[ubuntu/noble-proposed] linux 6.8.0-93.95 (Accepted)

Andy Whitcroft apw at canonical.com
Wed Jan 7 15:30:45 UTC 2026


linux (6.8.0-93.95) noble; urgency=medium

  * noble/linux: 6.8.0-93.95 -proposed tracker (LP: #2136909)

  * Enabling crypto selftests causes boot stall on 6.8 (LP: #2135716)
    - SAUCE: Revert "crypto: api - Fix boot-up self-test race"

  * Noble update: upstream stable patchset 2025-12-12 (LP: #2135261)
    - SAUCE: selftests: net: altnames.sh fix following upstream updates

  * ubuntu_bpf failed to build on Noble ( error: ‘struct prog_test_def’ has no
    member named ‘should_tmon’) (LP: #2112357)
    - selftests/bpf: Factor out get_xlated_program() helper
    - selftests/bpf: extract utility function for BPF disassembly
    - selftests/bpf: Add traffic monitor functions.
    - selftests/bpf: Add the traffic monitor option to test_progs.

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740)
    - ASoC: amd: yc: Add DMI quirk for HP Laptop 17 cp-2033dx
    - ethernet: intel: fix building with large NR_CPUS
    - ASoC: amd: yc: Add DMI entries to support HP 15-fb1xxx
    - ASoC: Intel: fix SND_SOC_SOF dependencies
    - ASoC: amd: yc: add DMI quirk for ASUS M6501RM
    - audit,module: restore audit logging in load failure case
    - fs_context: fix parameter name in infofc() macro
    - ublk: use vmalloc for ublk_device's __queues
    - hfsplus: make splice write available again
    - hfs: make splice write available again
    - ASoC: soc-dai: tidyup return value of snd_soc_xlate_tdm_slot_mask()
    - ASoC: ops: dynamically allocate struct snd_ctl_elem_value
    - ASoC: mediatek: use reserved memory or enable buffer pre-allocation
    - selftests: Fix errno checking in syscall_user_dispatch test
    - soc: qcom: QMI encoding/decoding for big endian
    - arm64: dts: qcom: sdm845: Expand IMEM region
    - arm64: dts: qcom: sc7180: Expand IMEM region
    - arm64: dts: qcom: msm8976: Make blsp_dma controlled-remotely
    - ARM: dts: vfxxx: Correctly use two tuples for timer address
    - usb: host: xhci-plat: fix incorrect type for of_match variable in
      xhci_plat_probe()
    - usb: misc: apple-mfi-fastcharge: Make power supply names unique
    - vmci: Prevent the dispatching of uninitialized payloads
    - pps: fix poll support
    - Revert "vmci: Prevent the dispatching of uninitialized payloads"
    - usb: early: xhci-dbc: Fix early_ioremap leak
    - arm: dts: ti: omap: Fixup pinheader typo
    - soc/tegra: cbb: Clear ERR_FORCE register with ERR_STATUS
    - ARM: dts: imx6ul-kontron-bl-common: Fix RTS polarity for RS485 interface
    - arm64: dts: imx8mm-beacon: Fix HS400 USDHC clock speed
    - arm64: dts: imx8mn-beacon: Fix HS400 USDHC clock speed
    - cpufreq: intel_pstate: Always use HWP_DESIRED_PERF in passive mode
    - cpufreq: Initialize cpufreq-based frequency-invariance later
    - cpufreq: Init policy->rwsem before it may be possibly used
    - samples: mei: Fix building on musl libc
    - soc: qcom: pmic_glink: fix OF node leak
    - interconnect: qcom: sc8280xp: specify num_links for qnm_a1noc_cfg
    - interconnect: qcom: sc8180x: specify num_nodes
    - staging: nvec: Fix incorrect null termination of battery manufacturer
    - drm/rockchip: cleanup fb when drm_gem_fb_afbc_init failed
    - bpf, sockmap: Fix psock incorrectly pointing to sk
    - selftests/bpf: fix signedness bug in redir_partial()
    - net: ipv6: ip6mr: Fix in/out netdev to pass to the FORWARD chain
    - drm/vmwgfx: Fix Host-Backed userspace on Guest-Backed kernel
    - bpftool: Fix memory leak in dump_xx_nlmsg on realloc failure
    - caif: reduce stack size, again
    - wifi: iwlwifi: Fix memory leak in iwl_mvm_init()
    - tcp: fix tcp_ofo_queue() to avoid including too much DUP SACK range
    - net: dst: annotate data-races around dst->input
    - net: dst: annotate data-races around dst->output
    - kselftest/arm64: Fix check for setting new VLs in sve-ptrace
    - drm/msm/dpu: Fill in min_prefill_lines for SC8180X
    - m68k: Don't unregister boot console needlessly
    - drm/amd/pm/powerplay/hwmgr/smu_helper: fix order of mask and value
    - sched/psi: Optimize psi_group_change() cpu_clock() usage
