Public bug reported:

    SRU Justification

    Impact:
       The upstream process for stable tree updates is quite similar
       in scope to the Ubuntu SRU process, e.g., each patch has to
       demonstrably fix a bug, and each patch is vetted by upstream
       by originating either directly from a mainline/stable Linux tree or
       a minimally backported form of that patch. The following upstream
       stable patches should be included in the Ubuntu kernel:

       v5.15.220 upstream stable release
       from git://git.kernel.org/

RDMA/rxe: Fix OOB in free_rd_atomic_resources()
ext4: don't enable DAX on new encrypted files
io_uring/io-wq: fix worker accounting when canceling creation callbacks
ipvs: reload ip header after head reallocation
bpf: Remove tst_run from lwt_seg6local_prog_ops.
jfs: add check read-only before truncation in jfs_truncate_nolock()
jfs: add check read-only before txBeginAnon() call
can: j1939: implement NETDEV_UNREGISTER notification handler
can: j1939: add missing calls in NETDEV_UNREGISTER notification handler
can: j1939: make j1939_sk_bind() fail if device is no longer registered
KVM: arm64: Prevent access to vCPU events before init
bpf: Fix use-after-free in offloaded map/prog info fill
Revert "PM: sleep: Use complete() in device_pm_sleep_init()"
smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk().
selinux: switch two allocations to use kzalloc_objs()
ALSA: pcm: fix wait_time calculations
ASoC: tegra: Fix Master Volume Control
ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain()
ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
kcov: replace local_irq_save() with a local_lock_t
kcov: fix data corruption and race conditions on PREEMPT_RT
ext4: propagate errors from fast commit range replay
nilfs2: correct return value kernel-doc descriptions for ioctl functions
nilfs2: reject invalid block index in GC ioctl
nfc: nci: add data_len bound checks to activation parameter extractors
HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
nvme: rename CDR/MORE/DNR to NVME_STATUS_*
nvmet-tcp: bound SGL data length before allocating command buffers
HID: uclogic: fix use-after-free of inrange_timer on remove
HID: ft260: fix i2c probing for hwmon devices
HID: ft260: improve i2c write performance
HID: ft260: improve i2c large reads performance
HID: ft260: skip unexpected HID input reports
HID: ft260: wake up device from power saving mode
HID: ft260: missed NACK from busy device
HID: ft260: validate i2c input report length
HID: ft260: fix stack-use-after-return write in I2C read race
HID: input: read battery capacity from its actual report offset
fpga: dfl: fme: add error handling
accessibility: speakup: unregister tty ldisc on later init failures
xhci: dbgtty: Fix unregister on tty_register_driver() failure
xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
fuse: fix invalidate lock leak on setattr writeback failure
fuse: fix invalidate lock leak on open O_TRUNC DAX failure
usb: usbtest: disable dynamic ID support
usb: gadget: f_tcm: keep port count until LUN teardown completes
xfrm: espintcp: fix UAF during close
xfrm: drop ESP-in-TCP packets with no ingress device
xfrm: ah6: validate routing header segments_left
xfrm: fix xfrm_state_construct() auth-trunc leak
net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
ipv6: seg6: clear IPv4 control block on IPIP decapsulation
mm/swap: reject swapon() on filesystem-level encrypted files
crypto: atmel-tdes - use scatterlist length before DMA mapping
crypto: qce - fix CCM AAD buffer underallocation
crypto: mxs-dcp - fix source scatterlist length access
crypto: qce - Remove unsafe/deprecated algorithms
KVM: s390: vsie: zero stale crypto bits
usb: core: Add lock to usb_wakeup_notification()
usb: core: Strengthen error handling in hub_hub_status()
ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
ALSA: usb-audio: Complete cleanup after system-resume errors
USB: serial: option: fix slab OOB read in interrupt URB callback
USB: serial: spcp8x5: drop broken carrier detect support
USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
usb: usbfs: fix use-after-free of usb_device in usbdev_release()
Linux 5.15.220
UBUNTU: Upstream stable to v5.15.220

** Affects: linux (Ubuntu)
     Importance: Undecided
         Status: Invalid

** Affects: linux (Ubuntu Jammy)
     Importance: Medium
     Assignee: Vinicius Peixoto (vpeixoto)
         Status: In Progress


** Tags: kernel-stable-tracking-bug

** Changed in: linux (Ubuntu)
       Status: New => Confirmed

** Also affects: linux (Ubuntu Jammy)
   Importance: Undecided
       Status: New

** Changed in: linux (Ubuntu)
       Status: Confirmed => Invalid

** Changed in: linux (Ubuntu Jammy)
   Importance: Undecided => Medium

** Changed in: linux (Ubuntu Jammy)
       Status: New => In Progress

** Changed in: linux (Ubuntu Jammy)
     Assignee: (unassigned) => Vinicius Peixoto (vpeixoto)

** Description changed:

  
      SRU Justification
  
      Impact:
         The upstream process for stable tree updates is quite similar
         in scope to the Ubuntu SRU process, e.g., each patch has to
         demonstrably fix a bug, and each patch is vetted by upstream
         by originating either directly from a mainline/stable Linux tree or
         a minimally backported form of that patch. The following upstream
         stable patches should be included in the Ubuntu kernel:
  
         v5.15.220 upstream stable release
         from git://git.kernel.org/
  
-             
+ RDMA/rxe: Fix OOB in free_rd_atomic_resources()
+ ext4: don't enable DAX on new encrypted files
+ io_uring/io-wq: fix worker accounting when canceling creation callbacks
+ ipvs: reload ip header after head reallocation
+ bpf: Remove tst_run from lwt_seg6local_prog_ops.
+ jfs: add check read-only before truncation in jfs_truncate_nolock()
+ jfs: add check read-only before txBeginAnon() call
+ can: j1939: implement NETDEV_UNREGISTER notification handler
+ can: j1939: add missing calls in NETDEV_UNREGISTER notification handler
+ can: j1939: make j1939_sk_bind() fail if device is no longer registered
+ KVM: arm64: Prevent access to vCPU events before init
+ bpf: Fix use-after-free in offloaded map/prog info fill
+ Revert "PM: sleep: Use complete() in device_pm_sleep_init()"
+ smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk().
+ selinux: switch two allocations to use kzalloc_objs()
+ ALSA: pcm: fix wait_time calculations
+ ASoC: tegra: Fix Master Volume Control
+ ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain()
+ ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
+ ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
+ kcov: replace local_irq_save() with a local_lock_t
+ kcov: fix data corruption and race conditions on PREEMPT_RT
+ ext4: propagate errors from fast commit range replay
+ nilfs2: correct return value kernel-doc descriptions for ioctl functions
+ nilfs2: reject invalid block index in GC ioctl
+ nfc: nci: add data_len bound checks to activation parameter extractors
+ HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
+ nvme: rename CDR/MORE/DNR to NVME_STATUS_*
+ nvmet-tcp: bound SGL data length before allocating command buffers
+ HID: uclogic: fix use-after-free of inrange_timer on remove
+ HID: ft260: fix i2c probing for hwmon devices
+ HID: ft260: improve i2c write performance
+ HID: ft260: improve i2c large reads performance
+ HID: ft260: skip unexpected HID input reports
+ HID: ft260: wake up device from power saving mode
+ HID: ft260: missed NACK from busy device
+ HID: ft260: validate i2c input report length
+ HID: ft260: fix stack-use-after-return write in I2C read race
+ HID: input: read battery capacity from its actual report offset
+ fpga: dfl: fme: add error handling
+ accessibility: speakup: unregister tty ldisc on later init failures
+ xhci: dbgtty: Fix unregister on tty_register_driver() failure
+ xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
+ fuse: fix invalidate lock leak on setattr writeback failure
+ fuse: fix invalidate lock leak on open O_TRUNC DAX failure
+ usb: usbtest: disable dynamic ID support
+ usb: gadget: f_tcm: keep port count until LUN teardown completes
+ xfrm: espintcp: fix UAF during close
+ xfrm: drop ESP-in-TCP packets with no ingress device
+ xfrm: ah6: validate routing header segments_left
+ xfrm: fix xfrm_state_construct() auth-trunc leak
+ net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
+ ipv6: seg6: clear IPv4 control block on IPIP decapsulation
+ mm/swap: reject swapon() on filesystem-level encrypted files
+ crypto: atmel-tdes - use scatterlist length before DMA mapping
+ crypto: qce - fix CCM AAD buffer underallocation
+ crypto: mxs-dcp - fix source scatterlist length access
+ crypto: qce - Remove unsafe/deprecated algorithms
+ KVM: s390: vsie: zero stale crypto bits
+ usb: core: Add lock to usb_wakeup_notification()
+ usb: core: Strengthen error handling in hub_hub_status()
+ ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
+ ALSA: usb-audio: Complete cleanup after system-resume errors
+ USB: serial: option: fix slab OOB read in interrupt URB callback
+ USB: serial: spcp8x5: drop broken carrier detect support
+ USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
+ usb: usbfs: fix use-after-free of usb_device in usbdev_release()
  Linux 5.15.220
- usb: usbfs: fix use-after-free of usb_device in usbdev_release()
- USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
- USB: serial: spcp8x5: drop broken carrier detect support
- USB: serial: option: fix slab OOB read in interrupt URB callback
- ALSA: usb-audio: Complete cleanup after system-resume errors
- ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
- usb: core: Strengthen error handling in hub_hub_status()
- usb: core: Add lock to usb_wakeup_notification()
- KVM: s390: vsie: zero stale crypto bits
- crypto: qce - Remove unsafe/deprecated algorithms
- crypto: mxs-dcp - fix source scatterlist length access
- crypto: qce - fix CCM AAD buffer underallocation
- crypto: atmel-tdes - use scatterlist length before DMA mapping
- mm/swap: reject swapon() on filesystem-level encrypted files
- ipv6: seg6: clear IPv4 control block on IPIP decapsulation
- net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
- xfrm: fix xfrm_state_construct() auth-trunc leak
- xfrm: ah6: validate routing header segments_left
- xfrm: drop ESP-in-TCP packets with no ingress device
- xfrm: espintcp: fix UAF during close
- usb: gadget: f_tcm: keep port count until LUN teardown completes
- usb: usbtest: disable dynamic ID support
- fuse: fix invalidate lock leak on open O_TRUNC DAX failure
- fuse: fix invalidate lock leak on setattr writeback failure
- xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
- xhci: dbgtty: Fix unregister on tty_register_driver() failure
- accessibility: speakup: unregister tty ldisc on later init failures
- fpga: dfl: fme: add error handling
- HID: input: read battery capacity from its actual report offset
- HID: ft260: fix stack-use-after-return write in I2C read race
- HID: ft260: validate i2c input report length
- HID: ft260: missed NACK from busy device
- HID: ft260: wake up device from power saving mode
- HID: ft260: skip unexpected HID input reports
- HID: ft260: improve i2c large reads performance
- HID: ft260: improve i2c write performance
- HID: ft260: fix i2c probing for hwmon devices
- HID: uclogic: fix use-after-free of inrange_timer on remove
- nvmet-tcp: bound SGL data length before allocating command buffers
- nvme: rename CDR/MORE/DNR to NVME_STATUS_*
- HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
- nfc: nci: add data_len bound checks to activation parameter extractors
- nilfs2: reject invalid block index in GC ioctl
- nilfs2: correct return value kernel-doc descriptions for ioctl functions
- ext4: propagate errors from fast commit range replay
- kcov: fix data corruption and race conditions on PREEMPT_RT
- kcov: replace local_irq_save() with a local_lock_t
- ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
- ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
- ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain()
- ASoC: tegra: Fix Master Volume Control
- ALSA: pcm: fix wait_time calculations
- Revert "smb: client: use kvzalloc() for megabyte buffer in simple fallocate"
- Revert "mtd: maps: vmu-flash: fix fault in unaligned fixup"
- selinux: switch two allocations to use kzalloc_objs()
- smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk().
- Revert "PM: sleep: Use complete() in device_pm_sleep_init()"
- bpf: Fix use-after-free in offloaded map/prog info fill
- KVM: arm64: Prevent access to vCPU events before init
- can: j1939: make j1939_sk_bind() fail if device is no longer registered
- can: j1939: add missing calls in NETDEV_UNREGISTER notification handler
- can: j1939: implement NETDEV_UNREGISTER notification handler
- jfs: add check read-only before txBeginAnon() call
- jfs: add check read-only before truncation in jfs_truncate_nolock()
- bpf: Remove tst_run from lwt_seg6local_prog_ops.
- ipvs: reload ip header after head reallocation
- io_uring/io-wq: fix worker accounting when canceling creation callbacks
- ext4: don't enable DAX on new encrypted files
- RDMA/rxe: Fix OOB in free_rd_atomic_resources()
+ UBUNTU: Upstream stable to v5.15.220

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168586

Title:
  Jammy update: v5.15.220 upstream stable release

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168586/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to