jammy/linux-hwe-6.2: 6.2.0-26.26~22.04.1 -proposed tracker

Bug #2026752 reported by Thadeu Lima de Souza Cascardo
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Kernel SRU Workflow
Fix Released
Medium
Unassigned
Automated-testing
Invalid
Medium
Canonical Kernel Team
Boot-testing
Fix Released
Medium
Unassigned
Certification-testing
Invalid
Medium
Canonical Hardware Certification
New-review
Fix Released
Medium
Andy Whitcroft
Prepare-package
Fix Released
Medium
Stefan Bader
Prepare-package-generate
Fix Released
Medium
Stefan Bader
Prepare-package-lrg
Fix Released
Medium
Stefan Bader
Prepare-package-lrm
Fix Released
Medium
Stefan Bader
Prepare-package-lrs
Fix Released
Medium
Stefan Bader
Prepare-package-meta
Fix Released
Medium
Stefan Bader
Prepare-package-signed
Fix Released
Medium
Stefan Bader
Promote-signing-to-proposed
Invalid
Medium
Unassigned
Promote-to-proposed
Fix Released
Medium
Ubuntu Stable Release Updates Team
Promote-to-security
Fix Released
Medium
Andy Whitcroft
Promote-to-updates
Fix Released
Medium
Andy Whitcroft
Regression-testing
Fix Released
Medium
Stefan Bader
Security-signoff
Fix Released
Medium
Canonical Security Team
Signing-signoff
Fix Released
Undecided
Stefan Bader
Sru-review
Fix Released
Medium
Andy Whitcroft
Verification-testing
Fix Released
Medium
Canonical Kernel Team
canonical-signing-jobs
Task00
Fix Released
Medium
Andy Whitcroft
linux-hwe-6.2 (Ubuntu)
Jammy
Fix Released
Medium
Unassigned

Bug Description

This bug will contain status and test results related to a kernel source (or snap) as stated in the title.

For an explanation of the tasks and the associated workflow see:
  https://wiki.ubuntu.com/Kernel/kernel-sru-workflow

-- swm properties --
built:
  from: 187c63b90477282c
  route-entry: 2
delta:
  promote-to-proposed: [lrm, lrs, main, meta, signed, lrg, generate]
  promote-to-security: []
  promote-to-updates: [lrm, lrs, main, meta, signed]
flag:
  boot-testing-requested: true
  bugs-spammed: true
  proposed-announcement-sent: true
  proposed-testing-requested: true
  stream-from-cycle: true
issue: KSRU-8405
kernel-stable-master-bug: 2026753
packages:
  generate: linux-generate-hwe-6.2
  lrg: linux-restricted-generate-hwe-6.2
  lrm: linux-restricted-modules-hwe-6.2
  lrs: linux-restricted-signatures-hwe-6.2
  main: linux-hwe-6.2
  meta: linux-meta-hwe-6.2
  signed: linux-signed-hwe-6.2
phase: Complete
phase-changed: Monday, 24. July 2023 21:10 UTC
reason: {}
synthetic:
  :promote-to-as-proposed: Invalid
variant: debs
versions:
  lrm: 6.2.0-26.26~22.04.1
  main: 6.2.0-26.26~22.04.1
  meta: 6.2.0.26.26~22.04.6
  signed: 6.2.0-26.26~22.04.1
~~:
  clamps:
    new-review: 187c63b90477282c
    promote-to-proposed: 187c63b90477282c
    self: 6.2.0-26.26~22.04.1
    sru-review: 187c63b90477282c

tags: added: kernel-release-tracking-bug-live
description: updated
tags: added: kernel-sru-cycle-s2023.06.12-1
description: updated
tags: added: kernel-sru-backport-of-2026753
Changed in kernel-sru-workflow:
status: New → Confirmed
importance: Undecided → Medium
Changed in linux-hwe-6.2 (Ubuntu Jammy):
importance: Undecided → Medium
Changed in kernel-sru-workflow:
status: Confirmed → Triaged
description: updated
Changed in kernel-sru-workflow:
status: Triaged → In Progress
tags: added: kernel-jira-issue-ksru-8405
tags: added: kernel-jira-issue-ksru-8447
description: updated
description: updated
Stefan Bader (smb)
summary: - jammy/linux-hwe-6.2: <version to be filled> -proposed tracker
+ jammy/linux-hwe-6.2: 6.2.0-26.26~22.04.1 -proposed tracker
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Ubuntu Kernel Bot (ubuntu-kernel-bot) wrote : Kernel requires additional signoff

New kernel with signed kernels; signing-review required.

description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Stefan Bader (smb) wrote :

We verified this for the jammy:linux-hwe-6.2 in 2023.06.12. Tested by having that kernel booting on a secure boot enabled T14.

description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Stefan Bader (smb) wrote :

Results match the 2023.06.12 counterparts.

tags: added: regression-testing-passed
description: updated
description: updated
description: updated
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux-hwe-6.2 - 6.2.0-26.26~22.04.1

---------------
linux-hwe-6.2 (6.2.0-26.26~22.04.1) jammy; urgency=medium

  * jammy/linux-hwe-6.2: 6.2.0-26.26~22.04.1 -proposed tracker (LP: #2026752)

  [ Ubuntu: 6.2.0-26.26 ]

  * lunar/linux: 6.2.0-26.26 -proposed tracker (LP: #2026753)
  * CVE-2023-2640 // CVE-2023-32629
    - Revert "UBUNTU: SAUCE: overlayfs: handle idmapped mounts in
      ovl_do_(set|remove)xattr"
    - Revert "UBUNTU: SAUCE: overlayfs: Skip permission checking for
      trusted.overlayfs.* xattrs"
    - SAUCE: overlayfs: default to userxattr when mounted from non initial user
      namespace
  * CVE-2023-35001
    - netfilter: nf_tables: prevent OOB access in nft_byteorder_eval
  * CVE-2023-31248
    - netfilter: nf_tables: do not ignore genmask when looking up chain by id
  * CVE-2023-3389
    - io_uring/poll: serialize poll linked timer start with poll removal
  * CVE-2023-3390
    - netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE
  * CVE-2023-3090
    - ipvlan:Fix out-of-bounds caused by unclear skb->cb
  * CVE-2023-3269
    - mm: introduce new 'lock_mm_and_find_vma()' page fault helper
    - mm: make the page fault mmap locking killable
    - arm64/mm: Convert to using lock_mm_and_find_vma()
    - powerpc/mm: Convert to using lock_mm_and_find_vma()
    - mips/mm: Convert to using lock_mm_and_find_vma()
    - riscv/mm: Convert to using lock_mm_and_find_vma()
    - arm/mm: Convert to using lock_mm_and_find_vma()
    - mm/fault: convert remaining simple cases to lock_mm_and_find_vma()
    - powerpc/mm: convert coprocessor fault to lock_mm_and_find_vma()
    - mm: make find_extend_vma() fail if write lock not held
    - execve: expand new process stack manually ahead of time
    - mm: always expand the stack with the mmap write lock held
    - [CONFIG]: Set CONFIG_LOCK_MM_AND_FIND_VMA

 -- Stefan Bader <email address hidden> Thu, 13 Jul 2023 15:22:42 +0200

Changed in linux-hwe-6.2 (Ubuntu Jammy):
status: New → Fix Released
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Ubuntu Kernel Bot (ubuntu-kernel-bot) wrote : Workflow done!

All tasks have been completed and the bug is being closed

Changed in kernel-sru-workflow:
status: In Progress → Fix Committed
Changed in kernel-sru-workflow:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.