[ubuntu/questing-proposed] linux 6.17.0-10.10 (Accepted)
Andy Whitcroft
apw at canonical.com
Tue Dec 16 21:25:43 UTC 2025
linux (6.17.0-10.10) questing; urgency=medium
* questing/linux: 6.17.0-10.10 -proposed tracker (LP: #2135908)
* [UBUNTU 24.04] KVM: s390: improve interrupt cpu for wakeup (LP: #2132317)
- KVM: s390: improve interrupt cpu for wakeup
* Questing update: v6.17.6 upstream stable release (LP: #2134982)
- sched/fair: Block delayed tasks on throttled hierarchy during dequeue
- vfio/cdx: update driver to build without CONFIG_GENERIC_MSI_IRQ
- expfs: Fix exportfs_can_encode_fh() for EXPORT_FH_FID
- cgroup/misc: fix misc_res_type kernel-doc warning
- dlm: move to rinfo for all middle conversion cases
- exec: Fix incorrect type for ret
- s390/pkey: Forward keygenflags to ep11_unwrapkey
- hfs: clear offset and space out of valid records in b-tree node
- hfs: make proper initalization of struct hfs_find_data
- hfs: validate record offset in hfsplus_bmap_alloc
- hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat()
- dlm: check for defined force value in dlm_lockspace_release
- hfsplus: return EIO when type of hidden directory mismatch in
hfsplus_fill_super()
- PCI: Test for bit underflow in pcie_set_readrq()
- lkdtm: fortify: Fix potential NULL dereference on kmalloc failure
- arm64: sysreg: Correct sign definitions for EIESB and DoubleLock
- m68k: bitops: Fix find_*_bit() signatures
- powerpc/32: Remove PAGE_KERNEL_TEXT to fix startup failure
- riscv: mm: Return intended SATP mode for noXlvl options
- riscv: mm: Use mmu-type from FDT to limit SATP mode
- riscv: cpufeature: add validation for zfa, zfh and zfhmin
- drivers/perf: hisi: Relax the event ID check in the framework
- s390/mm: Use __GFP_ACCOUNT for user page table allocations
- smb: client: queue post_recv_credits_work also if the peer raises the
credit target
- smb: client: limit the range of info->receive_credit_target
- smb: client: make use of ib_wc_status_msg() and skip IB_WC_WR_FLUSH_ERR
logging
- smb: server: let smb_direct_flush_send_list() invalidate a remote key
first
- Unbreak 'make tools/*' for user-space targets
- platform/mellanox: mlxbf-pmc: add sysfs_attr_init() to count_clock init
- cpufreq/amd-pstate: Fix a regression leading to EPP 0 after hibernate
- net/mlx5e: Return 1 instead of 0 in invalid case in
mlx5e_mpwrq_umr_entry_size()
- rtnetlink: Allow deleting FDB entries in user namespace
- net: enetc: fix the deadlock of enetc_mdio_lock
- net: enetc: correct the value of ENETC_RXB_TRUESIZE
- dpaa2-eth: fix the pointer passed to PTR_ALIGN on Tx path
- net: phy: realtek: fix rtl8221b-vm-cg name
- can: bxcan: bxcan_start_xmit(): use can_dev_dropped_skb() instead of
can_dropped_invalid_skb()
- can: esd: acc_start_xmit(): use can_dev_dropped_skb() instead of
can_dropped_invalid_skb()
- can: rockchip-canfd: rkcanfd_start_xmit(): use can_dev_dropped_skb()
instead of can_dropped_invalid_skb()
- selftests: net: fix server bind failure in sctp_vrf.sh
- net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for legacy RQ
- net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding
RQ
- net/smc: fix general protection fault in __smc_diag_dump
- net: ethernet: ti: am65-cpts: fix timestamp loss due to race conditions
- arm64, mm: avoid always making PTE dirty in pte_mkwrite()
- erofs: avoid infinite loops due to corrupted subpage compact indexes
- net: hibmcge: select FIXED_PHY
- ptp: ocp: Fix typo using index 1 instead of i in SMA initialization loop
- net: hsr: prevent creation of HSR device with slaves from another netns
- espintcp: use datagram_poll_queue for socket readiness
- net: datagram: introduce datagram_poll_queue for custom receive queues
- ovpn: use datagram_poll_queue for socket readiness in TCP
- net: bonding: fix possible peer notify event loss or dup issue
- hung_task: fix warnings caused by unaligned lock pointers
- mm: don't spin in add_stack_record when gfp flags don't allow
- dma-debug: don't report false positives with
DMA_BOUNCE_UNALIGNED_KMALLOC
- arch_topology: Fix incorrect error check in
topology_parse_cpu_capacity()
- riscv: hwprobe: Fix stale vDSO data for late-initialized keys at boot
- io_uring/sqpoll: switch away from getrusage() for CPU accounting
- io_uring/sqpoll: be smarter on when to update the stime usage
- btrfs: send: fix duplicated rmdir operations when using extrefs
- btrfs: ref-verify: fix IS_ERR() vs NULL check in btrfs_build_ref_tree()
- gpio: pci-idio-16: Define maximum valid register address offset
- gpio: 104-idio-16: Define maximum valid register address offset
- xfs: fix locking in xchk_nlinks_collect_dir
- platform/x86: alienware-wmi-wmax: Add AWCC support to Dell G15 5530
- Revert "cpuidle: menu: Avoid discarding useful information"
- riscv: cpufeature: avoid uninitialized variable in
has_thead_homogeneous_vlenb()
- rust: device: fix device context of Device::parent()
- slab: Avoid race on slab->obj_exts in alloc_slab_obj_exts
- slab: Fix obj_ext mistakenly considered NULL due to race condition
- smb: client: get rid of d_drop() in cifs_do_rename()
- ACPICA: Work around bogus -Wstringop-overread warning since GCC 11
- arm64: mte: Do not warn if the page is already tagged in copy_highpage()
- can: netlink: can_changelink(): allow disabling of automatic restart
- cifs: Fix TCP_Server_Info::credits to be signed
- devcoredump: Fix circular locking dependency with devcd->mutex.
- hwmon: (pmbus/max34440) Update adpm12160 coeff due to latest FW
- MIPS: Malta: Fix keyboard resource preventing i8042 driver from
registering
- rv: Make rtapp/pagefault monitor depends on CONFIG_MMU
- net: bonding: update the slave array for broadcast mode
- net: stmmac: dwmac-rk: Fix disabling set_clock_selection
- net: usb: rtl8150: Fix frame padding
- net: ravb: Enforce descriptor type ordering
- net: ravb: Ensure memory write completes before ringing TX doorbell
- mptcp: pm: in-kernel: C-flag: handle late ADD_ADDR
- selftests: mptcp: join: mark 'flush re-add' as skipped if not supported
- selftests: mptcp: join: mark implicit tests as skipped if not supported
- selftests: mptcp: join: mark 'delete re-add signal' as skipped if not
supported
- mm/mremap: correctly account old mapping after MREMAP_DONTUNMAP remap
- drm/xe: Check return value of GGTT workqueue allocation
- drm/amd/display: increase max link count and fix link->enc NULL pointer
access
- mm/damon/core: use damos_commit_quota_goal() for new goal commit
- mm/damon/core: fix list_add_tail() call on damon_call()
- spi: rockchip-sfc: Fix DMA-API usage
- firmware: arm_ffa: Add support for IMPDEF value in the memory access
descriptor
- spi: spi-nxp-fspi: add the support for sample data from DQS pad
- spi: spi-nxp-fspi: re-config the clock rate when operation require new
clock rate
- spi: spi-nxp-fspi: add extra delay after dll locked
- spi: spi-nxp-fspi: limit the clock rate for different sample clock
source selection
- spi: cadence-quadspi: Fix pm_runtime unbalance on dma EPROBE_DEFER
- arm64: dts: broadcom: bcm2712: Add default GIC address cells
- arm64: dts: broadcom: bcm2712: Define VGIC interrupt
- include: trace: Fix inflight count helper on failed initialization
- firmware: arm_scmi: Fix premature SCMI_XFER_FLAG_IS_RAW clearing in raw
mode
- spi: airoha: return an error for continuous mode dirmap creation cases
- spi: airoha: add support of dual/quad wires spi modes to exec_op()
handler
- spi: airoha: switch back to non-dma mode in the case of error
- spi: airoha: fix reading/writing of flashes with more than one plane per
lun
- sysfs: check visibility before changing group attribute ownership
- RISC-V: Define pgprot_dmacoherent() for non-coherent devices
- RISC-V: Don't print details of CPUs disabled in DT
- riscv: hwprobe: avoid uninitialized variable use in hwprobe_arch_id()
- hwmon: (pmbus/isl68137) Fix child node reference leak on early return
