This bug was fixed in the package linux - 6.8.0-146.146

---------------
linux (6.8.0-146.146) noble; urgency=medium

  * noble/linux: 6.8.0-146.146 -proposed tracker (LP: #2166353)

  * Packaging resync (LP: #1786013)
    - [Packaging] debian.master/dkms-versions -- update from kernel-versions
      (main/2026.08.31)

  * Bluetooth fails to initialize due to a kernel NULL pointer error
    (LP: #2165873)
    - Bluetooth: btmtk: move btusb_mtk_[setup, shutdown] to btmtk.c

  * Dell Precision fails to shutdown when HDMI display is connected (22.04
    HWE) (LP: #2164507)
    - drm/i915/vbt: Add fields dedicated_external and dyn_port_over_tc
    - drm/i915/display: Handle dedicated external ports in
      intel_encoder_is_tc()

  * ice: E810 interface fails to initialize (ice_init_hw failed: -5) during
    NVM read (LP: #2163508)
    - ice: acquire NVM lock around each flash read

  * [SRU] HPE:  Fix for UBSAN array-index-out-of-bounds (LP: #2161004)
    - x86/platform/uv: Fix UBSAN array-index-out-of-bounds

  * vfio_pci soft lockup on VM start while using PCIe passthrough
    (LP: #2089306)
    - SAUCE: Revert "vfio/pci: Use unmap_mapping_range()"

  * Reboot machine with ext4 configured to data=journal could dump spurious
    call trace (LP: #2164716)
    - ext4: clear stale xarray tags on folios skipped during writeback

  * [UBUNTU 22.04] s390/topology: Use zero-based numbering (LP: #2164516)
    - s390/topology: Use zero-based numbering for containing entities

  * [HP][ZBook Power 16 G11] Laptop freezed after upgrading the BIOS
    (LP: #2132119)
    - PCI/ASPM: Avoid L0s for Realtek RTS525A