    - fbcon: Fix outdated registered_fb reference in comment
    - netfilter: nf_tables: Drop dead code from fill_*_info routines
    - netfilter: nf_tables: adjust lockdep assertions handling
    - arch: powerpc: defconfig: Drop obsolete CONFIG_NET_CLS_TCINDEX
    - um: rtc: Avoid shadowing err in uml_rtc_start()
    - net_sched: act_ctinfo: use atomic64_t for three counters
    - xen/gntdev: remove struct gntdev_copy_batch from stack
    - tcp: call tcp_measure_rcv_mss() for ooo packets
    - wifi: rtl8xxxu: Fix RX skb size for aggregation disabled
    - mwl8k: Add missing check after DMA map
    - iommu/amd: Fix geometry.aperture_end for V2 tables
    - wifi: plfxlc: Fix error handling in usb driver probe
    - wifi: mac80211: Do not schedule stopped TXQs
    - wifi: mac80211: Don't call fq_flow_idx() for management frames
    - wifi: mac80211: Check 802.11 encaps offloading in
      ieee80211_tx_h_select_key()
    - Reapply "wifi: mac80211: Update skb's control block key in
      ieee80211_tx_dequeue()"
    - wifi: ath12k: fix endianness handling while accessing wmi service bit
    - wifi: brcmfmac: fix P2P discovery failure in P2P peer due to missing P2P
      IE
    - wifi: mac80211: Write cnt before copying in ieee80211_copy_rnr_beacon()
    - kcsan: test: Initialize dummy variable
    - Bluetooth: hci_event: Mask data status from LE ext adv reports
    - tools/rv: Do not skip idle in trace
    - can: peak_usb: fix USB FD devices potential malfunction
    - can: kvaser_pciefd: Store device channel index
    - can: kvaser_usb: Assign netdev.dev_port based on device channel index
    - net/mlx5e: Clear Read-Only port buffer size in PBMC before update
    - selftests: rtnetlink.sh: remove esp4_offload after test
    - vrf: Drop existing dst reference in vrf_ip6_input_dst
    - ipv6: annotate data-races around rt->fib6_nsiblings
    - bpf/preload: Don't select USERMODE_DRIVER
    - PCI: rockchip-host: Fix "Unexpected Completion" log message
    - crypto: sun8i-ce - fix nents passed to dma_unmap_sg()
    - crypto: qat - use unmanaged allocation for dc_data
    - crypto: marvell/cesa - Fix engine load inaccuracy
    - mtd: fix possible integer overflow in erase_xfer()
    - media: v4l2-ctrls: Fix H264 SEPARATE_COLOUR_PLANE check
    - power: supply: max14577: Handle NULL pdata when CONFIG_OF is not set
    - crypto: arm/aes-neonbs - work around gcc-15 warning
    - PCI: endpoint: pci-epf-vntb: Return -ENOENT if
      pci_epc_get_next_free_bar() fails
    - pinctrl: sunxi: Fix memory leak on krealloc failure
    - fanotify: sanitize handle_type values when reporting fid
    - clk: clk-axi-clkgen: fix fpfd_max frequency for zynq
    - Fix dma_unmap_sg() nents value
    - perf tools: Fix use-after-free in help_unknown_cmd()
    - perf sched: Free thread->priv using priv_destructor
    - perf sched: Fix memory leaks for evsel->priv in timehist
    - perf sched: Fix memory leaks in 'perf sched latency'
    - crypto: inside-secure - Fix `dma_unmap_sg()` nents value
    - RDMA/hns: Fix -Wframe-larger-than issue
    - kernel: trace: preemptirq_delay_test: use offstack cpu mask
    - perf tests bp_account: Fix leaked file descriptor
    - clk: sunxi-ng: v3s: Fix de clock definition
    - scsi: ibmvscsi_tgt: Fix dma_unmap_sg() nents value
    - scsi: elx: efct: Fix dma_unmap_sg() nents value
    - scsi: mvsas: Fix dma_unmap_sg() nents value
    - scsi: isci: Fix dma_unmap_sg() nents value
    - watchdog: ziirave_wdt: check record length in ziirave_firm_verify()
    - hwrng: mtk - handle devm_pm_runtime_enable errors
    - crypto: keembay - Fix dma_unmap_sg() nents value
    - crypto: img-hash - Fix dma_unmap_sg() nents value
    - soundwire: stream: restore params when prepare ports fail
    - PCI: endpoint: pci-epf-vntb: Fix the incorrect usage of __iomem
      attribute
    - fs/orangefs: Allow 2 more characters in do_c_string()
    - dmaengine: mv_xor: Fix missing check after DMA map and missing unmap
    - dmaengine: nbpfaxi: Add missing check after DMA map
    - ASoC: fsl_xcvr: get channel status data when PHY is not exists
    - sh: Do not use hyphen in exported variable name
    - perf tools: Remove libtraceevent in .gitignore
    - crypto: qat - fix DMA direction for compression on GEN2 devices
    - crypto: qat - fix seq_file position update in adf_ring_next()
    - jfs: fix metapage reference count leak in dbAllocCtl
    - mtd: rawnand: atmel: Fix dma_mapping_error() address
    - mtd: rawnand: rockchip: Add missing check after DMA map
    - mtd: rawnand: atmel: set pmecc data setup time
    - vhost-scsi: Fix log flooding with target does not exist errors
    - bpf: Check flow_dissector ctx accesses are aligned
    - bpf: Check netfilter ctx accesses are aligned
    - apparmor: ensure WB_HISTORY_SIZE value is a power of 2
    - apparmor: fix loop detection used in conflicting attachment resolution
    - module: Restore the moduleparam prefix length check
    - ucount: fix atomic_long_inc_below() argument type
    - rtc: ds1307: fix incorrect maximum clock rate handling
    - rtc: hym8563: fix incorrect maximum clock rate handling
    - rtc: nct3018y: fix incorrect maximum clock rate handling
    - rtc: pcf85063: fix incorrect maximum clock rate handling
    - rtc: pcf8563: fix incorrect maximum clock rate handling
    - rtc: rv3028: fix incorrect maximum clock rate handling
    - f2fs: doc: fix wrong quota mount option description
    - f2fs: fix to update upper_p in __get_secs_required() correctly
    - f2fs: fix to calculate dirty data during has_not_enough_free_secs()
    - vfio: Fix unbalanced vfio_df_close call in no-iommu mode
    - vfio: Prevent open_count decrement to negative
    - vfio/pci: Separate SR-IOV VF dev_set
    - scsi: mpt3sas: Fix a fw_event memory leak
    - scsi: Revert "scsi: iscsi: Fix HW conn removal use after free"
    - scsi: ufs: core: Use link recovery when h8 exit fails during runtime
      resume
    - scsi: sd: Make sd shutdown issue START STOP UNIT appropriately
    - kconfig: qconf: fix ConfigList::updateListAllforAll()
    - sched/psi: Fix psi_seq initialization
    - PCI: pnv_php: Work around switches with broken presence detection
    - powerpc/eeh: Export eeh_unfreeze_pe()
    - pNFS/flexfiles: don't attempt pnfs on fatal DS errors
    - sched: Add test_and_clear_wake_up_bit() and atomic_dec_and_wake_up()
    - NFS: Fix wakeup of __nfs_lookup_revalidate() in unblock_revalidate()
    - NFSv4.2: another fix for listxattr
    - NFS: Fixup allocation flags for nfsiod's __GFP_NORETRY
    - md/md-cluster: handle REMOVE message earlier
    - netpoll: prevent hanging NAPI when netcons gets enabled
    - phy: mscc: Fix parsing of unicast frames
    - net: ipa: add IPA v5.1 and v5.5 to ipa_version_string()
    - netlink: specs: ethtool: fix module EEPROM input/output arguments
    - net/mlx5: Correctly set gso_segs when LRO is used
    - net/sched: taprio: enforce minimum value for picos_per_byte
    - benet: fix BUG when creating VFs
    - irqchip: Build IMX_MU_MSI only on ARM
    - ALSA: hda/ca0132: Fix missing error handling in ca0132_alt_select_out()
    - smb: server: remove separate empty_recvmsg_queue
    - smb: server: make sure we call ib_dma_unmap_single() only if we called
      ib_dma_map_single already
    - smb: server: let recv_done() consistently call
      put_recvmsg/smb_direct_disconnect_rdma_connection
    - smb: server: let recv_done() avoid touching data_transfer after
      cleanup/move
    - smb: client: Use min() macro
    - smb: client: Correct typos in multiple comments across various files
    - smb: smbdirect: add smbdirect_socket.h
    - smb: client: make use of common smbdirect_socket
    - smb: client: make sure we call ib_dma_unmap_single() only if we called
      ib_dma_map_single already
    - smb: client: let recv_done() cleanup before notifying the callers.
    - pptp: fix pptp_xmit() error path
    - smb: client: return an error if rdma_connect does not return within 5
      seconds
    - selftests/perf_events: Add a mmap() correctness test
    - ksmbd: fix corrupted mtime and ctime in smb2_open
    - smb: server: Fix extension string in ksmbd_extract_shortname()
    - USB: serial: option: add Foxconn T99W709
    - Bluetooth: btusb: Add USB ID 3625:010b for TP-LINK Archer TX10UB Nano
    - net: usbnet: Avoid potential RCU stall on LINK_CHANGE event
    - net: usbnet: Fix the wrong netif_carrier_on() call
    - ALSA: intel_hdmi: Fix off-by-one error in __hdmi_lpe_audio_probe()
    - ALSA: scarlett2: Add retry on -EPROTO from scarlett2_usb_tx()
    - x86/fpu: Delay instruction pointer fixup until after warning
    - MIPS: mm: tlb-r4k: Uniquify TLB entries on init
    - mm/hmm: move pmd_to_hmm_pfn_flags() to the respective #ifdeffery
    - ALSA: hda/cs35l56: Workaround bad dev-index on Lenovo Yoga Book 9i GenX
    - arm64: dts: exynos: gs101: Add 'local-timer-stop' to cpuidle nodes
    - arm64: dts: ti: k3-am62p-j722s: fix pinctrl-single size
    - mei: vsc: Destroy mutex after freeing the IRQ
    - mei: vsc: Event notifier fixes
    - mei: vsc: Unset the event callback on remove and probe errors
    - arm64: dts: st: fix timer used for ticks
    - selftests: breakpoints: use suspend_stats to reliably check suspend
      success
    - PM / devfreq: Fix a index typo in trans_stat
    - drm/panfrost: Fix panfrost device variable name in devfreq
    - selftests/bpf: Fix unintentional switch case fall through
    - drm/amdgpu: Remove nbiov7.9 replay count reporting
    - bpf: Ensure RCU lock is held around bpf_prog_ksym_find
    - refscale: Check that nreaders and loops multiplication doesn't overflow
    - iommu/amd: Enable PASID and ATS capabilities in the correct order
    - file: add take_fd() cleanup helper
    - file: fix typo in take_fd() comment
    - rcu: Fix delayed execution of hurry callbacks
    - ring-buffer: Remove ring_buffer_read_prepare_sync()
    - net: dsa: microchip: Fix wrong rx drop MIB counter for KSZ8863
    - stmmac: xsk: fix negative overflow of budget in zerocopy mode
    - pinctrl: berlin: fix memory leak in berlin_pinctrl_build_state()
    - dmaengine: mmp: Fix again Wvoid-pointer-to-enum-cast warning
    - phy: qualcomm: phy-qcom-eusb2-repeater: Don't zero-out registers
    - perf dso: Add missed dso__put to dso__load_kcore
    - mtd: spi-nor: spansion: Fixup params->set_4byte_addr_mode for SEMPER
    - perf sched: Make sure it frees the usage string
    - perf sched: Fix memory leaks in 'perf sched map'
    - perf sched: Use RC_CHK_EQUAL() to compare pointers
    - RDMA/hns: Fix HW configurations not cleared in error flow
    - RDMA/hns: Get message length of ack_req from FW
    - RDMA/hns: Add mutex_destroy()
    - RDMA/hns: Fix accessing uninitialized resources
    - RDMA/hns: Drop GFP_NOWARN
    - crypto: qat - disable ZUC-256 capability for QAT GEN5
    - remoteproc: xlnx: Disable unsupported features
    - perf record: Cache build-ID of hit DSOs only
    - vdpa: Fix IDR memory leak in VDUSE module exit
    - vhost: Reintroduce kthread API and add mode selection
    - [Config] enable VHOST_ENABLE_FORK_OWNER_CONTROL
    - apparmor: Fix unaligned memory accesses in KUnit test
    - f2fs: turn off one_time when forcibly set to foreground GC
    - exfat: fdatasync flag should be same like generic_write_sync()
    - s390/ap: Unmask SLCF bit in card and queue ap functions sysfs
    - block: Fix default IO priority if there is no IO context
    - ASoC: tas2781: Fix the wrong step for TLV on tas2781
    - s390/mm: Allocate page table with PAGE_SIZE granularity
    - smb: client: remove separate empty_packet_queue
    - smb: client: let recv_done() avoid touching data_transfer after
      cleanup/move
    - drm/i915/ddi: change intel_ddi_init_{dp, hdmi}_connector() return type
    - drm/i915/hdmi: propagate errors from intel_hdmi_init_connector()
    - drm/i915/hdmi: add error handling in g4x_hdmi_init()
    - drm/i915/ddi: gracefully handle errors from
      intel_ddi_init_hdmi_connector()
    - drm/i915/display: add intel_encoder_is_hdmi()
    - drm/i915/ddi: only call shutdown hooks for valid encoders
    - PCI/ASPM: Save parent L1SS config in pci_save_aspm_l1ss_state()
    - PCI/ASPM: Fix L1SS saving
    - ALSA: hda/realtek - Fix mute LED for HP Victus 16-r1xxx
    - ALSA: hda/realtek - Fix mute LED for HP Victus 16-s0xxx
    - ALSA: hda/realtek - Fix mute LED for HP Victus 16-d1xxx (MB 8A26)
    - s390/mm: Remove possible false-positive warning in pte_free_defer()
    - Upstream stable to v6.6.102, v6.12.42

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38619
    - media: ti: j721e-csi2rx: fix list_del corruption

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38582
    - RDMA/hns: Fix double destruction of rsv_qp

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38585
    - staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38593
    - Bluetooth: hci_sync: fix double free in 'hci_discovery_filter_clear()'

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-39732
    - wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38595
    - xen: fix UAF in dmabuf_exp_from_pages()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38660
    - parse_longname(): strrchr() expects NUL-terminated string

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38555
    - usb: gadget : fix use-after-free in composite_dev_cleanup()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2024-36331 // CVE-2025-38560
    - x86/sev: Evict cache lines during SNP memory validation

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38501
    - ksmbd: limit repeated connections from clients with the same IP

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38562
    - ksmbd: fix null pointer dereference error in generate_encryptionkey

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38566
    - sunrpc: fix handling of server side tls alerts

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38568
    - net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38571
    - sunrpc: fix client side handling of tls alerts

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38622
    - net: drop UFO packets in udp_rcv_segment()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38572
    - ipv6: reject malicious packets in ipv6_gso_segment()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38574
    - pptp: ensure minimal skb length in pptp_xmit()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-39730
    - NFS: Fix filehandle bounds checking in nfs_fh_to_dentry()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38623
    - PCI: pnv_php: Fix surprise plug detection and recovery

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38576
    - powerpc/eeh: Make EEH driver device hotplug safe

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38624
    - PCI: pnv_php: Clean up allocated IRQs on unplug

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38625
    - vfio/pds: Fix missing detach_ioas op

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38626
    - f2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-39731
    - f2fs: vm_unmap_ram() may be called from an invalid context

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38652
    - f2fs: fix to avoid out-of-boundary access in devs.path

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38577
    - f2fs: fix to avoid panic in f2fs_evict_inode

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38578
    - f2fs: fix to avoid UAF in f2fs_sync_inode_meta()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38579
    - f2fs: fix KMSAN uninit-value in extent_info usage

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38630
    - fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38632
    - pinmux: fix race causing mux_owner NULL with active mux_usecount

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38653
    - proc: use the same treatment to check proc_lseek as ones for
      proc_read_iter et.al

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38581
    - crypto: ccp - Fix crash when rebind ccp device for ccp.ko

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38634
    - power: supply: cpcap-charger: Fix null check for
      power_supply_get_by_name

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38583
    - clk: xilinx: vcu: unregister pll_post only if registered correctly

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38635
    - clk: davinci: Add NULL check in davinci_lpsc_clk_register()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38587
    - ipv6: fix possible infinite loop in fib6_info_uses_dev()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38588
    - ipv6: prevent infinite loop in rt6_nlmsg_size()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38590
    - net/mlx5e: Remove skb secpath if xfrm state is not found

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38639
    - netfilter: xt_nfacct: don't assume acct name is null-terminated

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38640
    - bpf: Disable migration in nf_hook_run_bpf().

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38644
    - wifi: mac80211: reject TDLS operations when station is not associated

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38553
    - net/sched: Restrict conditions for adding duplicating netems to qdisc
      tree

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38645
    - net/mlx5: Check device memory pointer before usage

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38601
    - wifi: ath11k: clear initialized flag for deinit-ed srng lists

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38602
    - iwlwifi: Add missing check for alloc_ordered_workqueue

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38604
    - wifi: rtl818x: Kill URBs before clearing tx status queue

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38646
    - wifi: rtw89: avoid NULL dereference when RX problematic packet on
      unsupported 6 GHz band

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38608
    - bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38609
    - PM / devfreq: Check governor before using governor->name

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38610
    - powercap: dtpm_cpu: Fix NULL pointer dereference in get_pd_power_uw()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38612
    - staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc()

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38648
    - spi: stm32: Check for cfg availability in stm32_spi_probe

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38659
    - gfs2: No more self recovery

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-39734
    - Revert "fs/ntfs3: Replace inode_trylock with inode_lock"

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38650
    - hfsplus: remove mutex_lock check in hfsplus_free_extents

  * Noble update: upstream stable patchset 2025-12-17 (LP: #2136740) //
    CVE-2025-38615
    - fs/ntfs3: cancle set bad inode after removing name fails

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361)
    - virtio_ring: Fix error reporting in virtqueue_resize
    - RDMA/core: Rate limit GID cache warning messages
    - interconnect: qcom: sc7280: Add missing num_links to xm_pcie3_1 node
    - iio: adc: ad7949: use spi_is_bpw_supported()
    - regmap: fix potential memory leak of regmap_bus
    - x86/hyperv: Fix usage of cpu_online_mask to get valid cpu
    - platform/x86: Fix initialization order for firmware_attributes_class
    - staging: vchiq_arm: Make vchiq_shutdown never fail
    - net/mlx5: Fix memory leak in cmd_exec()
    - net/mlx5: E-Switch, Fix peer miss rules to use peer eswitch
    - i40e: report VF tx_dropped with tx_errors instead of tx_discards
    - i40e: When removing VF MAC filters, only check PF-set MAC
    - drm/bridge: ti-sn65dsi86: Remove extra semicolon in ti_sn_bridge_probe()
    - net: hns3: fix concurrent setting vlan filter issue
    - net: hns3: disable interrupt when ptp init failed
    - net: hns3: fixed vf get max channels bug
    - net: hns3: default enable tx bounce buffer when smmu enabled
    - platform/x86: ideapad-laptop: Fix kbd backlight not remembered among
      boots
    - i2c: tegra: Fix reset error handling with ACPI
    - i2c: virtio: Avoid hang by using interruptible completion wait
    - bus: fsl-mc: Fix potential double device reference in
      fsl_mc_get_endpoint()
    - sprintf.h requires stdarg.h
    - ALSA: hda/realtek - Add mute LED support for HP Pavilion 15-eg0xxx
    - dpaa2-eth: Fix device reference count leak in MAC endpoint handling
    - dpaa2-switch: Fix device reference count leak in MAC endpoint handling
    - e1000e: disregard NVM checksum on tgp when valid checksum bit is not set
    - e1000e: ignore uninitialized checksum word on tgp
    - gve: Fix stuck TX queue for DQ queue format
    - kasan: use vmalloc_dump_obj() for vmalloc error reports
    - resource: fix false warning in __request_region()
    - selftests: mptcp: connect: also cover alt modes
    - selftests: mptcp: connect: also cover checksum
    - mm/zsmalloc: do not pass __GFP_MOVABLE if CONFIG_COMPACTION=n
    - usb: typec: tcpm: allow to use sink in accessory mode
    - usb: typec: tcpm: allow switching to mode accessory to mux properly
    - usb: typec: tcpm: apply vbus before data bringup in tcpm_src_attach
    - comedi: comedi_test: Fix possible deletion of uninitialized timers
    - ALSA: hda/tegra: Add Tegra264 support
    - ALSA: hda: Add missing NVIDIA HDA codec IDs
    - drm/i915/dp: Fix 2.7 Gbps DP_LINK_BW value on g4x
    - mm: khugepaged: fix call hpage_collapse_scan_file() for anonymous vma
    - crypto: powerpc/poly1305 - add depends on BROKEN for now
    - [Config] disable CRYPTO_POLY1305_P10
    - iio: hid-sensor-prox: Fix incorrect OFFSET calculation
    - iio: hid-sensor-prox: Restore lost scale assignments
    - mtd: rawnand: qcom: Fix last codeword read in
      qcom_param_page_type_exec()
    - ksmbd: add free_transport ops in ksmbd connection
    - arm64/cpufeatures/kvm: Add ARMv8.9 FEAT_ECBHB bits in ID_AA64MMFR1
      register
    - ARM: 9448/1: Use an absolute path to unified.h in KBUILD_AFLAGS
    - Revert "selftests/bpf: Add a cgroup prog bpf_get_ns_current_pid_tgid()
      test"
    - x86/traps: Initialize DR7 by writing its architectural reset value
    - virtio_net: Enforce minimum TX ring size for reliability
    - platform/x86: asus-nb-wmi: add DMI quirk for ASUS Zenbook Duo UX8406CA
    - platform/mellanox: mlxbf-pmc: Remove newline char from event name input
    - platform/mellanox: mlxbf-pmc: Validate event/enable input
    - platform/mellanox: mlxbf-pmc: Use kstrtobool() to check 0/1 input
    - xfrm: state: use a consistent pcpu_id in xfrm_state_find
    - xfrm: Set transport header to fix UDP GRO handling
    - ALSA: hda/realtek: Fix mute LED mask on HP OMEN 16 laptop
    - drm/sched: Remove optimization that causes hang when killing dependent
      jobs
    - mm/ksm: fix -Wsometimes-uninitialized from clang-21 in
      advisor_mode_show()
    - ALSA: hda/realtek - Add mute LED support for HP Victus 15-fa0xxx
    - rust: give Clippy the minimum supported Rust version
    - selftests/bpf: Add tests with stack ptr register in conditional jmp
    - spi: cadence-quadspi: fix cleanup of rx_chan on failure paths
    - ext4: don't explicit update times in ext4_fallocate()
    - ext4: refactor ext4_punch_hole()
    - ext4: refactor ext4_zero_range()
    - ext4: refactor ext4_collapse_range()
    - ext4: refactor ext4_insert_range()
    - ext4: factor out ext4_do_fallocate()
    - ext4: move out inode_lock into ext4_fallocate()
    - fs: sort out the fallocate mode vs flag mess
    - ext4: move out common parts into ext4_fallocate()
    - ext4: fix incorrect punch max_end
    - ext4: correct the error handle in ext4_fallocate()
    - ext4: fix out of bounds punch offset
    - KVM: x86: drop x86.h include from cpuid.h
    - KVM: x86: Route non-canonical checks in emulator through emulate_ops
    - KVM: x86: Add X86EMUL_F_MSR and X86EMUL_F_DT_LOAD to aid canonical
      checks
    - KVM: x86: model canonical checks more precisely
    - x86/hyperv: Fix APIC ID and VP index confusion in hv_snp_boot_ap()
    - arm64: dts: qcom: x1-crd: Fix vreg_l2j_1p2 voltage
    - Drivers: hv: Make the sysfs node size for the ring buffer dynamic
    - Upstream stable to v6.6.101, v6.12.41

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-38351
    - KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-38675
    - xfrm: state: initialize state_ptrs earlier in xfrm_state_find

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-38322
    - perf/x86/intel: Fix crash in icl_update_topdown_event()

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-37777
    - ksmbd: fix use-after-free in __smb2_lease_break_noti()

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-37925
    - jfs: reject on-disk inodes of an unsupported type

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-38663
    - nilfs2: reject invalid file types when reading inodes

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-38664
    - ice: Fix a null pointer dereference in ice_copy_and_init_pkg()

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-38670
    - arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack()

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-38671
    - i2c: qup: jump out of the loop in case of timeout

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-39726
    - s390/ism: fix concurrency management in ism_cmd()

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-38665
    - can: netlink: can_changelink(): fix NULL pointer deref of struct
      can_priv::do_set_mode

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-38668
    - regulator: core: fix NULL dereference on unbind due to stale coupling
      data

