Public bug reported:

Please backport the following upstream Linux kernel CVE fixes in the next
Ubuntu 24.04 LTS (noble) linux-nvidia-tegra 6.8 update and publish the
corresponding USN.

Canonical’s current linux-nvidia-tegra package 6.8.0-1031.32 does not contain
the listed upstream fixes.

CVE-2026-53246
Fix: 0861615c28de668669d748ef4eb913ea9262d13b
sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing

CVE-2026-63984
Fix: 9d5e7a46a9f6d8f503b41bfefef70659845f1679
ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()

CVE-2026-64387
Fix: 9647492b5e41954be59d5157eddbcd4cdc1656f7
smb: client: fix query directory replay double-free

CVE-2026-64534
Fix: 4606467a75cfc16721937272ed29462a750b60c8
nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path

CVE-2026-64535
Fix: dbbd07d0a7020b80f6a7028e561908f7b83b3d5a
nvmet-tcp: fix potential UAF when ddgst mismatch

CVE-2026-64564
Fix: 9b2854f86f0b56e9027d68e7a3fc909d1a9b566f
sctp: don't free the ASCONF's own transport in DEL-IP processing

CVE-2026-64382
Fix: b55e182f2324bc6a604c21a47aa6c448f719a532
smb: client: fix double-free in SMB2_open() replay

CVE-2026-64552
Fix: 9e5ad06ea826322ce8c58b4a68442a96f600c3c4
virtio-net: fix len check in receive_big()

CVE-2026-53391
Fix: 41fe0f7b84f0cb822ae10ab08592996a592b2a25
NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr

CVE-2026-64111
Fix: 4a9b16541ad3faf8bccb398532bf3f8b6bbf1188
lsm: hold cred_guard_mutex for lsm_set_self_attr()

CVE-2026-53091
Fix: 7fb4c19670110f052c04e1ec1d2b953b9f4f57e4
net: pull headers in qdisc_pkt_len_segs_init()

CVE-2026-45850
Fix: 05cfe9863ef049d98141dc2969eefde72fb07625
ipvs: skip ipv6 extension headers for csum checks

CVE-2026-31692
Fix: 7b735ef81286007794a227ce2539419479c02a5f
rtnetlink: add missing netlink_ns_capable() check for peer netns

CVE-2025-68188
Fix: b62a59c18b692f892dcb8109c1c2e653b2abc95c
tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check()

Ubuntu release: 24.04 LTS (Noble)
Source package: linux-nvidia-tegra
Canonical package version reviewed: 6.8.0-1031.32

Expected result:
The listed upstream CVE fixes are included in the next Noble
linux-nvidia-tegra update and published in a corresponding USN.

Actual result:
The listed fixes remain absent from Canonical linux-nvidia-tegra
6.8.0-1031.32.

** Affects: linux-nvidia-tegra (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163482

Title:
  [SRU][noble] linux-nvidia-tegra 6.8: backport outstanding upstream CVE
  fixes missing in 6.8.0-1031.32

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux-nvidia-tegra/+bug/2163482/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to