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796)
    - netfilter: bitwise: rename some boolean operation functions
    - netfilter: bitwise: add support for doing AND, OR and XOR directly
    - drm/fbdev-helper: Set and clear VGA switcheroo client from fb_info
    - arm64: io: Rename ioremap_prot() to __ioremap_prot()
    - Disable -Wattribute-alias for clang-23 and newer
    - netfilter: xt_NFQUEUE: prefer raw_smp_processor_id
    - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c
    - pcnet32: stop holding device spin lock during napi_complete_done
    - net: Annotate sk->sk_write_space() for UDP SOCKMAP.
    - net: lan743x: permit VLAN-tagged packets up to configured MTU
    - net: fec: fix pinctrl default state restore order on resume
    - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame()
      extension handling
    - Bluetooth: MGMT: Fix backward compatibility with userspace
    - ptp: vclock: Switch from RCU to SRCU
    - octeontx2-af: npc: Fix CPT channel mask in npc_install_flow
    - vxlan: vnifilter: send notification on VNI add
    - vxlan: vnifilter: fix spurious notification on VNI update
    - ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp
    - time: Fix off-by-one in settimeofday() usec validation
    - tools/rv: Fix cleanup after failed trace setup
    - arm64: tlb: Allow XZR argument to TLBI ops
    - iomap: don't revert iov_iter on partially completed buffered writes
    - net/mlx4: avoid GCC 10 __bad_copy_from() false positive
    - r8152: handle the return value of usb_reset_device()
    - rds: mark snapshot pages dirty in rds_info_getsockopt()
    - net: mvpp2: Add metadata support for xdp mode
    - net: mvpp2: build skb from XDP-adjusted data on XDP_PASS
    - clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time
    - tracing/probes: Point the error offset correctly for eprobe argument
      error
    - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation
    - USB: serial: option: add usb-id for Dell Wireless DW5826e-m
    - ALSA: timer: Fix UAF at snd_timer_user_params()
    - drm/amd/display: Reject gpio_bitshift >= 32 in
      bios_parser_get_gpio_pin_info()
    - mm/damon/ops-common: call folio_test_lru() after folio_get()
    - ARM: socfpga: Fix OF node refcount leak in SMP setup
    - ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O
    - mptcp: fix retransmission loop when csum is enabled
    - mptcp: sockopt: check timestamping ret value
    - selftests: mptcp: add test for extra_subflows underflow on userspace PM
    - ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write
    - inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
    - pidfd: refuse access to tasks that have started exiting harder
    - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter
    - i2c: tegra: Fix NOIRQ suspend/resume
    - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK)
    - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard
    - net/mlx5: Reorder completion before putting command entry in
      cmd_work_handler
    - net: mv643xx: fix OF node refcount
    - octeontx2-af: fix memory leak in rvu_setup_hw_resources()
    - mmc: core: Fix host controller programming for fixed driver type
    - mmc: litex_mmc: Set mandatory idle clocks before CMD0
    - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC
    - mmc: sdhci: add signal voltage switch in sdhci_resume_host
    - slimbus: qcom-ngd-ctrl: fix OF node refcount
    - drm/amdgpu: restart the CS if some parts of the VM are still invalidated
    - fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
    - driver core: reject devices with unregistered buses
    - mm/hugetlb: avoid false positive lockdep assertion
    - soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get()
    - ipmi:ssif: Remove unnecessary indention
    - ipmi:ssif: NULL thread on error
    - selftests: mptcp: drop nanoseconds width specifier
    - tty: serial: samsung: use u32 for register interactions
    - RDMA/umem: fix kernel-doc warnings
    - RDMA: Move DMA block iterator logic into dedicated files
    - arm64: cputype: Add NVIDIA Olympus definitions
    - arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU
    - mptcp: add-addr: always drop other suboptions
    - mptcp: fix missing wakeups in edge scenarios
    - Revert "selftest/ptp: update ptp selftest to exercise the gettimex
      options"
    - ARM: fix hash_name() fault
    - wifi: remove zero-length arrays
    - soc: qcom: ice: Return -ENODEV if the ICE platform device is not found
    - Bluetooth: ISO: Fix not using bc_sid as advertisement SID
    - octeontx2-pf: Fix NDC sync operation errors
    - octeontx2-af: Fix initialization of mcam's entry2target_pffunc field
    - ima: kexec: skip IMA segment validation after kexec soft reboot
    - ima: kexec: move IMA log copy from kexec load to execute
    - gpio: zynq: fix runtime PM leak on remove
    - writeback: Avoid contention on wb->list_lock when switching inodes
    - writeback: Fix use after free in inode_switch_wbs_work_fn()
    - xfrm: hold device only for the asynchronous decryption
    - KVM: VMX: Update SVI during runtime APICv activation
    - drm/xe: fix refcount leak in xe_range_fence_insert()
    - slimbus: qcom-ngd-ctrl: Fix up platform_driver registration
    - slimbus: qcom-ngd-ctrl: Fix probe error path ordering
    - slimbus: qcom-ngd-ctrl: Initialize controller resources in controller
    - slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership
    - slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD
    - drm/amd/pm: fix smu13 power limit default/cap calculation
    - drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in
      set_soft_freq_limited_range
    - drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs
    - mailbox: Fix NULL message support in mbox_send_message()
    - vsock/virtio: fix skb overhead accounting to preserve full buf_alloc
    - net: introduce EXPORT_IPV6_MOD() and EXPORT_IPV6_MOD_GPL()
    - mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation
    - vsock/virtio: fix skb overhead overflow on 32-bit builds
    - Upstream stable to v6.6.143, v6.12.94

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53132
    - vsock/virtio: fix potential unbounded skb queue

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53138
    - drm/amd/display: Bound VBIOS record-chain walk loops

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53140
    - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53332
    - slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53156
    - nvmem: core: fix use-after-free bugs in error paths

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53202
    - accel/ivpu: Fix signed integer truncation in IPC receive

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53205
    - accel/ivpu: Add bounds checks for firmware log indices

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53210
    - tee: shm: fix shm leak in register_shm_helper()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-31663
    - xfrm: hold dev ref until after transport_finish NF_HOOK

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53220
    - netfilter: revalidate bridge ports

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53229
    - net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-46203
    - spi: cadence-quadspi: fix unclocked access on unbind

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-63871
    - Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53251
    - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-63869
    - wifi: mac80211: limit injected antenna index in
      ieee80211_parse_tx_radiotap

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53261
    - devlink: Release nested relation on devlink free

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53262
    - l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2025-10263. The existing ARM64_ERRATUM_4118414 handling already uses
    - arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-45850
    - ipvs: skip ipv6 extension headers for csum checks

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53133
    - RDMA/umem: Fix truncation for block sizes >= 4G

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-52908
    - RDMA: During rereg_mr ensure that REREG_ACCESS is compatible

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53199
    - hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53134
    - netfilter: nft_fib: fix stale stack leak via the OIFNAME register

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-63883
    - serial: qcom_geni: fix kfifo underflow when flush precedes DMA
      completion IRQ

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-64528
    - tty: serial: samsung: Remove redundant port lock acquisition in rx
      helpers

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53329
    - drm/amd/display: Use krealloc_array() in dal_vector_reserve()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53135
    - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53136
    - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53137
    - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53143
    - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on
      GFX11

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53144
    - drm/amdkfd: fix NULL dereference in get_queue_ids()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53331
    - slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53146
    - thunderbolt: Limit XDomain response copy to actual frame size

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53147
    - thunderbolt: Validate XDomain request packet size before type cast

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53148
    - thunderbolt: Clamp XDomain response data copy to allocation size

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53149
    - thunderbolt: Bound root directory content to block size

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53150
    - thunderbolt: Reject zero-length property entries in validator

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-52929
    - sctp: stream: fully roll back denied add-stream state

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-52917
    - sctp: diag: reject stale associations in dump_one path

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53154
    - mm/hugetlb: restore reservation on error in hugetlb folio copy paths

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53336
    - nvmem: layouts: onie-tlv: fix hang on unknown types

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53337
    - net: bonding: fix NULL pointer dereference in bond_do_ioctl()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53158
    - misc: fastrpc: Fix NULL pointer dereference in rpmsg callback

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53159
    - misc: fastrpc: fix DMA address corruption due to find_vma misuse

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53160
    - misc: fastrpc: fix use-after-free race in fastrpc_map_create

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53161
    - misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-52930
    - ipc/shm: serialize orphan cleanup with shm_nattch updates

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53339
    - i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53168
    - fuse: reject fuse_notify() pagecache ops on directories

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53177
    - bnxt_en: Fix NULL pointer dereference

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53181
    - vsock/vmci: fix sk_ack_backlog leak on failed handshake

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53182
    - wifi: nl80211: reject oversized EMA RNR lists

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53183
    - mptcp: allow subflow rcv wnd to shrink

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-63867
    - mptcp: close TOCTOU race while computing rcv_wnd

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53343
    - ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53184
    - udp: clear skb->dev before running a sockmap verdict

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53185
    - zram: fix use-after-free in zram_bvec_write_partial()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53190
    - drm/virtio: fix dma_fence refcount leak on error in
      virtio_gpu_dma_fence_wait()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53194
    - USB: serial: kl5kusb105: fix bulk-out buffer overflow

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53195
    - USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53196
    - USB: serial: io_ti: fix heap overflow in get_manuf_info()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-52935
    - xfrm: espintcp: do not reuse an in-progress partial send

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53198
    - ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53356
    - drm/i915/gem: Fix phys BO pread/pwrite with offset

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53345
    - KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53208
    - Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53209
    - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53213
    - drm/vc4: fix krealloc() memory leak

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53347
    - drm/virtio: Fix driver removal with disabled KMS

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-43116
    - netfilter: ctnetlink: ensure safe access to master conntrack

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53214
    - ipv6: Fix a potential NPD in cleanup_prefix_route()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53217
    - net: mvpp2: sync RX data at the hardware packet offset

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53218
    - netfilter: nft_exthdr: fix register tracking for F_PRESENT flag

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-52942
    - netfilter: nf_log: validate MAC header was set before dumping it

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53219
    - netfilter: x_tables: avoid leaking percpu counter pointers

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53349
    - netfilter: nf_conntrack: destroy stale expectfn expectations on
      unregister

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-52939
    - net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic
      completion

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53223
    - net: guard timestamp cmsgs to real error queue skbs

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53227
    - net: openvswitch: fix possible kfree_skb of ERR_PTR

