[ubuntu/jammy-proposed] linux 5.15.0-184.194 (Accepted)

Timo Aaltonen tjaalton at ubuntu.com
Wed May 27 11:56:33 UTC 2026


linux (5.15.0-184.194) jammy; urgency=medium

  * jammy/linux: 5.15.0-184.194 -proposed tracker (LP: #2154219)

  * Kernel regression (6.8.0-117.generic) (LP: #2153556)
    - net: bonding: update the slave array for broadcast mode
    - bonding: do not set usable_slaves for broadcast mode

  * kernel null pointer BUG in 5.15 when disconnecting from cifs share
    (LP: #2150730)
    - SAUCE: cifs: fix null pointer dereference in find_ipc_from_server_path

  * SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
    (LP: #2149767)
    - SUNRPC: Check if the xprt is connected before handling sysfs reads
    - SUNRPC: Do not dereference non-socket transports in sysfs

  * SUNRPC: System wide grep leads to NULL pointer deference in sysfs reads
    (LP: #2149767) // CVE-2022-48816
    - SUNRPC: lock against ->sock changing during sysfs read

  * iptables connlimit traffic loss (LP: #2149872)
    - netfilter: nf_conncount: fix tracking of connections from localhost

  * Some powerpc test from ubuntu_kernel_selftests timeout with 45 seconds
    (LP: #2141536)
    - selftests/powerpc: Lower run time of count_stcx_fail test
    - selftests/powerpc: Give all tests 2 minutes timeout

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598)
    - x86/kfence: fix booting on 32bit non-PAE systems
    - platform/x86: intel_telemetry: Fix swapped arrays in PSS output
    - rbd: check for EOD after exclusive lock is ensured to be held
    - ARM: 9468/1: fix memset64() on big-endian
    - mm/kfence: randomize the freelist on initialization
    - Documentation: Remove bogus claim about del_timer_sync()
    - timers: Get rid of del_singleshot_timer_sync()
    - Documentation: Replace del_timer/del_timer_sync()
    - timers: Update the documentation to reflect on the new timer_shutdown()
      API
    - Bluetooth: hci_qca: Fix the teardown problem for real
    - binderfs: fix ida_alloc_max() upper bound
    - net: usb: sr9700: support devices with virtual driver CD
    - block,bfq: fix aux stat accumulation destination
    - HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL
    - HID: intel-ish-hid: Reset enum_devices_done before enumeration
    - HID: playstation: Center initial joystick axes to prevent spurious
      events
    - ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk
    - netfilter: replace -EEXIST with -EBUSY
    - HID: quirks: Add another Chicony HP 5MP Cameras to hid_ignore_list
    - HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30 (2d99:a101)
    - ring-buffer: Avoid softlockup in ring_buffer_resize() during memory free
    - wifi: mac80211: collect station statistics earlier when disconnect
    - ASoC: davinci-evm: Fix reference leak in davinci_evm_probe
    - ASoC: tlv320adcx140: Propagate error codes during probe
    - wifi: cfg80211: Fix bitrate calculation overflow for HE rates
    - wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt twice
    - platform/x86: intel_telemetry: Fix PSS event register mask
    - tipc: use kfree_sensitive() for session key material
    - hwmon: (occ) Mark occ_init_attribute() as __printf
    - nvmet-tcp: add an helper to free the cmd buffers
    - nvmet-tcp: fix memory leak when performing a controller reset
    - nvmet-tcp: fix regression in data_digest calculation
    - nvmet-tcp: don't map pages which can't come from HIGHMEM
    - tracing: Fix ftrace event field alignments
    - gve: Correct ethtool rx_dropped calculation
    - spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed
      transfer
    - spi: tegra210-quad: Move curr_xfer read inside spinlock
    - spi: tegra210-quad: Protect curr_xfer assignment in
      tegra_qspi_setup_transfer_one
    - spi: tegra210-quad: Protect curr_xfer clearing in
      tegra_qspi_non_combined_seq_xfer
    - nvmet-tcp: pass iov_len instead of sg->length to bvec_set_page()
    - riscv: Replace function-like macro by static inline function
    - Linux 5.15.200

