Public bug reported:
SRU Justification
Impact:
The upstream process for stable tree updates is quite similar
in scope to the Ubuntu SRU process, e.g., each patch has to
demonstrably fix a bug, and each patch is vetted by upstream
by originating either directly from a mainline/stable Linux tree or
a minimally backported form of that patch. The following upstream
stable patches should be included in the Ubuntu kernel:
upstream stable patchset 2026-07-15
Ported from the following upstream stable releases:
v6.18.38, v7.1.3
from git://git.kernel.org/
KVM: x86: Fix shadow paging use-after-free due to unexpected role
Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion
support"
batman-adv: tp_meter: keep unacked list in ascending ordered
batman-adv: tp_meter: initialize dup_acks explicitly
batman-adv: tp_meter: initialize dec_cwnd explicitly
batman-adv: tp_meter: avoid window underflow
batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
batman-adv: tp_meter: fix fast recovery precondition
batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
batman-adv: tp_meter: add only finished tp_vars to lists
batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
batman-adv: prevent ELP transmission interval underflow
batman-adv: tp_meter: initialize last_recv_time during init
batman-adv: gw: don't deselect gateway with active hardif
batman-adv: ensure bcast is writable before modifying TTL
batman-adv: fix (m|b)cast csum after decrementing TTL
batman-adv: frag: ensure fragment is writable before modifying TTL
batman-adv: frag: avoid underflow of TTL
batman-adv: v: prevent OGM aggregation on disabled hardif
batman-adv: tp_meter: restrict number of unacked list entries
batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
batman-adv: tp_meter: prevent parallel modifications of last_recv
batman-adv: tp_meter: handle overlapping packets
batman-adv: tt: don't merge change entries with different VIDs
batman-adv: tt: track roam count per VID
batman-adv: dat: prevent false sharing between VLANs
batman-adv: tvlv: enforce 2-byte alignment
batman-adv: tvlv: avoid race of cifsnotfound handler state
ipv6: account for fraggap on the paged allocation path
ipv4: account for fraggap on the paged allocation path
ntfs3: reject direct userspace writes to reserved $LX* xattrs
wifi: mt76: add wcid publish check in mt76_sta_add
af_unix: Set gc_in_progress to true in unix_gc().
mac802154: llsec: add skb_cow_data() before in-place crypto
net: skmsg: preserve sg.copy across SG transforms
net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
apparmor: mediate the implicit connect of TCP fast open sendmsg
apparmor: fix use-after-free in rawdata dedup loop
NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
fbdev: fix use-after-free in store_modes()
kernel/fork: clear PF_BLOCK_TS in copy_process()
block: invalidate cached plug timestamp after task switch
KVM: arm64: Omit tag sync on stage-2 mappings of the zero page
err.h: use __always_inline on all error pointer helpers
gcov: use atomic counter updates to fix concurrent access crashes
KEYS: fix overflow in keyctl_pkey_params_get_2()
keys: Pin request_key_auth payload in instantiate paths
userfaultfd: ensure mremap_userfaultfd_fail() releases mmap_changing
wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer
wifi: ath11k: fix warning when unbinding
wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
wifi: rtw88: increase TX report timeout to fix race condition
wifi: rtw88: usb: fix memory leaks on USB write failures
wifi: iwlwifi: mvm: fix race condition in PTP removal
wifi: iwlwifi: mld: fix race condition in PTP removal
wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
f2fs: pass correct iostat type for single node writes
f2fs: validate orphan inode entry count
f2fs: validate compress cache inode only when enabled
f2fs: fix to round down start offset of fallocate for pin file
f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
f2fs: keep atomic write retry from zeroing original data
block: Avoid mounting the bdev pseudo-filesystem in userspace
bpf: use kvfree() for replaced sysctl write buffer
MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
exfat: fix potential use-after-free in exfat_find_dir_entry()
KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with
get_unaligned()
crypto: nx - fix nx_crypto_ctx_exit argument
gfs2: fix use-after-free in gfs2_qd_dealloc
pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
hdlc_ppp: sync per-proto timers before freeing hdlc state
blk-cgroup: fix UAF in __blkcg_rstat_flush()
tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
LoongArch: Report dying CPU to RCU in stop_this_cpu()
pNFS: Fix use-after-free in pnfs_update_layout()
irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
fpga: region: fix use-after-free in child_regions_with_firmware()
rpmsg: char: Fix use-after-free on probe error path
ocfs2: reject oversized group bitmap descriptors
9p: avoid putting oldfid in p9_client_walk() error path
MIPS: smp: report dying CPU to RCU in stop_this_cpu()
KVM: x86: hyper-v: Bound the bank index when querying sparse banks
KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