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53230
    - net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-52947
    - net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53232
    - net: phy: clean the sfp upstream if phy probing fails

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53236
    - tcp: restrict SO_ATTACH_FILTER to priv users

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53350
    - ASoC: wm_adsp: Fix NULL dereference when removing firmware controls

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53237
    - gpio: mvebu: fix NULL pointer dereference in suspend/resume

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53238
    - netlabel: validate unlabeled address and mask attribute lengths

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53239
    - xfrm: policy: fix use-after-free on inexact bin in
      xfrm_policy_bysel_ctx()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-46320
    - tap: free page on error paths in tap_get_user_xdp()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53242
    - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked
      streams

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53352
    - signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53245
    - net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-63870
    - ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53249
    - ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53252
    - Bluetooth: fix memory leak in error path of hci_alloc_dev()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53253
    - Bluetooth: bnep: reject short frames before parsing

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53254
    - Bluetooth: RFCOMM: validate skb length in MCC handlers

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53255
    - Bluetooth: MGMT: validate advertising TLV before type checks

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53256
    - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-63868
    - net: garp: fix unsigned integer underflow in garp_pdu_parse_attr

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53353
    - hsr: Remove WARN_ONCE() in hsr_addr_is_self().

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53263
    - 6lowpan: fix off-by-one in multicast context address compression

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53264
    - net/sched: act_api: use RCU with deferred freeing for action lifecycle

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53265
    - dm cache policy smq: check allocation under invalidate lock

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53266
    - netfilter: bridge: make ebt_snat ARP rewrite writable

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53267
    - netfilter: nft_ct: bail out on template ct in get eval

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53268
    - netfilter: conntrack_irc: fix possible out-of-bounds read

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53269
    - netfilter: synproxy: add mutex to guard hook reference counting

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53270
    - ipvs: clear the svc scheduler ptr early on edit

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53273
    - tee: optee: prevent use-after-free when the client exits before the
      supplicant

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53274
    - net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-53275
    - ipv6: mcast: Fix use-after-free when processing MLD queries

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-52948
    - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-63898
    - USB: serial: mct_u232: fix memory corruption with small endpoint

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-52910
    - bpf: Free reuseport cBPF prog after RCU grace period.

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-43311
    - soc/tegra: pmc: Fix unsafe generic_handle_irq() call

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-43240
    - x86/kexec: add a sanity check on previous kernel's ima kexec buffer

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-23346
    - arm64: io: Extract user memory type in ioremap_prot()

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2025-68296
    - drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-52944
    - ksmbd: fix FSCTL permission bypass by adding a permission check for
      FSCTL_SET_SPARSE

  * Noble update: upstream stable patchset 2026-08-21 (LP: #2164796) //
    CVE-2026-64006
    - netfilter: nf_tables: fix dst corruption in same register operation

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547)
    - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size
    - drm/v3d: Fix use-after-free of CPU job query arrays on error path
    - drm/v3d: Release indirect CSD GEM reference on CPU job free
    - xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
    - net/sched: sch_sfb: Replace direct dequeue call with peek and
      qdisc_dequeue_peeked
    - bcache: fix uninitialized closure object
    - nfc: llcp: Fix use-after-free in llcp_sock_release()
    - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()
    - xfrm: Check for underflow in xfrm_state_mtu
    - nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems
    - kunit: fix use-after-free in debugfs when using kunit.filter
    - netfilter: xt_cpu: prefer raw_smp_processor_id
    - vsock: keep poll shutdown state consistent
    - net: netlink: fix sending unassigned nsid after assigned one
    - net: netlink: don't set nsid on local notifications
    - net/smc: Do not re-initialize smc hashtables
    - net/iucv: fix locking in .getsockopt
    - scsi: core: Run queues for all non-SDEV_DEL devices from
      scsi_run_host_queues
    - ipv4: free net->ipv4.sysctl_local_reserved_ports after
      unregister_net_sysctl_table()
    - ALSA: pcm: oss: Fix setup list UAF on proc write error
    - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors
    - gpio: mxc: fix irq_high handling
    - ethtool: rss: fix hkey leak when indir_size is 0
    - ASoC: codecs: simple-mux: Fix enum control bounds check
    - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()
    - bonding: refuse to enslave CAN devices
    - ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during
      fallback
    - ethtool: eeprom: add more safeties to EEPROM Netlink fallback
    - net/sched: Revert "net/sched: Restrict conditions for adding duplicating
      netems to qdisc tree"
    - net/handshake: Use spin_lock_bh for hn_lock
    - nvme-tcp: store negative errno in queue->tls_err
    - net/handshake: Pass negative errno through handshake_complete()
    - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success
    - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
    - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
    - gpio: rockchip: convert bank->clk to devm_clk_get_enabled()
    - net: mana: Add NULL guards in teardown path to prevent panic on attach
      failure
    - sctp: fix race between sctp_wait_for_connect and peeloff
    - ipv6: fix possible infinite loop in rt6_fill_node()
    - ipv6: fix possible infinite loop in fib6_select_path()
    - net: skbuff: fix pskb_carve leaking zcopy pages
    - perf: Fix dangling cgroup pointer in cpuctx
    - batman-adv: tvlv: abort OGM send on tvlv append failure
    - batman-adv: tt: reject oversized local TVLV buffers
    - batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface
    - batman-adv: iv: recover OGM scheduling after forward packet error
    - batman-adv: tp_meter: avoid role confusion in tp_list
    - batman-adv: tp_meter: directly shut down timer on cleanup
    - batman-adv: tt: avoid empty VLAN responses
    - batman-adv: bla: avoid double decrement of bla.num_requests
    - media: rc: fix race between unregister and urb/irq callbacks
    - media: rc: ttusbir: fix inverted error logic
    - inet: frags: add inet_frag_queue_flush()
    - HID: core: Add printk_ratelimited variants to hid_warn() etc
    - drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register
    - drm/i915/psr: Read Intel DPCD workaround register
    - drm/dp: Add eDP 1.5 bit definition
    - drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used
    - phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X
    - batman-adv: tt: prevent TVLV entry number overflow
    - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer
    - usb: typec: ucsi: ccg: reject firmware images without a ':' record
      header
    - usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload
      VDO
    - usb: typec: altmodes/displayport: validate count before reading Status
      Update VDO
    - usb: typec: wcove: don't write past struct pd_message in
      wcove_read_rx_buffer()
    - usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
    - usb: typec: ucsi: validate connector number in ucsi_connector_change()
    - USB: serial: safe_serial: fix memory corruption with small endpoint
    - media: rc: igorplugusb: fix control request setup packet
    - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free()
    - HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse
    - Bluetooth: btusb: Allow firmware re-download when version matches
    - hpfs: fix a crash if hpfs_map_dnode_bitmap fails
    - auxdisplay: line-display: fix OOB read on zero-length message_store()
    - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn
    - Bluetooth: HIDP: fix missing length checks in hidp_input_report()
    - Bluetooth: ISO: fix UAF in iso_recv_frame
    - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock
    - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync
    - Input: xpad - fix out-of-bounds access for Share button
    - parport: Fix race between port and client registration
    - USB: cdc-acm: Fix bit overlap and move quirk definitions to header
    - KVM: arm64: PMU: Preserve AArch32 counter low bits
    - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC
    - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux
    - iio: adc: npcm: fix unbalanced clk_disable_unprepare()
    - iio: dac: max5821: fix return value check in powerdown sync
    - iio: dac: ad5686: fix input raw value check
    - iio: dac: ad5686: acquire lock when doing powerdown control
    - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw
    - iio: gyro: itg3200: fix i2c read into the wrong stack location
    - iio: gyro: adis16260: fix division by zero in write_raw
    - iio: ssp_sensors: cancel delayed work_refresh on remove
    - iio: temperature: tsys01: fix broken PROM checksum validation
    - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL
    - iio: light: cm3323: fix reg_conf not being initialized correctly
    - iio: buffer: hw-consumer: fix use-after-free in error path
    - USB: serial: omninet: fix memory corruption with small endpoint
    - usb: cdns3: gadget: fix request skipping after clearing halt
    - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy
      acquisition failure
    - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently
      leaks the runtime PM usage counter across bind/unbind cycles
    - usb: dwc2: Fix use after free in debug code
    - Input: elan_i2c - validate firmware size before use
    - wireguard: send: append trailer after expanding head
    - bpf: sockmap: fix tail fragment offset in bpf_msg_push_data
    - macsec: fix replay protection at XPN lower-PN wrap
    - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params
    - ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().
    - ipv6: validate extension header length before copying to cmsg
    - xfrm: input: hold netns during deferred transport reinjection
    - ip6: vti: Use ip6_tnl.net in vti6_changelink().
    - HID: wacom: Fix OOB write in wacom_hid_set_device_mode()
    - iommu, debugobjects: avoid gcc-16.1 section mismatch warnings
    - nfc: hci: fix out-of-bounds read in HCP header parsing
    - xfrm: route MIGRATE notifications to caller's netns
    - xfrm: ah: use skb_to_full_sk in async output callbacks
    - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417
    - netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without
      direction check
    - ASoC: qcom: q6asm-dai: close stream only when running
    - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger
      callbacks
    - Input: xpad - add "Nova 2 Lite" from GameSir
    - Input: xpad - add support for ASUS ROG RAIKIRI II
    - ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops
    - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem
    - Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490
    - comedi: comedi_test: fix check for valid scan_begin_src in
      waveform_ai_cmdtest()
    - comedi: comedi_test: Fix limiting of convert_arg in
      waveform_ai_cmdtest()
    - counter: Fix refcount leak in counter_alloc() error path
    - tty: serial: pch_uart: add check for dma_alloc_coherent()
    - usb: chipidea: core: convert ci_role_switch to local variable
    - usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval
    - USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub
      controllers
    - usb: storage: Add quirks for PNY Elite Portable SSD
    - usbip: vudc: Fix use after free bug in vudc_remove due to race condition
    - usb: usbtmc: check URB actual_length for interrupt-IN notifications
    - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize
    - USB: serial: option: add MeiG SRM813Q
    - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL
    - USB: serial: belkin_sa: validate interrupt status length
    - USB: serial: cypress_m8: validate interrupt packet headers
    - USB: serial: keyspan: fix missing indat transfer sanity check
    - USB: serial: mxuport: fix memory corruption with small endpoint
    - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check
    - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind
    - usb: gadget: net2280: Fix double free in probe error path
    - usb: gadget: f_hid: fix device reference leak in hidg_alloc()
    - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling
    - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports
    - usb: gadget: f_fs: copy only received bytes on short ep0 read
    - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()
    - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow
    - scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker
    - scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32
    - drm/hyperv: validate resolution_count and fix WIN8 fallback
    - drm/hyperv: validate VMBus packet size in receive callback
    - drm/i915: Fix potential UAF in TTM object purge
    - drm/amd/pm/si: Disregard vblank time when no displays are connected
    - serial: altera_jtaguart: handle uart_add_one_port() failures
    - serial: qcom-geni: fix UART_RX_PAR_EN bit position
    - serial: sh-sci: fix memory region release in error path
    - serial: zs: Fix swapped RI/DSR modem line transition counting
    - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma
    - drm/amdkfd: fix NULL pointer bug in svm_range_set_attr
    - drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
    - drm/amdkfd: Check for pdd drm file first in CRIU restore path
    - serial: dz: Fix bootconsole message clobbering at chip reset
    - serial: dz: Fix bootconsole handover lockup
    - serial: dz: Convert to use a platform device
    - serial: zs: Fix bootconsole handover lockup
    - serial: zs: Switch to using channel reset
    - serial: zs: Convert to use a platform device
    - USB: serial: cypress_m8: fix memory corruption with small endpoint
    - USB: serial: digi_acceleport: fix memory corruption with small endpoints
    - xhci: tegra: Fix ghost USB device on dual-role port unplug
    - iommu: Skip PASID validation for devices without PASID capability
    - x86/boot: Disable stack protector for early boot code
    - rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg
    - rxrpc: Fix RESPONSE packet verification to extract skb to a linear
      buffer
    - serdev: Provide a bustype shutdown function
    - Bluetooth: hci_qca: Migrate to serdev specific shutdown function
    - Bluetooth: hci_qca: Convert timeout from jiffies to ms
    - ALSA: scarlett2: Return ENOSPC for out-of-bounds flash writes
    - ALSA: scarlett2: Allow flash writes ending at segment boundary
    - mm/memory: fix spurious warning when unmapping device-private/exclusive
      pages
    - platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery
    - net: hsr: defer node table free until after RCU readers
    - mptcp: pm: fix ADD_ADDR timer infinite retry on option space
      insufficient
    - ice: fix VF queue configuration with low MTU values
    - mptcp: cleanup fallback dummy mapping generation
    - mptcp: reset rcv wnd on disconnect
    - arm64: tlb: Flush walk cache when unsharing PMD tables
    - octeontx2-pf: avoid double free of pool->stack on AQ init failure
    - mptcp: introduce the mptcp_init_skb helper
    - mptcp: handle first subflow closing consistently
    - mptcp: do not drop partial packets
    - mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()
    - iio: chemical: scd30: Use guard(mutex) to allow early returns
    - iio: chemical: scd30: fix division by zero in write_raw
    - iio: dac: ad5686: fix ref bit initialization for single-channel parts
    - ALSA: firewire-motu: Protect register DSP event queue positions
    - usb: dwc3: xilinx: fix error handling in zynqmp init error paths
    - usb: musb: omap2430: Fix use-after-free in omap2430_probe()
    - usb: typec: ucsi: Check if power role change actually happened before
      handling
    - thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()
    - usb: typec: ucsi: Don't update power_supply on power role change if not
      connected
    - hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with
      pmbus_lock
    - hwmon: (pmbus/adm1266) serialize NVMEM blackbox read with pmbus_lock
    - hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock
    - mm: perform all memfd seal checks in a single place
    - mm/memfd: fix spelling and grammatical issues
    - memfd: deny writeable mappings when implying SEAL_WRITE
    - usb: core: Fix SuperSpeed root hub wMaxPacketSize
    - Upstream stable to v6.12.93