  * Noble update: upstream stable patchset 2025-12-16 (LP: #2136361) //
    CVE-2025-38335
    - Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221)
    - phy: tegra: xusb: Decouple CYA_TRK_CODE_UPDATE_ON_IDLE from trk_hw_mode
    - phy: tegra: xusb: Disable periodic tracking on Tegra234
    - USB: serial: option: add Telit Cinterion FE910C04 (ECM) composition
    - USB: serial: option: add Foxconn T99W640
    - USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI
    - usb: musb: fix gadget state on disconnect
    - i2c: stm32: fix the device used for the DMA map
    - thunderbolt: Fix wake on connect at runtime
    - thunderbolt: Fix bit masking in tb_dp_port_set_hops()
    - nvmem: imx-ocotp: fix MAC address byte length
    - Input: xpad - set correct controller type for Acer NGR200
    - pch_uart: Fix dma_sync_sg_for_device() nents value
    - spi: Add check for 8-bit transfer with 8 IO mode support
    - HID: core: ensure __hid_request reserves the report ID as the first byte
    - tracing/probes: Avoid using params uninitialized in parse_btf_arg()
    - drm/amdgpu/gfx8: reset compute ring wptr on the GPU on resume
    - ALSA: hda/realtek: Add quirk for ASUS ROG Strix G712LWS
    - io_uring/poll: fix POLLERR handling
    - phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in
      pep_sock_accept()
    - net/mlx5: Update the list of the PCI supported devices
    - arm64: dts: imx8mp-venice-gw74xx: fix TPM SPI frequency
    - arm64: dts: freescale: imx8mm-verdin: Keep LDO5 always on
    - arm64: dts: rockchip: use cs-gpios for spi1 on ringneck
    - af_packet: fix the SO_SNDTIMEO constraint not effective on tpacked_snd()
    - af_packet: fix soft lockup issue caused by tpacket_snd()
    - isofs: Verify inode mode when loading from disk
    - memstick: core: Zero initialize id_reg in h_memstick_read_dev_id()
    - mmc: bcm2835: Fix dma_unmap_sg() nents value
    - mmc: sdhci-pci: Quirk for broken command queuing on Intel GLK-based
      Positivo models
    - mmc: sdhci_am654: Workaround for Errata i2312
    - pmdomain: governor: Consider CPU latency tolerance from
      pm_domain_cpu_gov
    - soc: aspeed: lpc-snoop: Cleanup resources in stack-order
    - iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[]
    - iio: adc: max1363: Reorder mode_list[] entries
    - iio: adc: stm32-adc: Fix race in installing chained IRQ handler
    - comedi: Fix some signed shift left operations
    - soundwire: amd: fix for handling slave alerts after link is down
    - soundwire: amd: fix for clearing command status register
    - cachefiles: Fix the incorrect return value in __cachefiles_write()
    - net: emaclite: Fix missing pointer increment in aligned_read()
    - block: fix kobject leak in blk_unregister_queue
    - nvme: fix inconsistent RCU list manipulation in
      nvme_ns_add_to_ctrl_list()
    - nvme: fix misaccounting of nvme-mpath inflight I/O
    - wifi: cfg80211: remove scan request n_channels counted_by
    - selftests: net: increase inter-packet timeout in udpgro.sh
    - Bluetooth: hci_sync: fix connectable extended advertising when using
      static random address
    - Bluetooth: SMP: If an unallowed command is received consider it a
      failure
    - Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout
    - Bluetooth: btusb: QCA: Fix downloading wrong NVM for WCN6855 GF variant
      without board ID
    - net/mlx5: Correctly set gso_size when LRO is used
    - Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU
    - hv_netvsc: Set VF priv_flags to IFF_NO_ADDRCONF before open to prevent
      IPv6 addrconf
    - net: bridge: Do not offload IGMP/MLD messages
    - rxrpc: Fix transmission of an abort in response to an abort
    - Revert "cgroup_freezer: cgroup_freezing: Check if not frozen"
    - sched: Change nr_uninterruptible type to unsigned long
    - ipv6: make addrconf_wq single threaded
    - usb: hub: fix detection of high tier USB3 devices behind suspended hubs
    - usb: hub: Fix flushing and scheduling of delayed work that tunes runtime
      pm
    - usb: hub: Fix flushing of delayed work used for post resume purposes
    - usb: hub: Don't try to recover devices lost during warm reset.
    - usb: dwc3: qcom: Don't leave BCR asserted
    - i2c: omap: Add support for setting mux
    - [Config] make mux support built-in on arm
    - i2c: omap: Fix an error handling path in omap_i2c_probe()
    - i2c: omap: Handle omap_i2c_init() errors in omap_i2c_probe()
    - Revert "selftests/bpf: adjust dummy_st_ops_success to detect additional
      error"
    - Revert "selftests/bpf: dummy_st_ops should reject 0 for non-nullable
      params"
    - i2c: omap: fix deprecated of_property_read_bool() use
    - nvmem: layouts: u-boot-env: remove crc32 endianness conversion
    - i2c: stm32f7: unmap DMA mapped buffer
    - drm/amdgpu: Increase reset counter only on success
    - ALSA: hda/realtek - Fix mute LED for HP Victus 16-r0xxx
    - mptcp: reset fallback status gracefully at disconnect() time
    - arm64: dts: imx8mp-venice-gw72xx: fix TPM SPI frequency
    - arm64: dts: imx8mp-venice-gw73xx: fix TPM SPI frequency
    - arm64: dts: rockchip: Add cd-gpios for sdcard detect on Cool Pi CM5
    - arm64: dts: rockchip: Add cd-gpios for sdcard detect on Cool Pi 4B
    - nvme: fix endianness of command word prints in nvme_log_err_passthru()
    - nvmet-tcp: fix callback lock for TLS handshake
    - can: tcan4x5x: add option for selecting nWKRQ voltage
    - can: tcan4x5x: fix reset gpio usage during probe
    - ice: check correct pointer in fwlog debugfs
    - riscv: Enable interrupt during exception handling
    - riscv: traps_misaligned: properly sign extend value in misaligned load
      handler
    - Bluetooth: hci_core: add missing braces when using macro parameters
    - drm/mediatek: Add wait_event_timeout when disabling plane
    - drm/mediatek: only announce AFBC if really supported
    - net: libwx: fix multicast packets received count
    - sched,freezer: Remove unnecessary warning in __thaw_task
    - drm/xe/mocs: Initialize MOCS index early
    - drm/xe: Move page fault init after topology init
    - smb: client: let smbd_post_send_iter() respect the peers max_send_size
      and transmit all data
    - Upstream stable to v6.6.100, v6.12.40