power: reset: linkstation-poweroff: fix use-after-free in the
linkstation_poweroff_init()
riscv: mm: Extract helper mark_new_valid_map()
riscv: kfence: Call mark_new_valid_map() for kfence_unprotect()
fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
fbdev: modedb: fix a possible UAF in fb_find_mode()
fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
i2c: core: fix adapter registration race
NFSD: Fix SECINFO_NO_NAME decode error cleanup
nfsd: fix posix_acl leak on SETACL decode failure
nfsd: fix inverted cp_ttl check in async copy reaper
nfsd: check get_user() return when reading princhashlen
nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
nfsd: reset write verifier on deferred writeback errors
NFSv4/flexfiles: reject zero filehandle version count
NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
NFSv4: clear exception state on successful mkdir retry
NFS: Prevent resource leak in nfs_alloc_server()
ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
net/tcp-ao: fix use-after-free of key in del_async path
apparmor: advertise the tcp fast open fix is applied
PCI/P2PDMA: Add Intel QAT, DSA, IAA devices to whitelist
fscrypt: Fix key setup in edge case with multiple data unit sizes
wifi: rtl8xxxu: Detect the maximum supported channel width
f2fs: fix missing read bio submission on large folio error
f2fs: reject setattr size changes on large folio files
f2fs: fix to do sanity check on f2fs_get_node_folio_ra()
f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block"
f2fs: read COW data with the original inode during atomic write
sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path
fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
fbdev: omap2: fix inconsistent lock returns in omapfb_mmap
fbdev: omap2: fix use-after-free in omapfb_mmap
nfsd: release layout stid on setlease failure
nfsd: fix posix_acl leak and ignored error in nfsd4_create_file
nfsd: fix dead ACL conflict guard in nfsd4_create
UBUNTU: Upstream stable to v6.18.38, v7.1.3
** Affects: linux (Ubuntu)
Importance: Undecided
Status: Invalid
** Affects: linux (Ubuntu Resolute)
Importance: Medium
Assignee: Alice C. Munduruca (cremfuelled)
Status: In Progress
** Tags: kernel-stable-tracking-bug
** Changed in: linux (Ubuntu)
Status: New => Confirmed
** Also affects: linux (Ubuntu Resolute)
Importance: Undecided
Status: New
** Changed in: linux (Ubuntu)
Status: Confirmed => Invalid
** Changed in: linux (Ubuntu Resolute)
Importance: Undecided => Medium
** Changed in: linux (Ubuntu Resolute)
Status: New => In Progress
** Changed in: linux (Ubuntu Resolute)
Assignee: (unassigned) => Alice C. Munduruca (cremfuelled)
** Description changed:
SRU Justification
Impact:
The upstream process for stable tree updates is quite similar
in scope to the Ubuntu SRU process, e.g., each patch has to
demonstrably fix a bug, and each patch is vetted by upstream
by originating either directly from a mainline/stable Linux tree or
a minimally backported form of that patch. The following upstream
stable patches should be included in the Ubuntu kernel:
upstream stable patchset 2026-07-15
+
+ Ported from the following upstream stable releases:
+ v6.18.38, v7.1.3
+
from git://git.kernel.org/
+
+ KVM: x86: Fix shadow paging use-after-free due to unexpected role
+ Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command
Completion support"
+ batman-adv: tp_meter: keep unacked list in ascending ordered
+ batman-adv: tp_meter: initialize dup_acks explicitly
+ batman-adv: tp_meter: initialize dec_cwnd explicitly
+ batman-adv: tp_meter: avoid window underflow
+ batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
+ batman-adv: tp_meter: fix fast recovery precondition
+ batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
+ batman-adv: tp_meter: add only finished tp_vars to lists
+ batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
+ batman-adv: prevent ELP transmission interval underflow
+ batman-adv: tp_meter: initialize last_recv_time during init
+ batman-adv: gw: don't deselect gateway with active hardif
+ batman-adv: ensure bcast is writable before modifying TTL
+ batman-adv: fix (m|b)cast csum after decrementing TTL
+ batman-adv: frag: ensure fragment is writable before modifying TTL
+ batman-adv: frag: avoid underflow of TTL
+ batman-adv: v: prevent OGM aggregation on disabled hardif
+ batman-adv: tp_meter: restrict number of unacked list entries
+ batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
+ batman-adv: tp_meter: prevent parallel modifications of last_recv
+ batman-adv: tp_meter: handle overlapping packets
+ batman-adv: tt: don't merge change entries with different VIDs
+ batman-adv: tt: track roam count per VID
+ batman-adv: dat: prevent false sharing between VLANs
+ batman-adv: tvlv: enforce 2-byte alignment
+ batman-adv: tvlv: avoid race of cifsnotfound handler state
+ ipv6: account for fraggap on the paged allocation path
+ ipv4: account for fraggap on the paged allocation path
+ ntfs3: reject direct userspace writes to reserved $LX* xattrs
+ wifi: mt76: add wcid publish check in mt76_sta_add
+ af_unix: Set gc_in_progress to true in unix_gc().
+ mac802154: llsec: add skb_cow_data() before in-place crypto
+ net: skmsg: preserve sg.copy across SG transforms
+ net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
+ apparmor: mediate the implicit connect of TCP fast open sendmsg
+ apparmor: fix use-after-free in rawdata dedup loop
+ NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
+ fbdev: fix use-after-free in store_modes()
+ kernel/fork: clear PF_BLOCK_TS in copy_process()
+ block: invalidate cached plug timestamp after task switch
+ KVM: arm64: Omit tag sync on stage-2 mappings of the zero page
+ err.h: use __always_inline on all error pointer helpers
+ gcov: use atomic counter updates to fix concurrent access crashes
+ KEYS: fix overflow in keyctl_pkey_params_get_2()
+ keys: Pin request_key_auth payload in instantiate paths
+ userfaultfd: ensure mremap_userfaultfd_fail() releases mmap_changing
+ wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
+ wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer
+ wifi: ath11k: fix warning when unbinding
+ wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
+ wifi: rtw88: increase TX report timeout to fix race condition
+ wifi: rtw88: usb: fix memory leaks on USB write failures
+ wifi: iwlwifi: mvm: fix race condition in PTP removal
+ wifi: iwlwifi: mld: fix race condition in PTP removal
+ wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
+ f2fs: pass correct iostat type for single node writes
+ f2fs: validate orphan inode entry count
+ f2fs: validate compress cache inode only when enabled
+ f2fs: fix to round down start offset of fallocate for pin file
+ f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
+ f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
+ f2fs: keep atomic write retry from zeroing original data
+ block: Avoid mounting the bdev pseudo-filesystem in userspace
+ bpf: use kvfree() for replaced sysctl write buffer
+ MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
+ exfat: fix potential use-after-free in exfat_find_dir_entry()
+ KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
+ KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with
get_unaligned()
+ crypto: nx - fix nx_crypto_ctx_exit argument
+ gfs2: fix use-after-free in gfs2_qd_dealloc
+ pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
+ hdlc_ppp: sync per-proto timers before freeing hdlc state
+ blk-cgroup: fix UAF in __blkcg_rstat_flush()
+ tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
+ LoongArch: Report dying CPU to RCU in stop_this_cpu()
+ pNFS: Fix use-after-free in pnfs_update_layout()
+ irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on
remove
+ fpga: region: fix use-after-free in child_regions_with_firmware()
+ rpmsg: char: Fix use-after-free on probe error path
+ ocfs2: reject oversized group bitmap descriptors
+ 9p: avoid putting oldfid in p9_client_walk() error path
+ MIPS: smp: report dying CPU to RCU in stop_this_cpu()
+ KVM: x86: hyper-v: Bound the bank index when querying sparse banks
+ KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
+ power: reset: linkstation-poweroff: fix use-after-free in the
linkstation_poweroff_init()
+ riscv: mm: Extract helper mark_new_valid_map()
+ riscv: kfence: Call mark_new_valid_map() for kfence_unprotect()
+ fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
+ fbdev: modedb: fix a possible UAF in fb_find_mode()
+ fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
+ i2c: core: fix adapter registration race
+ NFSD: Fix SECINFO_NO_NAME decode error cleanup
+ nfsd: fix posix_acl leak on SETACL decode failure
+ nfsd: fix inverted cp_ttl check in async copy reaper
+ nfsd: check get_user() return when reading princhashlen
+ nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
+ nfsd: reset write verifier on deferred writeback errors
+ NFSv4/flexfiles: reject zero filehandle version count
+ NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
+ NFSv4: clear exception state on successful mkdir retry
+ NFS: Prevent resource leak in nfs_alloc_server()
+ ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
+ net/tcp-ao: fix use-after-free of key in del_async path
+ apparmor: advertise the tcp fast open fix is applied
+ PCI/P2PDMA: Add Intel QAT, DSA, IAA devices to whitelist
+ fscrypt: Fix key setup in edge case with multiple data unit sizes
+ wifi: rtl8xxxu: Detect the maximum supported channel width
+ f2fs: fix missing read bio submission on large folio error
+ f2fs: reject setattr size changes on large folio files
+ f2fs: fix to do sanity check on f2fs_get_node_folio_ra()
+ f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
+ f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
+ Revert "f2fs: remove non-uptodate folio from the page cache in
move_data_block"
+ f2fs: read COW data with the original inode during atomic write
+ sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path
+ fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
+ fbdev: omap2: fix inconsistent lock returns in omapfb_mmap
+ fbdev: omap2: fix use-after-free in omapfb_mmap
+ nfsd: release layout stid on setlease failure
+ nfsd: fix posix_acl leak and ignored error in nfsd4_create_file
+ nfsd: fix dead ACL conflict guard in nfsd4_create
+ UBUNTU: Upstream stable to v6.18.38, v7.1.3
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160733
Title:
Resolute update: upstream stable patchset 2026-07-15
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2160733/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs