This bug was fixed in the package linux-oem-7.0 - 7.0.0-1014.14
---------------
linux-oem-7.0 (7.0.0-1014.14) resolute; urgency=medium
* resolute/linux-oem-7.0: 7.0.0-1014.14 -proposed tracker (LP:
#2165761)
* Packaging resync (LP: #1786013)
- [Packaging] update variants
* [SRU] Add support for amd-pmf AMDI0112 ID (LP: #2165251)
- SAUCE: platform/x86/amd/pmf: Add AMDI0112 ACPI ID
* Speakers not detected on HP systems with TI TAS2783 SoundWire amps
(LP: #2164504)
- ASoC: sdw_utils: Add missed component_name strings for TI amps
* WWAN modem unresponsive after freeze on Dell systems with DW5826e
(LP: #2163214)
- platform/x86: dell-dw5826e: Add reset driver for DW5826e
- platform/x86: dell-dw5826e: fix ACPI _DSM function index and bitmask
usage
- [Config] Add CONFIG_DELL_DW5826E_RESET=m
* btintel_pcie NULL pointer call trace during boot on Intel Bluetooth PCIe
controllers (LP: #2163723)
- Bluetooth: btintel_pcie: Support Product level reset
- Bluetooth: btintel_pcie: Add support for smart trigger dump
- Bluetooth: btintel_pcie: Add 50 ms delay before MAC init on BlazarIW
- Bluetooth: btintel_pcie: Load IOSF debug regs by controller variant
- Bluetooth: btintel_pcie: Separate coredump work from RX work
- Bluetooth: btintel_pcie: Refactor FLR to use device_reprobe()
- Bluetooth: btintel_pcie: split coredump worker into per-trigger works
- Bluetooth: btintel_pcie: serialize reset_type with RECOVERY_IN_PROGRESS
* [SRU] Fix incorrect GTT calculation on the APU systems (LP: #2162038)
- drm/amdgpu: cap GTT size to physical RAM on APUs
* [SRU] Fix hang on shutdown with TBT3 connected (LP: #2161964)
- thunderbolt: Assert downstream port reset on shutdown
* [SRU] Add DisplayID to the panel detection logic in amdgpu dm
(LP: #2161064)
- drm/edid: Parse AMD Vendor-Specific Data Block
- drm/amd/display: Use drm_display_info for AMD VSDB data
- drm/edid: extract base section header processing into helper
- drm/edid: parse panel type from DisplayID 2.x Display Parameters
- drm/amd/display: use DisplayID panel type in dm_set_panel_type
[ Ubuntu: 7.0.0-34.34 ]
* resolute/linux: 7.0.0-34.34 -proposed tracker (LP: #2165995)
[ Ubuntu: 7.0.0-32.32 ]
* resolute/linux: 7.0.0-32.32 -proposed tracker (LP: #2165777)
* CVE-2026-72064
- net: mana: Sync page pool RX frags for CPU
* CVE-2026-72065
- net: mana: Validate the packet length reported by the NIC
* CVE-2026-72098
- dm-verity-fec: replace {MAX,MIN}_RSN with {MIN,MAX}_ROOTS
- dm-verity: fix buffer overflow in FEC calculation
* CVE-2026-72248
- netfilter: flowtable: support IPIP tunnel with direct xmit
- netfilter: flowtable: use correct direction to set up tunnel route
* CVE-2026-72249
- netfilter: flowtable: use dst in this direction when pushing IPIP header
* CVE-2026-72287
- KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal"
checks
* CVE-2026-72329
- net/liquidio: drop cached VF pci_dev LUT
* CVE-2026-72355
- netfs: Fix barriering when walking subrequest list
* CVE-2026-72412
- s390/mm: Fix handling of _PAGE_UNUSED pte bit
* CVE-2026-72417
- netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()
* CVE-2026-72442
- netfilter: flowtable: fix and simplify IP6IP6 tunnel handling
* CVE-2026-72463
- xfrm: Fix dev use-after-free in xfrm async resumption
* CVE-2026-72477
- fs/ntfs3: call _ntfs_bad_inode() when failing to rename
* CVE-2026-72493
- net: serialize netif_running() check in enqueue_to_backlog()
* CVE-2026-72494
- RDMA/irdma: Replace waitqueue and flag with completion
* CVE-2026-72496
- RDMA/bnxt_re: Proper rollback if the ioremap fails
* CVE-2026-74269
- bnxt: fix head underflow on XDP head-grow
* CVE-2026-74350
- ocfs2: validate fast symlink target during inode read
* CVE-2026-72495
- RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
* CVE-2026-72501
- RDMA/bnxt_re: Initialize dpi variable to zero
* CVE-2026-72278
- KVM: arm64: nv: Re-translate VNCR before injecting abort
* CVE-2026-68083
- ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
* CVE-2026-68457
- ksmbd: use opener credentials for FSCTL mutations
* CVE-2026-68476
- ipvs: reload ip header after head reallocation
* CVE-2026-68477
- ipvs: fix more places with wrong ipv6 transport offsets
* CVE-2026-72014
- drbd: reject data replies with an out-of-range payload size
* CVE-2026-72020
- ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
* CVE-2026-72033
- orangefs: keep the readdir entry size 64-bit in fill_from_part()
* CVE-2026-72041
- espintcp: use sk_msg_free_partial to fix partial send
* CVE-2026-72046
- gve: fix header buffer corruption with header-split and HW-GRO
* CVE-2026-72069
- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
* CVE-2026-72083
- scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
* CVE-2026-72084
- scsi: target: Bound PR-OUT TransportID parsing to the received buffer
* CVE-2026-72085
- scsi: xen: scsiback: Free unsubmitted command instead of double-putting
it
* CVE-2026-72129
- nvmet-rdma: handle inline data with a nonzero offset
* CVE-2026-72130
- nvmet-auth: reject short AUTH_RECEIVE buffers
* CVE-2026-64551
- sctp: validate STALE_COOKIE cause length before reading staleness
* CVE-2026-72137
- xfrm: nat_keepalive: avoid double free on send error
* CVE-2026-72139
- tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
* CVE-2026-72191
- ntfs3: validate split-point offset in indx_insert_into_buffer
* CVE-2026-72192
- ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
* CVE-2026-72194
- fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
* CVE-2026-72217
- SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
* CVE-2026-72220
- sunrpc: harden rq_procinfo lifecycle to prevent double-free