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-43331
    - x86/kexec: Disable KCOV instrumentation after load_segments()

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-52943
    - net: skbuff: fix missing zerocopy reference in pskb_carve helpers

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-53358
    - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-52923
    - ipc: limit next_id allocation to the valid ID range

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2025-68768
    - inet: frags: flush pending skbs in fqdir_pre_exit()

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-43303
    - mm/page_alloc: clear page->private in free_pages_prepare()

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-52934
    - batman-adv: tvlv: reject oversized TVLV packets

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-52913
    - batman-adv: v: stop OGMv2 on disabled interface

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-46322
    - tun: free page on build_skb failure in tun_xdp_one()

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-46321
    - tun: free page on short-frame rejection in tun_xdp_one()

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-52927
    - netfilter: ebtables: fix OOB read in compat_mtw_from_user

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-43219
    - net: cpsw_new: Fix potential unregister of netdev that has not been
      registered yet

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-45930
    - net: mctp: ensure our nlmsg responses are initialised

  * Noble update: upstream stable patchset 2026-07-22 (LP: #2161547) //
    CVE-2026-53080
    - net/sched: cls_fw: fix NULL dereference of "old" filters before change()

  * CVE-2025-10263 // CVE-2026-53354
    - arm64: errata: Mitigate TLBI errata on various Arm CPUs
    - [Config] Enable CONFIG_ARM64_ERRATUM_4118414

  * CVE-2025-10263
    - arm64: cputype: Add C1-Ultra definitions
    - arm64: cputype: Add C1-Premium definitions

  * CVE-2026-53355
    - net: rds: clear i_sends on setup unwind

  * CVE-2026-53186
    - RDMA/srp: bound SRP_RSP sense copy by the received length

  * CVE-2026-53216
    - net: mvpp2: limit XDP frame size to the RX buffer

  * CVE-2026-63888
    - scsi: target: iscsi: Fix CRC overread and double-free in
      iscsit_handle_text_cmd()

  * CVE-2026-63886
    - scsi: target: iscsi: Validate CHAP_R length before base64 decode

  * CVE-2026-63887
    - scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf

  * CVE-2026-63912
    - xfrm: esp: restore combined single-frag length gate

  * CVE-2026-63922
    - ipv6: exthdrs: refresh nh after handling HAO option

  * CVE-2026-63924
    - ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()

  * CVE-2026-64091
    - batman-adv: tt: fix TOCTOU race for reported vlans

  * CVE-2026-63984
    - ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()

  * CVE-2026-63992
    - tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()

  * CVE-2026-63993
    - vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()

  * CVE-2026-63994
    - tunnels: load network headers after skb_cow() in
      iptunnel_pmtud_build_icmp[v6]()

  * CVE-2026-64000
    - net: hsr: fix potential OOB access in supervision frame handling

  * CVE-2026-64007
    - netfilter: synproxy: refresh tcphdr after skb_ensure_writable

  * CVE-2026-53221
    - ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()

  * CVE-2026-53131
    - netfilter: require Ethernet MAC header before using eth_hdr()

 -- Edoardo Canepa <[email protected]>  Thu, 03 Sep 2026
17:47:58 +0300

** Changed in: linux (Ubuntu Noble)
       Status: Fix Committed => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2025-10263

** CVE added: https://cve.org/CVERecord?id=CVE-2025-68296

** CVE added: https://cve.org/CVERecord?id=CVE-2025-68768

** CVE added: https://cve.org/CVERecord?id=CVE-2026-23346

** CVE added: https://cve.org/CVERecord?id=CVE-2026-31663

** CVE added: https://cve.org/CVERecord?id=CVE-2026-43116

** CVE added: https://cve.org/CVERecord?id=CVE-2026-43219

** CVE added: https://cve.org/CVERecord?id=CVE-2026-43240

** CVE added: https://cve.org/CVERecord?id=CVE-2026-43303

** CVE added: https://cve.org/CVERecord?id=CVE-2026-43311

** CVE added: https://cve.org/CVERecord?id=CVE-2026-43331

** CVE added: https://cve.org/CVERecord?id=CVE-2026-45850

** CVE added: https://cve.org/CVERecord?id=CVE-2026-45930

** CVE added: https://cve.org/CVERecord?id=CVE-2026-46203

** CVE added: https://cve.org/CVERecord?id=CVE-2026-46320

** CVE added: https://cve.org/CVERecord?id=CVE-2026-46321

** CVE added: https://cve.org/CVERecord?id=CVE-2026-46322

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52908

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52910

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52913

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52917

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52923

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52927

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52929

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52930

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52934

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52935

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52939

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52942

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52943

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52944

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52947

** CVE added: https://cve.org/CVERecord?id=CVE-2026-52948

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53080

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53131

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53132

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53133

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53134

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53135

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53136

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53137

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53138

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53140

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53143

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53144

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53146

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53147

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53148

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53149

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53150

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53154

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53156

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53158

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53159

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53160

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53161

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53168

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53177

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53181

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53182

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53183

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53184

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53185

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53186

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53190

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53194

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53195

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53196

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53198

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53199

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53202

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53205

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53208

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53209

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53210

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53213

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53214

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53216

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53217

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53218

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53219

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53220

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53221

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53223

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53227

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53229

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53230

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53232

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53236

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53237

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53238

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53239

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53242

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53245

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53249

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53251

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53252

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53253

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53254

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53255

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53256

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53261

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53262

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53263

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53264

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53265

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53266

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53267

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53268

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53269

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53270

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53273

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53274

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53275

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53329

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53331

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53332

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53336

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53337

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53339

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53343

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53345

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53347

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53349

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53350

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53352

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53353

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53354

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53355

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53356

** CVE added: https://cve.org/CVERecord?id=CVE-2026-53358

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63867

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63868

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63869

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63870

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63871

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63883

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63886

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63887

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63888

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63898

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63912

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63922

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63924

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63984

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63992

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63993

** CVE added: https://cve.org/CVERecord?id=CVE-2026-63994

** CVE added: https://cve.org/CVERecord?id=CVE-2026-64000

** CVE added: https://cve.org/CVERecord?id=CVE-2026-64006

** CVE added: https://cve.org/CVERecord?id=CVE-2026-64007

** CVE added: https://cve.org/CVERecord?id=CVE-2026-64091

** CVE added: https://cve.org/CVERecord?id=CVE-2026-64528

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2164716

Title:
  Reboot machine with ext4 configured to data=journal could dump
  spurious call trace

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2164716/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to