[ubuntu/resolute-updates] linux-realtime 7.0.0-22.22.1 (Accepted)
Andy Whitcroft
apw at canonical.com
Thu May 28 15:35:17 UTC 2026
linux-realtime (7.0.0-22.22.1) resolute; urgency=medium
[ Ubuntu: 7.0.0-22.22 ]
* GRO managed-frag use-after-free leading to local privilege escalation
(LP: #2154172)
- net: gro: don't merge zcopy skbs
[ Ubuntu: 7.0.0-20.20 ]
* apparmor (LP: #2151747)
- SAUCE: apparmor: pass big_resp to handler
- SAUCE: apparmor: remove redundant kref_init for listener->count
- SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb
* apparmor (LP: #2151747) // CVE-2026-47337
- SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr
* apparmor (LP: #2151747) // CVE-2026-47334
- SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock
* apparmor (LP: #2151747) // CVE-2026-47333
- SAUCE: apparmor: fix dfa unpacking size of the notification filter
* apparmor (LP: #2151747) // CVE-2026-47332
- SAUCE: apparmor: fix size check against type instead of pointer
* apparmor: LLVM/clang build failure due to uninitialized variable in
notify.c (LP: #2148809) // CVE-2026-47330
- SAUCE: apparmor: initialize variable used in uninitialized context
* apparmor (LP: #2151747) // CVE-2026-47329
- SAUCE: apparmor: fix name validation bypass on notification
* apparmor (LP: #2151747) // CVE-2026-47327 // CVE-2026-47328
- SAUCE: apparmor: fix glob memory leak after kstrdup
* apparmor (LP: #2151747) // CVE-2026-47326
- SAUCE: apparmor: fix inverted NULL check after aa_get_buffer
[ Ubuntu: 7.0.0-19.19 ]
* resolute/linux: 7.0.0-19.19 -proposed tracker (LP: #2153786)
* Packaging resync (LP: #1786013)
- [Packaging] update annotations scripts
- [Packaging] debian.master/dkms-versions -- remove dkms-versions
(main/s2026.05.11)
* CVE-2026-46300
- net: skbuff: preserve shared-frag marker during coalescing
- net: skbuff: propagate shared-frag marker through frag-transfer helpers
* net/rds: reset op_nents when zerocopy page pin fails (LP: #2153962)
- net/rds: reset op_nents when zerocopy page pin fails
* CVE-2026-46333
- ptrace: slightly saner 'get_dumpable()' logic
* CVE-2026-43500
- rxrpc: Fix conn-level packet handling to unshare RESPONSE packets
- rxrpc: Fix potential UAF after skb_unshare() failure
- rxrpc: Fix rxrpc_input_call_event() to only unshare DATA packets
- rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
* CVE-2026-43284
- xfrm: esp: avoid in-place decrypt on shared skb frags
[ Ubuntu: 7.0.0-15.15 ]
* resolute/linux: 7.0.0-15.15 -proposed tracker (LP: #2148866)
* Qualcomm X1E: Speaker overdrive causes hardware protection shutdown
(LP: #2149808)
- SAUCE: ASoC: qcom: x1e80100: limit speaker volumes
* intel-ipu7 / intel-ipu7-isys modules are shipped unsigned in latest
Resolute kernels, breaking Secure Boot systems (LP: #2148718)
- [packaging] add intel-ipu7 to signature inclusion list
Date: 2026-05-26 14:19:10.429910+00:00
Changed-By: Edoardo Canepa <edoardo.canepa at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-realtime/7.0.0-22.22.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list