- hwmon: (sht3x) Fix error handling
- io_uring: fix incorrect unlikely() usage in io_waitid_prep()
- nbd: override creds to kernel when calling sock_{send,recv}msg()
- drm/panic: Fix drawing the logo on a small narrow screen
- drm/panic: Fix qr_code, ensure vmargin is positive
- drm/panic: Fix 24bit pixel crossing page boundaries
- of/irq: Convert of_msi_map_id() callers to of_msi_xlate()
- of/irq: Add msi-parent check to of_msi_xlate()
- block: require LBA dma_alignment when using PI
- gpio: ljca: Fix duplicated IRQ mapping
- io_uring: correct __must_hold annotation in io_install_fixed_file
- sched: Remove never used code in mm_cid_get()
- USB: serial: option: add UNISOC UIS7720
- USB: serial: option: add Quectel RG255C
- USB: serial: option: add Telit FN920C04 ECM compositions
- usb/core/quirks: Add Huawei ME906S to wakeup quirk
- usb: raw-gadget: do not limit transfer length
- xhci: dbc: enable back DbC in resume if it was enabled before suspend
- xhci: dbc: fix bogus 1024 byte prefix if ttyDBC read races with stall
event
- x86/microcode: Fix Entrysign revision check for Zen1/Naples
- binder: remove "invalid inc weak" check
- mei: me: add wildcat lake P DID
- objtool/rust: add one more `noreturn` Rust function
- nvmem: rcar-efuse: add missing MODULE_DEVICE_TABLE
- misc: fastrpc: Fix dma_buf object leak in fastrpc_map_lookup
- most: usb: hdm_probe: Fix calling put_device() before device
initialization
- tcpm: switch check for role_sw device with fw_node
- dt-bindings: serial: sh-sci: Fix r8a78000 interrupts
- dt-bindings: usb: dwc3-imx8mp: dma-range is required only for imx8mp
- dt-bindings: usb: qcom,snps-dwc3: Fix bindings for X1E80100
- serial: 8250_dw: handle reset control deassert error
- serial: 8250_exar: add support for Advantech 2 port card with Device ID
0x0018
- serial: 8250_mtk: Enable baud clock and manage in runtime PM
- serial: sc16is7xx: remove useless enable of enhanced features
- staging: gpib: Fix device reference leak in fmh_gpib driver
- staging: gpib: Fix no EOI on 1 and 2 byte writes
- staging: gpib: Return -EINTR on device clear
- staging: gpib: Fix sending clear and trigger events
- mm/migrate: remove MIGRATEPAGE_UNMAP
- treewide: remove MIGRATEPAGE_SUCCESS
- vmw_balloon: indicate success when effectively deflating during
migration
- xfs: always warn about deprecated mount options
- gpio: regmap: Allow to allocate regmap-irq device
- gpio: regmap: add the .fixed_direction_output configuration parameter
- gpio: idio-16: Define fixed direction of the GPIO lines
- Linux 6.17.6
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40084
- ksmbd: transport_ipc: validate payload size before reading handle
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40222
- tty: serial: sh-sci: fix RSCI FIFO overrun handling
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40223
- most: usb: Fix use-after-free in hdm_disconnect
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40106
- comedi: fix divide-by-zero in comedi_buf_munge()
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40224
- hwmon: (cgbc-hwmon) Add missing NULL check after devm_kzalloc()
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40225
- drm/panthor: Fix kernel panic on partial unmap of a GPU VA region
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40226
- firmware: arm_scmi: Account for failed debug initialization
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40227
- mm/damon/sysfs: dealloc commit test ctx always
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40228
- mm/damon/sysfs: catch commit test ctx alloc failure
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40229
- mm/damon/core: fix potential memory leak by cleaning ops_filter in
damon_destroy_scheme
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40230
- mm: prevent poison consumption when splitting THP
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40231
- vsock: fix lock inversion in vsock_assign_transport()
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40233
- ocfs2: clear extent cache after moving/defragmenting extents
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40235
- btrfs: directly free partially initialized fs_info in
btrfs_check_leaked_roots()
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40236
- virtio-net: zero unused hash fields
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40237
- fs/notify: call exportfs_encode_fid with s_umount
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40238
- net/mlx5: Fix IPsec cleanup over MPV device
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40239
- net: phy: micrel: always set shared->phydev for LAN8814
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40240
- sctp: avoid NULL dereference when chunk data buffer is missing
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40241
- erofs: fix crafted invalid cases for encoded extents
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40242
- gfs2: Fix unlikely race in gdlm_put_lock
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40243
- hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40244
- hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()
* Questing update: v6.17.6 upstream stable release (LP: #2134982) //
CVE-2025-40245
- nios2: ensure that memblock.current_limit is set when setting pfn limits
* Questing update: v6.17.5 upstream stable release (LP: #2133557)
- docs: kdoc: handle the obsolescensce of docutils.ErrorString()
- Revert "fs: make vfs_fileattr_[get|set] return -EOPNOTSUPP"
- PCI: vmd: Override irq_startup()/irq_shutdown() in
vmd_init_dev_msi_info()
- ata: libata-core: relax checks in ata_read_log_directory()
- arm64/sysreg: Fix GIC CDEOI instruction encoding
- ixgbevf: fix getting link speed data for E610 devices
- rust: cfi: only 64-bit arm and x86 support CFI_CLANG
- x86/CPU/AMD: Prevent reset reasons from being retained across reboot
- slab: reset slab->obj_ext when freeing and it is OBJEXTS_ALLOC_FAIL
- Revert "io_uring/rw: drop -EOPNOTSUPP check in
__io_complete_rw_common()"
- io_uring: protect mem region deregistration
- Revert "drm/amd/display: Only restore backlight after amdgpu_dm_init or
dm_resume"
- r8152: add error handling in rtl8152_driver_init
- net: usb: lan78xx: Fix lost EEPROM write timeout error(-ETIMEDOUT) in
lan78xx_write_raw_eeprom
- f2fs: fix wrong block mapping for multi-devices
- gve: Check valid ts bit on RX descriptor before hw timestamping
- jbd2: ensure that all ongoing I/O complete before freeing blocks
- ext4: wait for ongoing I/O to complete before freeing blocks
- btrfs: fix clearing of BTRFS_FS_RELOC_RUNNING if relocation already
running
- btrfs: fix memory leak on duplicated memory in the qgroup assign ioctl
- btrfs: only set the device specific options after devices are opened
- btrfs: fix incorrect readahead expansion length
- can: gs_usb: gs_make_candev(): populate net_device->dev_port
- can: gs_usb: increase max interface to U8_MAX
- cxl/acpi: Fix setup of memory resource in cxl_acpi_set_cache_size()
- ALSA: hda/intel: Add MSI X870E Tomahawk to denylist
- ALSA: hda/realtek: Add quirk entry for HP ZBook 17 G6
- drm/amdgpu: use atomic functions with memory barriers for vm fault info
- drm/amdgpu: fix gfx12 mes packet status return check
- drm/xe: Increase global invalidation timeout to 1000us
- perf/core: Fix address filter match with backing files
- perf/core: Fix MMAP event path names with backing files
- perf/core: Fix MMAP2 event device with backing files
- drm/amd: Check whether secure display TA loaded successfully
- PM: hibernate: Add pm_hibernation_mode_is_suspend()
- drm/amd: Fix hybrid sleep
- usb: gadget: Store endpoint pointer in usb_request
- usb: gadget: Introduce free_usb_request helper
- HID: multitouch: fix sticky fingers
- dax: skip read lock assertion for read-only filesystems
- coredump: fix core_pattern input validation
- can: m_can: m_can_plat_remove(): add missing pm_runtime_disable()
- can: m_can: m_can_handle_state_errors(): fix CAN state transition to
Error Active
- can: m_can: m_can_chip_config(): bring up interface in correct state
- can: m_can: fix CAN state in system PM
- net: mtk: wed: add dma mask limitation and GFP_DMA32 for device with
more than 4GB DRAM
- net: dlink: handle dma_map_single() failure properly
- doc: fix seg6_flowlabel path
- can: j1939: add missing calls in NETDEV_UNREGISTER notification handler
- dpll: zl3073x: Refactor DPLL initialization
- dpll: zl3073x: Handle missing or corrupted flash configuration
- r8169: fix packet truncation after S4 resume on RTL8168H/RTL8111H
- net: phy: bcm54811: Fix GMII/MII/MII-Lite selection
- net: phy: realtek: Avoid PHYCR2 access if PHYCR2 not present
- amd-xgbe: Avoid spurious link down messages during interface toggle
- Octeontx2-af: Fix missing error code in cgx_probe()
- tcp: fix tcp_tso_should_defer() vs large RTT
- net: airoha: Take into account out-of-order tx completions in
airoha_dev_xmit()
- selftests: net: check jq command is supported
- net: core: fix lockdep splat on device unregister
- ksmbd: fix recursive locking in RPC handle list access
- tg3: prevent use of uninitialized remote_adv and local_adv variables
- tls: trim encrypted message to match the plaintext on short splice
- tls: wait for async encrypt in case of error during latter iterations of
sendmsg
- tls: always set record_type in tls_process_cmsg
- tls: don't rely on tx_work during send()
- netdevsim: set the carrier when the device goes up
- net: usb: lan78xx: fix use of improperly initialized dev->chipid in
lan78xx_reset
- drm/panthor: Ensure MCU is disabled on suspend
- nvme-multipath: Skip nr_active increments in RETRY disposition
- riscv: kprobes: Fix probe address validation
- drm/bridge: lt9211: Drop check for last nibble of version register
- powerpc/fadump: skip parameter area allocation when fadump is disabled
- ASoC: codecs: Fix gain setting ranges for Renesas IDT821034 codec
- ASoC: nau8821: Cancel jdet_work before handling jack ejection
- ASoC: nau8821: Generalize helper to clear IRQ status
- ASoC: nau8821: Consistently clear interrupts before unmasking
- ASoC: nau8821: Add DMI quirk to bypass jack debounce circuit
- drm/i915/guc: Skip communication warning on reset in progress
- drm/i915/frontbuffer: Move bo refcounting
intel_frontbuffer_{get,release}()
- drm/i915/fb: Fix the set_tiling vs. addfb race, again
- drm/amdgpu: add ip offset support for cyan skillfish
- drm/amdgpu: add support for cyan skillfish without IP discovery
- drm/amdgpu: fix handling of harvesting for ip_discovery firmware
- drm/amdgpu: handle wrap around in reemit handling
- drm/amdgpu: set an error on all fences from a bad context
- drm/amdgpu: drop unused structures in amdgpu_drm.h
- drm/amd/powerplay: Fix CIK shutdown temperature
- drm/xe: Enable media sampler power gating
- drm/draw: fix color truncation in drm_draw_fill24
- drm/rockchip: vop2: use correct destination rectangle height check
- HID: intel-thc-hid: Intel-quickspi: switch first interrupt from level to
edge detection
- sched/fair: Fix pelt lost idle time detection
- ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings
- accel/qaic: Synchronize access to DBC request queue head & tail pointer
- nvme-auth: update sc_c in host response
- cxl/trace: Subtract to find an hpa_alias0 in cxl_poison events
- selftests/bpf: make arg_parsing.c more robust to crashes
- blk-mq: fix stale tag depth for shared sched tags in
blk_mq_update_nr_requests()
- block: Remove elevator_lock usage from blkg_conf frozen operations
- HID: hid-input: only ignore 0 battery events for digitizers
- HID: multitouch: fix name of Stylus input devices
- drm/xe/evict: drop bogus assert
- selftests: arg_parsing: Ensure data is flushed to disk before reading.
- nvme/tcp: handle tls partially sent records in write_space()
- rust: cpufreq: fix formatting
- arm64: debug: always unmask interrupts in el0_softstp()
- arm64: cputype: Add Neoverse-V3AE definitions
- arm64: errata: Apply workarounds for Neoverse-V3AE
- xfs: rename the old_crc variable in xlog_recover_process
- xfs: fix log CRC mismatches between i386 and other architectures
- NFSD: Rework encoding and decoding of nfsd4_deviceid
- NFSD: Minor cleanup in layoutcommit processing
- NFSD: Implement large extent array support in pNFS
- NFSD: Fix last write offset handling in layoutcommit
- phy: cdns-dphy: Store hs_clk_rate and return it
- phy: cadence: cdns-dphy: Fix PLL lock and O_CMN_READY polling
- x86/resctrl: Refactor resctrl_arch_rmid_read()
- x86/resctrl: Fix miscount of bandwidth event when reactivating
previously unavailable RMID
- cxl: Fix match_region_by_range() to use region_res_match_cxl_range()
- phy: cadence: cdns-dphy: Update calibration wait time for startup state
machine
- drm/xe: Use devm_ioremap_wc for VRAM mapping and drop manual unmap
- drm/xe: Use dynamic allocation for tile and device VRAM region
structures
- drm/xe: Move struct xe_vram_region to a dedicated header
- drm/xe: Unify the initialization of VRAM regions
- drm/xe: Move rebar to be done earlier
- PM: hibernate: Fix pm_hibernation_mode_is_suspend() build breakage
- drm/xe: Fix an IS_ERR() vs NULL bug in xe_tile_alloc_vram()
- Linux 6.17.5
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40086
- drm/xe: Don't allow evicting of BOs in same VM in array of VM binds
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40087
- NFSD: Define a proc_layoutcommit for the FlexFiles layout type
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40088
- hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp()
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40162
- ASoC: amd/sdw_utils: avoid NULL deref when devm_kasprintf() fails
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40085
- ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40172
- accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages()
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40177
- accel/qaic: Fix bootlog initialization ordering
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40163
- sched/deadline: Stop dl_server before CPU goes offline
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40174
- x86/mm: Fix SMP ordering in switch_mm_irqs_off()
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40089
- cxl/features: Add check for no entries in cxl_feature_info
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40176
- tls: wait for pending async decryptions if tls_strp_msg_hold fails
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40164
- usbnet: Fix using smp_processor_id() in preemptible code warnings
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40091
- ixgbe: fix too early devlink_free() in ixgbe_remove()
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40175
- idpf: cleanup remaining SKBs in PTP flows
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40173
- net/ip6_tunnel: Prevent perpetual tunnel growth
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40092
- usb: gadget: f_ncm: Refactor bind path to use __free()
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40093
- usb: gadget: f_ecm: Refactor bind path to use __free()
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40094
- usb: gadget: f_acm: Refactor bind path to use __free()
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40095
- usb: gadget: f_rndis: Refactor bind path to use __free()
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40165
- media: nxp: imx8-isi: m2m: Fix streaming cleanup on release
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40096
- drm/sched: Fix potential double free in
drm_sched_job_add_resv_dependencies
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40097
- ALSA: hda: Fix missing pointer check in hda_component_manager_init
function
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40098
- ALSA: hda: cs35l41: Fix NULL pointer dereference in
cs35l41_get_acpi_mute_state()
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40099
- cifs: parse_dfs_referrals: prevent oob on malformed input
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40100
- btrfs: do not assert we found block group item when creating free space
tree
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40101
- btrfs: fix memory leaks when rejecting a non SINGLE data profile without
an RST
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40167
- ext4: detect invalid INLINE_DATA + EXTENTS flag combination
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40102
- KVM: arm64: Prevent access to vCPU events before init
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40103
- smb: client: Fix refcount leak for cifs_sb_tlink
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40104
- ixgbevf: fix mailbox API compatibility by negotiating supported features
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40166
- drm/xe/guc: Check GuC running state before deregistering exec queue
* Questing update: v6.17.5 upstream stable release (LP: #2133557) //
CVE-2025-40105
- vfs: Don't leak disconnected dentries on umount
Date: 2025-12-13 23:03:09.771503+00:00
Changed-By: Mehmet Basaran <mehmet.basaran at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux/6.17.0-10.10
-------------- next part --------------
Sorry, changesfile not available.
More information about the Questing-changes
mailing list