* CVE-2023-42756
- netfilter: ipset: Fix race between IPSET_CMD_CREATE and IPSET_CMD_SWAP
* CVE-2023-4244
- netfilter: nf_tables: don't skip expired elements during walk
- netfilter: nf_tables: GC transaction API to avoid race with control plane
- netfilter: nf_tables: adapt set backend to use GC transaction API
- netfilter: nft_set_hash: mark set element as dead when deleting from packet
path
- netfilter: nf_tables: remove busy mark and gc batch API
- netfilter: nf_tables: don't fail inserts if duplicate has expired
- netfilter: nf_tables: fix kdoc warnings after gc rework
- netfilter: nf_tables: fix GC transaction races with netns and netlink event
exit path
- netfilter: nf_tables: GC transaction race with netns dismantle
- netfilter: nf_tables: GC transaction race with abort path
- netfilter: nf_tables: use correct lock to protect gc_list
- netfilter: nf_tables: defer gc run if previous batch is still pending
* CVE-2023-42752
- net: remove osize variable in __alloc_skb()
- net: factorize code in kmalloc_reserve()
- net: deal with integer overflows in kmalloc_reserve()
* Fix ADL: System enabled AHCI can't get into s0ix when attached ODD
(LP: #2037493)
- SAUCE: ata: ahci: Add Intel Alder Lake-P AHCI controller to low power
chipsets list
* Fix unstable audio at low levels on Thinkpad P1G4 (LP: #2037077)
- ALSA: hda/realtek - ALC287 I2S speaker platform support
* Infinite systemd loop when power off the machine with multiple MD RAIDs
(LP: #2036184)
- SAUCE: md: do not _put wrong device in md_seq_next
* Fix RCU warning on AMD laptops (LP: #2036377)
- power: supply: core: Use blocking_notifier_call_chain to avoid RCU complaint
-- Timo Aaltonen <email address hidden> Tue, 03 Oct 2023 18:13:17 +0300
This bug was fixed in the package linux-oem-6.1 - 6.1.0-1024.24
---------------
linux-oem-6.1 (6.1.0-1024.24) jammy; urgency=medium
* jammy/linux- oem-6.1: 6.1.0-1024.24 -proposed tracker (LP: #2038210)
* Packaging resync (LP: #1786013)
- [Packaging] update annotations scripts
- [Packaging] resync getabis
- [Packaging] update helper scripts
* CVE-2023-42756
- netfilter: ipset: Fix race between IPSET_CMD_CREATE and IPSET_CMD_SWAP
* CVE-2023-4244
- netfilter: nf_tables: don't skip expired elements during walk
- netfilter: nf_tables: GC transaction API to avoid race with control plane
- netfilter: nf_tables: adapt set backend to use GC transaction API
- netfilter: nft_set_hash: mark set element as dead when deleting from packet
path
- netfilter: nf_tables: remove busy mark and gc batch API
- netfilter: nf_tables: don't fail inserts if duplicate has expired
- netfilter: nf_tables: fix kdoc warnings after gc rework
- netfilter: nf_tables: fix GC transaction races with netns and netlink event
exit path
- netfilter: nf_tables: GC transaction race with netns dismantle
- netfilter: nf_tables: GC transaction race with abort path
- netfilter: nf_tables: use correct lock to protect gc_list
- netfilter: nf_tables: defer gc run if previous batch is still pending
* CVE-2023-42752
- net: remove osize variable in __alloc_skb()
- net: factorize code in kmalloc_reserve()
- net: deal with integer overflows in kmalloc_reserve()
* CVE-2023-42572
- net: add SKB_HEAD_ALIGN() helper
* CVE-2023-5197
- netfilter: nf_tables: disallow rule removal from chain binding
* CVE-2023-42755
- net/sched: Retire rsvp classifier
- [Config] remove NET_CLS_RSVP and NET_CLS_RSVP6
* CVE-2023-4881
- netfilter: nftables: exthdr: fix 4-byte stack OOB write
* Fix ADL: System enabled AHCI can't get into s0ix when attached ODD
(LP: #2037493)
- SAUCE: ata: ahci: Add Intel Alder Lake-P AHCI controller to low power
chipsets list
* Fix unstable audio at low levels on Thinkpad P1G4 (LP: #2037077)
- ALSA: hda/realtek - ALC287 I2S speaker platform support
* Infinite systemd loop when power off the machine with multiple MD RAIDs
(LP: #2036184)
- SAUCE: md: do not _put wrong device in md_seq_next
* Fix RCU warning on AMD laptops (LP: #2036377) notifier_ call_chain to avoid RCU complaint
- power: supply: core: Use blocking_
-- Timo Aaltonen <email address hidden> Tue, 03 Oct 2023 18:13:17 +0300