* CVE-2026-72221
- sunrpc: wait for in-flight TLS handshake callback when cancel loses race
* CVE-2026-72222
- sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
* CVE-2026-72226
- batman-adv: tt: prevent TVLV OOB check overflow
* CVE-2026-72234
- batman-adv: access unicast_ttvn skb->data only after skb realloc
* CVE-2026-72251
- netfilter: nf_nat_sip: reload possible stale data pointer
* CVE-2026-72277
- KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
- KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
* CVE-2026-72279
- KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
* CVE-2026-72288
- KVM: arm64: vgic: Handle race between interrupt affinity change and LPI
disabling
* CVE-2026-72289
- KVM: arm64: vgic: Check the interrupt is still ours before migrating it
* CVE-2026-72296
- net: ife: require ETH_HLEN to be pullable in ife_decode()
* CVE-2026-72299
- tipc: restrict socket queue dumps in enqueue tracepoints
* CVE-2026-72317
- SUNRPC: pin upper rpc_clnt across the TLS connect_worker
* CVE-2026-72318
- cifs: validate DFS referral string offsets
* CVE-2026-72319
- ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
- ipvs: ensure inner headers in ICMP errors are in headroom
* CVE-2026-72320
- netfilter: nft_lookup: fix catchall element handling with inverted
lookups
* CVE-2026-72322
- ipv6: mcast: Fix potential UAF in MLD delayed work
* CVE-2026-72323
- ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
* CVE-2026-64541
- net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
* CVE-2026-72339
- qede: fix off-by-one in BD ring consumption on build_skb failure
* CVE-2026-72348
- netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
* CVE-2026-72351
- gue: validate REMCSUM private option length
* CVE-2026-72366
- netfs: Fix netfs_create_write_req() to handle async cache object
creation
* CVE-2026-72381
- ksmbd: fix use-after-free of fp->owner.name in durable handle owner
check
* CVE-2026-72393
- eth: fbnic: don't cache shinfo across skb realloc
* CVE-2026-72398
- sctp: add INIT verification after cookie unpacking
* CVE-2026-72399
- net: enetc: check the number of BDs needed for xdp_frame
* CVE-2026-64530
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
* CVE-2026-72422
- ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2
NEGOTIATE
* CVE-2026-72429
- ipv6: ioam: fix type confusion of dst_entry
* CVE-2026-72436
- netfilter: ipset: Fix data race between add and dump in all hash types
- netfilter: ipset: annotate "pos" for concurrent readers/writers
- netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash
types
* CVE-2026-72451
- xfrm: Fix xfrm state cache insertion race
* CVE-2026-72466
- xprtrdma: Fix bcall rep leak and unbounded peek
* CVE-2026-72472
- nfs: use nfsi->rwsem to protect traversal of the file lock list
* CVE-2026-72473
- xprtrdma: Avoid 250 ms delay on backlog wakeup
- xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot
- xprtrdma: Post receive buffers after RPC completion
- xprtrdma: Use sendctx DMA state for Send signaling
- xprtrdma: Decouple req recycling from RPC completion
* CVE-2026-72491
- net/9p: fix race condition on rdma->state in trans_rdma.c
* CVE-2026-72495 // CVE-2026-72501
- RDMA/bnxt_re: Move the UAPI methods to a dedicated file
* CVE-2026-74255
- tipc: fix UAF in tipc_l2_send_msg()
* CVE-2026-74267
- net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek
before restoring qlen
* CVE-2026-74268
- tcp: clear sock_ops cb flags before force-closing a child socket
* CVE-2026-74287
- sctp: validate embedded address parameter length
* CVE-2026-74310
- vhost/net: complete zerocopy ubufs only once
* CVE-2026-74345
- RDMA/siw: Fix endpoint/socket association handling
* CVE-2026-74361
- nvme: fix FDP fdpcidx bounds check
* CVE-2026-74376
- md/raid10: reset read_slot when reusing r10bio for discard
* CVE-2026-74384
- nvme-multipath: fix flex array size in struct nvme_ns_head
* CVE-2026-74394
- RDMA/srpt: fix integer overflow in immediate data length check
* CVE-2026-74398
- ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
* CVE-2026-74401
- dlm: fix add msg handle in send_queue ordered
* CVE-2026-74406
- vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
* CVE-2026-74427
- afs: Fix netns teardown to cancel the preallocation charger
- afs: Fix further netns teardown to cancel the preallocation charger
* CVE-2026-74428
- rxrpc: Fix double unlock in rxrpc_recvmsg()
* CVE-2026-74433
- rxrpc: Fix UAF in rxgk_issue_challenge()
* CVE-2026-74434
- rxrpc: Don't move a peeked OOB message onto the pending queue
* CVE-2026-74436
- rxrpc: serialize kernel accept preallocation with socket teardown
* CVE-2026-64535
- nvmet-tcp: Fix potential UAF when ddgst mismatch
* CVE-2026-74439
- iommu/vt-d: Clear Present bit before tearing down scalable-mode context
entry
* CVE-2026-64534
- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error
path
-- Kuan-Ying Lee <[email protected]> Mon, 07 Sep 2026
11:00:18 +0800
** Changed in: linux-oem-7.0 (Ubuntu Resolute)
Status: Fix Committed => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-64530
** CVE added: https://cve.org/CVERecord?id=CVE-2026-64534
** CVE added: https://cve.org/CVERecord?id=CVE-2026-64535
** CVE added: https://cve.org/CVERecord?id=CVE-2026-64541
** CVE added: https://cve.org/CVERecord?id=CVE-2026-64551
** CVE added: https://cve.org/CVERecord?id=CVE-2026-68083
** CVE added: https://cve.org/CVERecord?id=CVE-2026-68457
** CVE added: https://cve.org/CVERecord?id=CVE-2026-68476
** CVE added: https://cve.org/CVERecord?id=CVE-2026-68477
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72014
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72020
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72033
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72041
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72046
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72064
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72065
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72069
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72083
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72084
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72085
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72098
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72129
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72130
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72137
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72139
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72191
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72192
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72194
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72217
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72220
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72221
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72222
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72226
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72234
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72248
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72249
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72251
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72277
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72278
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72279
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72287
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72288
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72289
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72296
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72299
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72317
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72318
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72319
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72320
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72322
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72323
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72329
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72339
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72348
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72351
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72355
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72366
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72381
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72393
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72398
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72399
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72412
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72417
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72422
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72429
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72436
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72442
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72451
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72463
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72466
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72472
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72473
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72477
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72491
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72493
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72494
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72495
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72496
** CVE added: https://cve.org/CVERecord?id=CVE-2026-72501
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74255
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74267
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74268
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74269
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74287
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74310
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74345
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74350
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74361
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74376
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74384
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74394
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74398
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74401
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74406
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74427
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74428
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74433
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74434
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74436
** CVE added: https://cve.org/CVERecord?id=CVE-2026-74439
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163723
Title:
btintel_pcie NULL pointer call trace during boot on Intel Bluetooth
PCIe controllers
To manage notifications about this bug go to:
https://bugs.launchpad.net/hwe-next/+bug/2163723/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs