This bug was fixed in the package linux - 6.8.0-139.139
---------------
linux (6.8.0-139.139) noble; urgency=medium
* noble/linux: 6.8.0-139.139 -proposed tracker (LP: #2162466)
* Packaging resync (LP: #1786013)
- [Packaging] update annotations scripts
- [Packaging] debian.master/dkms-versions -- update from kernel-versions
(main/2026.08.03)
* kselftests_net.net:test_bpf.sh fails on ppc64el (LP: #2072994)
- powerpc64/bpf: jit support for 32bit offset jmp instruction
- powerpc64/bpf: jit support for unconditional byte swap
- powerpc64/bpf: jit support for sign extended load
- powerpc64/bpf: jit support for sign extended mov
- powerpc64/bpf: jit support for signed division and modulo
* noble/linux-raspi FTBFS: bcmasp phylib managed-EEE backport missing
prerequisites (LP: #2159608)
- SAUCE: Revert "net: bcm: asp2: convert to phylib managed EEE"
- SAUCE: Revert "net: bcm: asp2: remove tx_lpi_enabled"
- SAUCE: Revert "net: bcm: asp2: fix LPI timer handling"
* Drop DEP-8 tests from kernel packages (LP: #2160302)
- [Packaging] Drop DEP-8 tests from kernel source
* noble-stable-2026-06-16 dropped a bracket causing FTBFS (LP: #2158920)
- SAUCE: drm/v3d: Fix bracket drop FTBFS for non-generic kernels
* ubuntu_bpf failed to build on Noble ( error: ‘XDP_UMEM_TX_METADATA_LEN’
undeclared ) (LP: #2139686)
- selftests/bpf: Add XDP_UMEM_TX_METADATA_LEN to XSK TX metadata test
* Malformed HV_LINUX_VENDOR_ID breaks VM Availability Metric on Azure
(LP: #2158462)
- SAUCE: (no-up) hv: Fix supplied vendor ID
* net/tls: Three upstream fixes without CVE missing from Ubuntu
6.8.0-124-generic (LP: #2155609)
- net: tls: fix silent data drop under pipe back-pressure
* net:fcnal-test.sh fails because it can't find wait_local_port_listen on
noble (LP: #2142613)
- selftests: net: move wait_local_port_listen to lib.sh
* Noble update: upstream stable patchset 2026-07-09 (LP: #2160250)
- mptcp: sync the msk->sndbuf at accept() time
- mptcp: pm: ADD_ADDR rtx: allow ID 0
- s390/debug: Reject zero-length input before trimming a newline
- Revert "x86/vdso: Fix output operand size of RDPID"
- Revert "s390/cio: Update purge function to unregister the unused
subchannels"
- sysfs: don't remove existing directory on update failure
- mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()
- smb: client: protect tc_count increment in
smb2_find_smb_sess_tcon_unlocked()
- smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close
- hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
- ALSA: ua101: Reject too-short USB descriptors
- ALSA: pcm: Don't setup bogus iov_iter for silencing
- ALSA: asihpi: Fix potential OOB array access at reading cache
- efi: Allocate runtime workqueue before ACPI init
- drivers/base/memory: fix memory block reference leak in poison
accounting
- net: wwan: iosm: fix potential memory leaks in ipc_imem_init()
- Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
- Bluetooth: ISO: drop ISO_END frames received without prior ISO_START
- Bluetooth: bnep: Fix UAF read of dev->name
- Bluetooth: MGMT: validate Add Extended Advertising Data length
- Bluetooth: serialize accept_q access
- phonet/pep: disable BH around forwarded sk_receive_skb()
- net: bcmgenet: keep RBUF EEE/PM disabled
- net: ifb: report ethtool stats over num_tx_queues
- netfilter: ip6t_hbh: reject oversized option lists
- netfilter: nf_queue: hold bridge skb->dev while queued
- netfilter: ipset: stop hash:* range iteration at end
- qed: fix double free in qed_cxt_tables_alloc()
- ring-buffer: Fix reporting of missed events in iterator
- vsock/vmci: fix UAF when peer resets connection during handshake
- vsock/virtio: reset connection on receiving queue overflow
- wifi: ath11k: clear shared SRNG pointer state on restart
- ipv4: raw: reject IP_HDRINCL packets with ihl < 5
- ixgbevf: fix use-after-free in VEPA multicast source pruning
- ice: fix setting promisc mode while adding VID filter
- wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
- cifs: Fix busy dentry used after unmounting
- tracing: Do not call map->ops->elt_free() if elt_alloc() fails
- arm64: probes: Handle probes on hinted conditional branch instructions
- KVM: arm64: vgic-its: Reject restored DTE with out-of-range
num_eventid_bits
- drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe
- spi: qup: fix error pointer deref after DMA setup failure
- phy: tegra: xusb: Fix per-pad high-speed termination calibration
- scsi: isci: Fix use-after-free in device removal path
- spi: sprd: fix error pointer deref after DMA setup failure
- spi: ti-qspi: fix use-after-free after DMA setup failure
- RDMA/siw: Reject MPA FPDU length underflow before signed receive math
- LoongArch: Remove unused code to avoid build warning
- device property: set fwnode->secondary to NULL in fwnode_init()
- drm/virtio: use uninterruptible resv lock for plane updates
- drm/bridge: it66121: acquire reset GPIO in probe
- drm/bridge: megachips: remove bridge when irq request fails
- drm/amd/display: Fix integer overflow in bios_get_image()
- drm/amd/display: Validate GPIO pin LUT table size before iterating
- drm/amd/display: Validate payload length and link_index in
dc_process_dmub_aux_transfer_async
- batman-adv: mcast: fix use-after-free in orig_node RCU release
- batman-adv: clear current gateway during teardown
- batman-adv: dat: handle forward allocation error
- batman-adv: fix tp_meter counter underflow during shutdown
- batman-adv: frag: disallow unicast fragment in fragment
- batman-adv: bla: fix report_work leak on backbone_gw purge
- batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown
- batman-adv: tp_meter: fix race condition in send error reporting
- batman-adv: tt: fix negative last_changeset_len
- batman-adv: tt: fix negative tt_buff_len
- hwmon: (pmbus/adm1266) seed timestamp from the real-time clock
- hwmon: (pmbus/adm1266) reject implausible blackbox record_count
- hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer
- hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized
buffer
- hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
- hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in
get_multiple
- hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe()
- hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe()
- hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO
accessors
- HID: uclogic: Fix regression of input name assignment
- firmware: arm_ffa: Check for NULL FF-A ID table while driver
registration
- firmware: arm_ffa: Skip free_pages on RX buffer alloc failure
- kunit: config: Enable KUNIT_DEBUGFS by default
- kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS
- pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150
- ARM: integrator: Fix early initialization
- ALSA: hda: cs35l56: Put ACPI device after setting companion
- netfilter: x_tables: unregister the templates first
- kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist()
- test_kprobes: clear kprobes between test runs
- tcp: Fix imbalanced icsk_accept_queue count.
- ice: fix locking in ice_dcb_rebuild()
- net: lan966x: avoid unregistering netdev on register failure
- phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register
access
- irqchip/ath79-cpu: Remove unused function
- irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT
- zonefs: handle integer overflow in zonefs_fname_to_fno
- netfs: Fix overrun check in netfs_extract_user_iter()
- net: ethernet: cortina: Make RX SKB per-port
- net: ethernet: cortina: Drop half-assembled SKB
- net: ethernet: cortina: Carry over frag counter
- net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference
- wifi: ath11k: fix error path leaks in some WMI WOW calls
- wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm()
- accel/qaic: Add overflow check to remap_pfn_range during mmap
- net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint
- ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics
- drm/msm/dsi: don't dump registers past the mapped region
- drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN
- powerpc/time: Remove redundant preempt_disable|enable() calls from
arch_irq_work_raise()
- net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot
- net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
- net: tls: prevent chain-after-chain in plain text SG
- net: phy: DP83TC811: add reading of abilities
- x86/xen: Fix xen_e820_swap_entry_with_ram()
- tls: Preserve sk_err across recvmsg() when data has been copied
- net/mlx5: Do not restore destination-less TC rules
- spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache()
- drm/msm/snapshot: fix dumping of the unaligned regions
- wifi: ath11k: fix peer resolution on rx path when peer_id=0
- net: dsa: mt7530: fix FDB entries not aging out with short timeout
- net: dsa: mt7530: rename mt753x_bpdu_port_fw enum to mt753x_to_cpu_fw
- net: dsa: mt7530: preserve VLAN tags on trapped link-local frames
- net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
- platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL
- platform/x86: hp_accel: Check ACPI_COMPANION() against NULL
- platform/x86: intel-hid: Check ACPI_HANDLE() against NULL
- platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL
- RDMA/rtrs: Fix use-after-free in path file creation cleanup
- net: bridge: Flush multicast groups when snooping is disabled
- bridge: mcast: Fix a possible use-after-free when removing a bridge port
- pds_core: fix error handling in pdsc_devcmd_wait
- pds_core: fix debugfs_lookup dentry leak and error handling
- ALSA: seq: ump: Use guard() for locking
- ALSA: seq: Serialize UMP output teardown with event_input
- Bluetooth: btmtk: add the function to get the fw name
- Bluetooth: btusb: mediatek: refactor the function btusb_mtk_reset
- Bluetooth: btmtk: rename btmediatek_data
- Bluetooth: btmtk: move btusb_mtk_hci_wmt_sync to btmtk.c
- Bluetooth: btmtk: fix urb->setup_packet leak in error paths
- net: ag71xx: check error for platform_get_irq
- bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
- string: add mem_is_zero() helper to check if memory area is all zeros
- gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n)
- gpio: cdev: check if uAPI v2 config attributes are correctly zeroed
- ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove()
- net: mana: validate rx_req_idx to prevent out-of-bounds array access
- pds_core: ensure null-termination for firmware version strings
- LoongArch: kprobes: Fix handling of fatal unrecoverable recursions
- security/keys: fix missed RCU read section on lookup
- ata: libata-scsi: improve readability of ata_scsi_qc_issue()
- ata: libata-scsi: do not use the deferred QC feature for ATA_DEFER_PORT
- ata: libata-scsi: do not use the deferred QC feature on PMPs with CBS
- ata: libata-scsi: do not needlessly defer commands when using PMP with
FBS
- perf parse-events: Expose/rename config_term_name
- net/mlx5e: Trigger neighbor resolution for unresolved destinations
- net/mlx5e: Use ip6_dst_lookup instead of ipv6_dst_lookup_flow for MAC
init
- ksmbd: validate SID in parent security descriptor during ACL inheritance
- smb: client: require net admin for CIFS SWN netlink
- smb: client: use data_len for SMB2 READ encrypted folioq copy
- mm/memory_hotplug: fix memory block reference leak on remove
- Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer
- cgroup/cpuset: Reset DL migration state on can_attach() failure
- ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()
- lsm: hold cred_guard_mutex for lsm_set_self_attr()
- octeontx2-af: CGX: add bounds check to cgx_speed_mbps index
- ice: restore PTP Rx timestamp config after ethtool set-channels
- af_unix: Fix UAF read of tail->len in unix_stream_data_wait()
- ARM: dts: renesas: genmai: Drop superfluous cells
- ARM: dts: renesas: rskrza1: Drop superfluous cells
- riscv: mm: Fixup no5lvl failure when vaddr is invalid
- ALSA: hda: cs35l41: Put ACPI device on missing physical node
- ice: fix setting RSS VSI hash for E830
- tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().
- powerpc: fix dead default for GUEST_STATE_BUFFER_TEST
- netfs: Fix trimming of streaming-write folios in netfs_inval_folio()
- netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes
gone
- wifi: ath10k: skip WMI and beacon transmission when device is wedged
- scsi: sd: Fix return code handling in sd_spinup_disk()
- ALSA: scarlett2: Add missing error check when initialise Autogain Status
- btrfs: fix squota accounting during enable generation
- landlock: Fix TCP handling of short AF_UNSPEC addresses
- Upstream stable to v6.6.142, v6.12.92
* Noble update: upstream stable patchset 2026-07-09 (LP: #2160250) //
CVE-2025-71289
- fs/ntfs3: handle attr_set_size() errors when truncating files
* Noble update: upstream stable patchset 2026-07-09 (LP: #2160250) //
CVE-2026-46315
- io_uring/waitid: clear waitid info before copying it to userspace
* Noble update: upstream stable patchset 2026-07-09 (LP: #2160250) //
CVE-2026-31486
- hwmon: (pmbus/core) Protect regulator operations with mutex
* Noble update: upstream stable patchset 2026-07-09 (LP: #2160250) //
CVE-2026-23469
- drm/imagination: Synchronize interrupts before suspending the GPU
* Noble update: upstream stable patchset 2026-07-09 (LP: #2160250) //
CVE-2026-31560
- spi: spi-dw-dma: fix print error log when wait finish transaction
* Noble update: upstream stable patchset 2026-07-09 (LP: #2160250) //
CVE-2026-31420
- bridge: mrp: reject zero test interval to avoid OOM panic
* Noble update: upstream stable patchset 2026-07-09 (LP: #2160250) //
CVE-2026-46275
- Bluetooth: hci_uart: fix UAFs and race conditions in close and init
paths
* Noble update: upstream stable patchset 2026-07-09 (LP: #2160250) //
CVE-2026-46170
- mptcp: pm: ADD_ADDR rtx: free sk if last
* Noble update: upstream stable patchset 2026-07-09 (LP: #2160250) //
CVE-2026-46158
- mptcp: pm: ADD_ADDR rtx: always decrease sk refcount
* CVE-2026-64531
- net: openvswitch: reject oversized nested action attrs
* CVE-2026-53247
- net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
* CVE-2026-53224
- sctp: validate embedded INIT chunk and address list lengths in cookie
* CVE-2026-53246
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
* CVE-2026-53225
- sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
* CVE-2026-53228
- ipv6: sit: reload inner IPv6 header after GSO offloads
* CVE-2026-46242
- eventpoll: fix ep_remove struct eventpoll / struct file UAF
* CVE-2026-46331
- net/sched: fix pedit partial COW leading to page cache corruption
* CVE-2026-53212
- netfilter: nft_tunnel: fix use-after-free on object destroy
* CVE-2026-53359
- KVM: x86: Fix shadow paging use-after-free due to unexpected role
* CVE-2026-53151
- rxrpc: Fix the ACK parser to extract the SACK table for parsing
* CVE-2026-52924
- sctp: purge outqueue on stale COOKIE-ECHO handling
* CVE-2026-53215
- net: mvpp2: refill RX buffers before XDP or skb use
* CVE-2026-53176
- IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
* CVE-2026-52931
- batman-adv: tp_meter: avoid use of uninit sender vars
* CVE-2026-52914
- batman-adv: fix fragment reassembly length accounting
* CVE-2026-46325
- RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE
* CVE-2026-43465
- net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ
* CVE-2026-43198
- tcp: fix potential race in tcp_v6_syn_recv_sock()
* CVE-2026-43197
- netconsole: avoid OOB reads, msg is not nul-terminated
* CVE-2026-43083
- net: ioam6: fix OOB and missing lock
-- Edoardo Canepa <[email protected]> Sat, 01 Aug 2026
04:25:37 +0200
** Changed in: linux (Ubuntu Noble)
Status: Fix Committed => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2025-71289
** CVE added: https://cve.org/CVERecord?id=CVE-2026-23469
** CVE added: https://cve.org/CVERecord?id=CVE-2026-31420
** CVE added: https://cve.org/CVERecord?id=CVE-2026-31486
** CVE added: https://cve.org/CVERecord?id=CVE-2026-31560
** CVE added: https://cve.org/CVERecord?id=CVE-2026-43083
** CVE added: https://cve.org/CVERecord?id=CVE-2026-43197
** CVE added: https://cve.org/CVERecord?id=CVE-2026-43198
** CVE added: https://cve.org/CVERecord?id=CVE-2026-43465
** CVE added: https://cve.org/CVERecord?id=CVE-2026-46158
** CVE added: https://cve.org/CVERecord?id=CVE-2026-46170
** CVE added: https://cve.org/CVERecord?id=CVE-2026-46242
** CVE added: https://cve.org/CVERecord?id=CVE-2026-46275
** CVE added: https://cve.org/CVERecord?id=CVE-2026-46315
** CVE added: https://cve.org/CVERecord?id=CVE-2026-46325
** CVE added: https://cve.org/CVERecord?id=CVE-2026-46331
** CVE added: https://cve.org/CVERecord?id=CVE-2026-52914
** CVE added: https://cve.org/CVERecord?id=CVE-2026-52924
** CVE added: https://cve.org/CVERecord?id=CVE-2026-52931
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53151
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53176
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53212
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53215
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53224
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53225
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53228
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53246
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53247
** CVE added: https://cve.org/CVERecord?id=CVE-2026-53359
** CVE added: https://cve.org/CVERecord?id=CVE-2026-64531
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160250
Title:
Noble update: upstream stable patchset 2026-07-09
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2160250/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs