~ubuntu-kernel/ubuntu/+source/linux/+git/noble:hwe-6.17-next

Last commit made on 2026-08-01
Get this branch:
git clone -b hwe-6.17-next https://git.launchpad.net/~ubuntu-kernel/ubuntu/+source/linux/+git/noble
Members of Ubuntu Kernel Repositories can upload to this branch. Log in for directions.

Branch merges

Branch information

Name:
hwe-6.17-next
Repository:
lp:~ubuntu-kernel/ubuntu/+source/linux/+git/noble

Recent commits

845fcaa... by Edoardo Canepa

UBUNTU: Ubuntu-hwe-6.17-6.17.0-44.44

Signed-off-by: Edoardo Canepa <email address hidden>

7934bc8... by Edoardo Canepa

UBUNTU: link-to-tracker: update tracking bug

BugLink: https://bugs.launchpad.net/bugs/2162477
Properties: no-test-build
Signed-off-by: Edoardo Canepa <email address hidden>

67bcf93... by Zhan Jun <email address hidden>

net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()

syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit()
when accessing skb->len for tx statistics after usb_submit_urb() has
been called:

  BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f/0x760
    drivers/net/usb/rtl8150.c:712
  Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226

The URB completion handler write_bulk_callback() frees the skb via
dev_kfree_skb_irq(dev->tx_skb). The URB may complete on another CPU
in softirq context before usb_submit_urb() returns in the submitter,
so by the time the submitter reads skb->len the skb has already been
queued to the per-CPU completion_queue and freed by net_tx_action():

  CPU A (xmit) CPU B (USB completion softirq)
  ------------ ------------------------------
  dev->tx_skb = skb;
  usb_submit_urb() --+
                          |-------> write_bulk_callback()
                          | dev_kfree_skb_irq(dev->tx_skb)
                          | net_tx_action()
                          | napi_skb_cache_put() <-- free
  netdev->stats.tx_bytes |
    += skb->len; <-- UAF read

Fix it by caching skb->len before submitting the URB and using the
cached value when updating the tx_bytes counter.

The pre-existing tx_bytes semantics are preserved: the counter tracks
the original frame length (skb->len), not the ETH_ZLEN/USB-alignment
padded "count" value that is handed to the device. Changing that
would be a user-visible accounting change and is out of scope for
this UAF fix.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: <email address hidden>
Closes: https://<email address hidden>/
Closes: https://syzkaller.appspot.com/bug?extid=3f46c095ac0ca048cb71
Reviewed-by: Andrew Lunn <email address hidden>
Signed-off-by: Zhan Jun <email address hidden>
Link: https://patch<email address hidden>
Signed-off-by: Jakub Kicinski <email address hidden>
(cherry picked from commit 23f0e34c64acba15cad4d23e50f41f533da195fa)
CVE-2026-52982
Assisted-by: kybele:claude-opus-4.8
Signed-off-by: Cengiz Can <email address hidden>
Acked-by: Edoardo Canepa <email address hidden>
Acked-by: Benjamin Wheeler <email address hidden>
Signed-off-by: Edoardo Canepa <email address hidden>

8ccf9fa... by Fernando Fernandez Mancera <email address hidden>

netfilter: nfnetlink_osf: fix out-of-bounds read on option matching

In nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once
and passed by reference to nf_osf_match_one() for each fingerprint
checked. During TCP option parsing, nf_osf_match_one() advances the
shared ctx->optp pointer.

If a fingerprint perfectly matches, the function returns early without
restoring ctx->optp to its initial state. If the user has configured
NF_OSF_LOGLEVEL_ALL, the loop continues to the next fingerprint.
However, because ctx->optp was not restored, the next call to
nf_osf_match_one() starts parsing from the end of the options buffer.
This causes subsequent matches to read garbage data and fail
immediately, making it impossible to log more than one match or logging
incorrect matches.

Instead of using a shared ctx->optp pointer, pass the context as a
constant pointer and use a local pointer (optp) for TCP option
traversal. This makes nf_osf_match_one() strictly stateless from the
caller's perspective, ensuring every fingerprint check starts at the
correct option offset.

Fixes: 1a6a0951fc00 ("netfilter: nfnetlink_osf: add missing fmatch check")
Suggested-by: Florian Westphal <email address hidden>
Signed-off-by: Fernando Fernandez Mancera <email address hidden>
Reviewed-by: Pablo Neira Ayuso <email address hidden>
Signed-off-by: Pablo Neira Ayuso <email address hidden>
(cherry picked from commit f5ca450087c3baf3651055e7a6de92600f827af3)
CVE-2026-52999
Assisted-by: kybele:claude-opus-4.8
Signed-off-by: Cengiz Can <email address hidden>
Acked-by: Edoardo Canepa <email address hidden>
Acked-by: Benjamin Wheeler <email address hidden>
Signed-off-by: Edoardo Canepa <email address hidden>

b65c3d7... by Asim Viladi Oglu Manizada <email address hidden>

net: openvswitch: reject oversized nested action attrs

Open vSwitch stores generated flow actions as nlattrs, whose nla_len
field is u16. Commit a1e64addf3ff ("net: openvswitch: remove
misbehaving actions length check") allowed the total sw_flow_actions
stream to grow beyond 64 KiB, which is valid, but also removed the last
guard preventing a generated nested action attribute from exceeding
U16_MAX.

An oversized generated container can thus be closed with a truncated
nla_len. A later dump or teardown then walks a structurally different
stream than the one that was validated. In particular, an oversized
nested CLONE/CT action may cause subsequent bytes in the generated
stream to be interpreted as independent actions.

Keep the larger total-action-stream behavior, but make nested action
close reject generated containers that do not fit in nla_len, and return
the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and
CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse
construction order before discarding failed wrappers, so resources copied
into the rejected tails are released before the wrappers are removed.

Most failed outer wrappers are discarded by truncating actions_len after
child resources have been released. CHECK_PKT_LEN also trims its parent
after branch resources are gone. SET/TUNNEL close failures unwind their
known tun_dst ownership directly, and SET_TO_MASKED has no external
ownership and truncates on close failure.

Fixes: a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check")
Cc: <email address hidden>
Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
Signed-off-by: Asim Viladi Oglu Manizada <email address hidden>
Reviewed-by: Eelco Chaudron <email address hidden>
Reviewed-by: Aaron Conole <email address hidden>
Reviewed-by: Ilya Maximets <email address hidden>
Link: https://<email address hidden>
Signed-off-by: Paolo Abeni <email address hidden>
CVE-2026-64531
(cherry picked from commit 3f1f755366687d051174739fb99f7d560202f60b)
Signed-off-by: Cengiz Can <email address hidden>
Acked-by: Tim Whisonant <email address hidden>
Acked-by: Benjamin Wheeler <email address hidden>
Signed-off-by: Edoardo Canepa <email address hidden>

6188613... by Til Kaiser <email address hidden>

net: mvpp2: limit XDP frame size to the RX buffer

mvpp2 has short and long BM pools, and short pool buffers can be smaller
than PAGE_SIZE. The XDP path nevertheless initializes every xdp_buff with
PAGE_SIZE as frame size.

XDP helpers use frame_sz to validate tail growth and to derive the hard
end of the data area. Advertising PAGE_SIZE for short buffers can let
bpf_xdp_adjust_tail() grow a packet past the real allocation, corrupting
memory or later tripping skb tailroom checks.

Initialize the XDP buffer with bm_pool->frag_size so XDP tailroom matches
the actual buffer backing the packet.

Fixes: 07dd0a7aae7f ("mvpp2: add basic XDP support")
Signed-off-by: Til Kaiser <email address hidden>
Link: https://<email address hidden>
Signed-off-by: Paolo Abeni <email address hidden>
(cherry picked from commit f3c6aa078927e6fe8121c9c591ddee8716c5305a)
CVE-2026-53216
Assisted-by: kybele:claude-opus-4.8
Signed-off-by: Cengiz Can <email address hidden>
Acked-by: Tim Whisonant <email address hidden>
Acked-by: Edoardo Canepa <email address hidden>
Signed-off-by: Edoardo Canepa <email address hidden>

3019ed6... by Andreas Gruenbacher <email address hidden>

gfs2: add some missing log locking

Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(),
gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock,
but these functions require exclusion against concurrent transactions.

To fix that, add a non-locking __gfs2_log_flush() function. Then, in
gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log
flushing functions and __gfs2_log_flush().

Fixes: 5e4c7632aae1c ("gfs2: Issue revokes more intelligently")
Signed-off-by: Andreas Gruenbacher <email address hidden>
(cherry picked from commit fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8)
CVE-2026-53049
Assisted-by: kybele:claude-opus-4.8
Signed-off-by: Cengiz Can <email address hidden>
Acked-by: "Alice C. Munduruca" <email address hidden>
Acked-by: Tim Whisonant <email address hidden>
Signed-off-by: Edoardo Canepa <email address hidden>

0d9ce82... by Hyunwoo Kim <email address hidden>

inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush

On netns teardown, fqdir_pre_exit() walks the fqdir rhashtable and
flushes every fragment queue that is not yet complete using
inet_frag_queue_flush(). That helper frees all the skbs queued on the
fragment queue but does not set INET_FRAG_COMPLETE, and leaves
q->fragments_tail and q->last_run_head pointing at the freed skbs.
The queue itself stays in the rhashtable.

fqdir_pre_exit() first lowers high_thresh to 0 to stop new queue lookups,
but it cannot stop a fragment that already obtained the queue through
inet_frag_find() earlier and stalled just before taking the queue lock.
Once that fragment resumes after the flush and takes the queue lock,
it passes the INET_FRAG_COMPLETE check and then dereferences the freed
fragments_tail. inet_frag_queue_insert() reads FRAG_CB() and ->len of
that pointer and, on the append path, writes ->next_frag, causing a
slab use-after-free. IPv6, nf_conntrack_reasm6 and 6lowpan reassembly
share the same flush path and are affected as well.

Reset rb_fragments, fragments_tail and last_run_head in
inet_frag_queue_flush() so a flushed queue no longer points at the
freed skbs. A fragment that resumes after the flush and takes the
queue lock then finds an empty queue and starts a new run instead of
dereferencing the freed fragments_tail. ip_frag_reinit() already
performed this reset after its own flush, so drop the now duplicate
code there.

Cc: <email address hidden>
Fixes: 006a5035b495 ("inet: frags: flush pending skbs in fqdir_pre_exit()")
Suggested-by: Eric Dumazet <email address hidden>
Signed-off-by: Hyunwoo Kim <email address hidden>
Link: https://patch.msgid.link/ah6ukYq5G98LshdA@v4bel
Signed-off-by: Jakub Kicinski <email address hidden>
(cherry picked from commit 32594b09854970d7ba83eb2dc8c69a2edd158c8e)
CVE-2026-53175
Assisted-by: kybele:claude-opus-4.8
Signed-off-by: Cengiz Can <email address hidden>
Acked-by: Tim Whisonant <email address hidden>
Acked-by: Edoardo Canepa <email address hidden>
Signed-off-by: Edoardo Canepa <email address hidden>

b377036... by Eric Dumazet <email address hidden>

ipv6: fix possible UAF in icmpv6_rcv()

Caching saddr and daddr before pskb_pull() is problematic
since skb->head can change.

Remove these temporary variables:

- We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr
  when net_dbg_ratelimited() is called in the slow path.

- Avoid potential future misuse after pskb_pull() call.

Fixes: 4b3418fba0fe ("ipv6: icmp: include addresses in debug messages")
Signed-off-by: Eric Dumazet <email address hidden>
Reviewed-by: Fernando Fernandez Mancera <email address hidden>
Reviewed-by: Joe Damato <email address hidden>
Reviewed-by: Ido Schimmel <email address hidden>
Link: https://<email address hidden>
Signed-off-by: Jakub Kicinski <email address hidden>
(cherry picked from commit f996edd7615e686ada141b7f3395025729ff8ccb)
CVE-2026-53006
Assisted-by: kybele:claude-opus-4.8
Signed-off-by: Cengiz Can <email address hidden>
Acked-by: Edoardo Canepa <email address hidden>
Acked-by: Tim Whisonant <email address hidden>
Signed-off-by: Edoardo Canepa <email address hidden>

402b684... by Lee Jones <email address hidden>

tipc: fix double-free in tipc_buf_append()

tipc_msg_validate() can potentially reallocate the skb it is validating,
freeing the old one. In tipc_buf_append(), it was being called with a
pointer to a local variable which was a copy of the caller's skb
pointer.

If the skb was reallocated and validation subsequently failed, the error
handling path would free the original skb pointer, which had already
been freed, leading to double-free.

Fix this by checking if head now points to a newly allocated reassembled
skb. If it does, reassign *headbuf for later freeing operations.

Fixes: d618d09a68e4 ("tipc: enforce valid ratio between skb truesize and contents")
Suggested-by: Tung Nguyen <email address hidden>
Signed-off-by: Lee Jones <email address hidden>
Reviewed-by: Tung Nguyen <email address hidden>
Signed-off-by: Jakub Kicinski <email address hidden>
(cherry picked from commit d293ca716e7d5dffdaecaf6b9b2f857a33dc3d3a)
CVE-2026-52993
Assisted-by: kybele:claude-opus-4.8
Signed-off-by: Cengiz Can <email address hidden>
Acked-by: Edoardo Canepa <email address hidden>
Acked-by: Tim Whisonant <email address hidden>
Signed-off-by: Edoardo Canepa <email address hidden>