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23182
    - spi: tegra: Fix a memory leak in tegra_slink_probe()

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23202
    - spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-71089
    - iommu: disable SVA when CONFIG_X86 is set

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2023-53673
    - Bluetooth: hci_event: call disconnect callback before deleting conn

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23262
    - gve: Fix stats report corruption on queue count change

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-40082
    - hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-37822
    - riscv: uprobes: Add missing fence.i after building the XOL buffer

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23190
    - ASoC: amd: fix memory leak in acp3x pdm dma ops

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23112
    - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23111
    - netfilter: nf_tables: fix inverted genmask check in
      nft_map_catchall_activate()

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23180
    - dpaa2-switch: add bounds check for if_id in IRQ handler

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23256
    - net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23257
    - net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23258
    - net: liquidio: Initialize netdev pointer before queue setup

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23206
    - dpaa2-switch: prevent ZERO_SIZE_PTR dereference when num_ifs is zero

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23176
    - platform/x86: toshiba_haps: Fix memory leaks in add/remove routines

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23216
    - scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count()

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23193
    - scsi: target: iscsi: Fix use-after-free in
      iscsit_dec_session_usage_count()

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-71220
    - smb/server: call ksmbd_session_rpc_close() on error path in
      create_smb2_pipe()

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-71222
    - wifi: wlcore: ensure skb headroom before skb_push

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-71224
    - wifi: mac80211: ocb: skip rx_no_sta when interface is not joined

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-68214
    - timers: Fix NULL function pointer race in timer_shutdown_sync()

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2025-38201
    - netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX

  * Jammy update: v5.15.200 upstream stable release (LP: #2147598) //
    CVE-2026-23198
    - KVM: Don't clobber irqfd routing type when deassigning irqfd

  * CVE-2026-23272
    - netfilter: nf_tables: always increment set element count
    - netfilter: nf_tables: fix set size with rbtree backend
    - netfilter: nf_tables: unconditionally bump set->nelems before insertion

  * CVE-2026-31418
    - netfilter: ipset: drop logically empty buckets in mtype_del

  * CVE-2026-23278
    - netfilter: nf_tables: always walk all pending catchall elements

  * CVE-2026-46300
    - net: skbuff: preserve shared-frag marker during coalescing
    - net: skbuff: propagate shared-frag marker through frag-transfer helpers

  * net/rds: reset op_nents when zerocopy page pin fails (LP: #2153962)
    - net/rds: reset op_nents when zerocopy page pin fails

  * CVE-2026-46333
    - ptrace: slightly saner 'get_dumpable()' logic

  * CVE-2026-43500
    - rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present

  * CVE-2026-43284
    - xfrm: esp: avoid in-place decrypt on shared skb frags
    - xfrm: esp: ipv4: fix up flags setting

  * CVE-2026-31419
    - net: bonding: fix use-after-free in bond_xmit_broadcast()

  * CVE-2026-31431
    - crypto: scatterwalk - Backport memcpy_sglist()
    - crypto: algif_aead - use memcpy_sglist() instead of null skcipher
    - crypto: algif_aead - Revert to operating out-of-place
    - crypto: algif_aead - snapshot IV for async AEAD requests
    - crypto: authenc - use memcpy_sglist() instead of null skcipher
    - crypto: authencesn - Do not place hiseq at end of dst for out-of-place
      decryption
    - crypto: authencesn - Fix src offset when decrypting in-place
    - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
    - crypto: algif_aead - Fix minimum RX size check for decryption

  * CVE-2026-31533
    - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption

  * CVE-2026-31504
    - net: fix fanout UAF in packet_release() via NETDEV_UP race

Date: 2026-05-25 18:30:10.469395+00:00
Changed-By: Edoardo Canepa <edoardo.canepa at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux/5.15.0-184.194
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list