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-22115
    - btrfs: fix block group refcount race in
      btrfs_create_pending_block_groups()

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38549
    - efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38551
    - virtio-net: fix recursived rtnl_lock() during probe()

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38531
    - iio: common: st_sensors: Fix use of uninitialize device structs

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38552
    - mptcp: plug races between subflow fail and subflow creation

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38491
    - mptcp: make fallback action and fallback decision atomic

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38469
    - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll
      hypercalls

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38499
    - clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the
      right userns

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38524
    - rxrpc: Fix recv-recv race of completed call

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38468
    - net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38470
    - net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during
      runtime

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38471
    - tls: always refresh the queue when reading sock

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38472
    - netfilter: nf_conntrack: fix crash due to removal of uninitialised entry

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38550
    - ipv6: mcast: Delay put pmc->idev in mld_del_delrec()

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38473
    - Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb()

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38474
    - usb: net: sierra: check for no status endpoint

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38526
    - ice: add NULL check in eswitch lag check

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38548
    - hwmon: (corsair-cpro) Validate the size of the received input buffer

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38537
    - net: phy: Don't register LEDs for genphy

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38527
    - smb: client: fix use-after-free in cifs_oplock_break

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38476
    - rpl: Fix use-after-free in rpl_do_srh_inline().

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38528
    - bpf: Reject %p% format string in bprintf-like helpers

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38478
    - comedi: Fix initialization of data for instructions that write to
      subdevice

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38480
    - comedi: Fix use of uninitialized data in insn_rw_emulate_bits()

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38481
    - comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38482
    - comedi: das6402: Fix bit shift out of bounds

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38483
    - comedi: das16m1: Fix bit shift out of bounds

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38529
    - comedi: aio_iiro_16: Fix bit shift out of bounds

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38530
    - comedi: pcl812: Fix bit shift out of bounds

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38485
    - iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38487
    - soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2024-50047 fix. // CVE-2025-38488
    - smb: client: fix use-after-free in crypt_message when using async crypto

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38489
    - s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38532
    - net: libwx: properly reset Rx ring descriptor

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38533
    - net: libwx: fix the using of Rx buffer DMA

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38490
    - net: libwx: remove duplicate page_pool_put_full_page()

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38538
    - dmaengine: nbpfaxi: Fix memory corruption in probe()

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38493
    - tracing/osnoise: Fix crash in timerlat_dump_stack()

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38539
    - tracing: Add down_write(trace_event_sem) when adding trace event

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38494
    - HID: core: do not bypass hid_hw_raw_request

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38495
    - HID: core: ensure the allocated report buffer can contain the reserved
      report ID

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38496
    - dm-bufio: fix sched in atomic context

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38497
    - usb: gadget: configfs: Fix OOB read on empty string write

  * Noble update: upstream stable patchset 2025-12-15 (LP: #2136221) //
    CVE-2025-38535
    - phy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode

  * Miscellaneous Ubuntu changes
    - [SAUCE] Fix selftest/net/rtnetlink.sh for Big Endian

  * Miscellaneous upstream changes
    - selftests: rtnetlink: skip tests if tools or feats are missing
    - selftests: rtnetlink: correct error message in rtnetlink.sh fou test
    - netdevsim: fix rtnetlink.sh selftest
    - selftests: net: use slowwait to stabilize vrf_route_leaking test

Date: 2025-12-20 06:06:12.878438+00:00
Changed-By: Mehmet Basaran <mehmet.basaran at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux/6.8.0-93.95
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list