nf_conncount: fix tracking of connections from localhost
* Some powerpc test from ubuntu_kernel_selftests timeout with 45 seconds
(LP: #2141536)
- selftests/powerpc: Lower run time of count_stcx_fail test
- selftests/powerpc: Give all tests 2 minutes timeout
* Jammy update: v5.15.200 upstream stable release (LP: #2147598)
- x86/kfence: fix booting on 32bit non-PAE systems
- platform/x86: intel_telemetry: Fix swapped arrays in PSS output
- rbd: check for EOD after exclusive lock is ensured to be held
- ARM: 9468/1: fix memset64() on big-endian
- mm/kfence: randomize the freelist on initialization
- Documentation: Remove bogus claim about del_timer_sync()
- timers: Get rid of del_singleshot_timer_sync()
- Documentation: Replace del_timer/del_timer_sync()
- timers: Update the documentation to reflect on the new timer_shutdown()
API
- Bluetooth: hci_qca: Fix the teardown problem for real
- binderfs: fix ida_alloc_max() upper bound
- net: usb: sr9700: support devices with virtual driver CD
- block,bfq: fix aux stat accumulation destination
- HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL
- HID: intel-ish-hid: Reset enum_devices_done before enumeration
- HID: playstation: Center initial joystick axes to prevent spurious
events
- ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk
- netfilter: replace -EEXIST with -EBUSY
- HID: quirks: Add another Chicony HP 5MP Cameras to hid_ignore_list
- HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30 (2d99:a101)
- ring-buffer: Avoid softlockup in ring_buffer_resize() during memory free
- wifi: mac80211: collect station statistics earlier when disconnect
- ASoC: davinci-evm: Fix reference leak in davinci_evm_probe
- ASoC: tlv320adcx140: Propagate error codes during probe
- wifi: cfg80211: Fix bitrate calculation overflow for HE rates
- wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt twice
- platform/x86: intel_telemetry: Fix PSS event register mask
- tipc: use kfree_sensitive() for session key material
- hwmon: (occ) Mark occ_init_attribute() as __printf
- nvmet-tcp: add an helper to free the cmd buffers
- nvmet-tcp: fix memory leak when performing a controller reset
- nvmet-tcp: fix regression in data_digest calculation
- nvmet-tcp: don't map pages which can't come from HIGHMEM
- tracing: Fix ftrace event field alignments
- gve: Correct ethtool rx_dropped calculation
- spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed
transfer
- spi: tegra210-quad: Move curr_xfer read inside spinlock
- spi: tegra210-quad: Protect curr_xfer assignment in
tegra_qspi_setup_transfer_one
- spi: tegra210-quad: Protect curr_xfer clearing in
tegra_qspi_non_combined_seq_xfer
- nvmet-tcp: pass iov_len instead of sg->length to bvec_set_page()
- riscv: Replace function-like macro by static inline function
- Linux 5.15.200
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23182
- spi: tegra: Fix a memory leak in tegra_slink_probe()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23202
- spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-71089
- iommu: disable SVA when CONFIG_X86 is set
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2023-53673
- Bluetooth: hci_event: call disconnect callback before deleting conn
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23262
- gve: Fix stats report corruption on queue count change
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-40082
- hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-37822
- riscv: uprobes: Add missing fence.i after building the XOL buffer
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23190
- ASoC: amd: fix memory leak in acp3x pdm dma ops
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23112
- nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23111
- netfilter: nf_tables: fix inverted genmask check in
nft_map_catchall_activate()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23180
- dpaa2-switch: add bounds check for if_id in IRQ handler
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23256
- net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23257
- net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23258
- net: liquidio: Initialize netdev pointer before queue setup
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23206
- dpaa2-switch: prevent ZERO_SIZE_PTR dereference when num_ifs is zero
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23176
- platform/x86: toshiba_haps: Fix memory leaks in add/remove routines
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23216
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23193
- scsi: target: iscsi: Fix use-after-free in
iscsit_dec_session_usage_count()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-71220
- smb/server: call ksmbd_session_rpc_close() on error path in
create_smb2_pipe()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-71222
- wifi: wlcore: ensure skb headroom before skb_push
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-71224
- wifi: mac80211: ocb: skip rx_no_sta when interface is not joined
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-68214
- timers: Fix NULL function pointer race in timer_shutdown_sync()
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2025-38201
- netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX
* Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
CVE-2026-23198
- KVM: Don't clobber irqfd routing type when deassigning irqfd
* CVE-2026-23272
- netfilter: nf_tables: always increment set element count
- netfilter: nf_tables: fix set size with rbtree backend
- netfilter: nf_tables: unconditionally bump set->nelems before insertion
* CVE-2026-31418
- netfilter: ipset: drop logically empty buckets in mtype_del
* CVE-2026-23278
- netfilter: nf_tables: always walk all pending catchall elements
* CVE-2026-46300
- net: skbuff: preserve shared-frag marker during coalescing
- net: skbuff: propagate shared-frag marker through frag-transfer helpers
* net/rds: reset op_nents when zerocopy page pin fails (LP: #2153962)
- net/rds: reset op_nents when zerocopy page pin fails
* CVE-2026-46333
- ptrace: slightly saner 'get_dumpable()' logic
* CVE-2026-43500
- rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
* CVE-2026-43284
- xfrm: esp: avoid in-place decrypt on shared skb frags
- xfrm: esp: ipv4: fix up flags setting
* CVE-2026-31419
- net: bonding: fix use-after-free in bond_xmit_broadcast()
* CVE-2026-31431
- crypto: scatterwalk - Backport memcpy_sglist()
- crypto: algif_aead - use memcpy_sglist() instead of null skcipher
- crypto: algif_aead - Revert to operating out-of-place
- crypto: algif_aead - snapshot IV for async AEAD requests
- crypto: authenc - use memcpy_sglist() instead of null skcipher
- crypto: authencesn - Do not place hiseq at end of dst for out-of-place
decryption
- crypto: authencesn - Fix src offset when decrypting in-place
- crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
- crypto: algif_aead - Fix minimum RX size check for decryption
* CVE-2026-31533
- net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
* CVE-2026-31504
- net: fix fanout UAF in packet_release() via NETDEV_UP race
Date: 2026-05-25 18:30:10.469395+00:00
Changed-By: Edoardo Canepa <edoardo.canepa at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux/5.15.0-184.194
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list