jammy/linux: 5.15.0-33.34 -proposed tracker

Bug #1973924 reported by Stefan Bader
14
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Kernel SRU Workflow
Fix Released
Medium
Unassigned
Automated-testing
Fix Released
Medium
Stefan Bader
Boot-testing
Fix Released
Medium
Stefan Bader
Certification-testing
Invalid
Medium
Canonical Hardware Certification
Kernel-signoff
Fix Released
Medium
Stefan Bader
New-review
Fix Released
Undecided
Unassigned
Prepare-package
Fix Released
Medium
Stefan Bader
Prepare-package-lrg
Fix Released
Medium
Stefan Bader
Prepare-package-lrm
Fix Released
Medium
Stefan Bader
Prepare-package-lrs
Fix Released
Medium
Stefan Bader
Prepare-package-meta
Fix Released
Medium
Stefan Bader
Prepare-package-signed
Fix Released
Medium
Stefan Bader
Promote-signing-to-proposed
Invalid
Medium
Ubuntu Stable Release Updates Team
Promote-to-proposed
Fix Released
Medium
Ubuntu Stable Release Updates Team
Promote-to-security
Fix Released
Medium
Andy Whitcroft
Promote-to-updates
Fix Released
Medium
Andy Whitcroft
Regression-testing
Invalid
Medium
Canonical Kernel Team
Security-signoff
Fix Released
Medium
Steve Beattie
Sru-review
Fix Released
Medium
Andy Whitcroft
Verification-testing
Fix Released
Medium
Canonical Kernel Team
linux (Ubuntu)
Jammy
Fix Released
Medium
Unassigned

Bug Description

This bug will contain status and test results related to a kernel source (or snap) as stated in the title.

For an explanation of the tasks and the associated workflow see:
  https://wiki.ubuntu.com/Kernel/kernel-sru-workflow

-- swm properties --
boot-testing-requested: true
bugs-spammed: true
built:
  from: f248b5572c0af186
  route-entry: 1
delta:
  promote-to-proposed:
  - signed
  - lrm
  - lrs
  - main
  - meta
  - lrg
  promote-to-security: []
  promote-to-updates:
  - lrs
  - signed
  - main
  - lrm
  - meta
issue: KSRU-2121
packages:
  lrg: linux-restricted-generate
  lrm: linux-restricted-modules
  lrs: linux-restricted-signatures
  main: linux
  meta: linux-meta
  signed: linux-signed
phase: Complete
phase-changed: Monday, 23. May 2022 19:48 UTC
proposed-announcement-sent: true
reason: {}
synthetic:
  :promote-to-as-proposed: Fix Released
trackers:
  jammy/linux-aws: bug 1973893
  jammy/linux-azure: bug 1973896
  jammy/linux-fips: bug 1973918
  jammy/linux-gcp: bug 1973899
  jammy/linux-gke: bug 1973919
  jammy/linux-ibm: bug 1973901
  jammy/linux-ibm-gt: bug 1973920
  jammy/linux-intel-iotg: bug 1973921
  jammy/linux-kvm: bug 1973903
  jammy/linux-lowlatency: bug 1973907
  jammy/linux-oracle: bug 1973910
  jammy/linux-raspi: bug 1973913
  jammy/linux-realtime: bug 1973915
  jammy/linux-riscv: bug 1973917
  jammy/linux-uc22: bug 1973923
  kinetic/linux: bug 1973890
variant: debs
versions:
  lrm: 5.15.0-33.34
  main: 5.15.0-33.34
  meta: 5.15.0.33.36
  signed: 5.15.0-33.34
versions-replace:
  lrm:
  - 5.15.0-32.33+1
  - 5.15.0-32.33
  main:
  - 5.15.0-32.33
  meta:
  - 5.15.0.32.35
  signed:
  - 5.15.0-32.33
~~:
  clamps:
    new-review: f248b5572c0af186
    promote-to-proposed: f248b5572c0af186
    self: 5.15.0-33.34
    sru-review: f248b5572c0af186

CVE References

Stefan Bader (smb)
tags: added: kernel-release-tracking-bug-live
description: updated
tags: added: kernel-sru-cycle-2022.04.18-9
Changed in kernel-sru-workflow:
status: New → Confirmed
importance: Undecided → Medium
Changed in linux (Ubuntu Jammy):
importance: Undecided → Medium
tags: added: kernel-block-derivatives
Changed in kernel-sru-workflow:
status: Confirmed → Triaged
description: updated
Changed in kernel-sru-workflow:
status: Triaged → In Progress
tags: added: kernel-jira-issue-ksru-2121
description: updated
Andy Whitcroft (apw)
description: updated
Stefan Bader (smb)
summary: - jammy/linux: <version to be filled> -proposed tracker
+ jammy/linux: 5.15.0-33.34 -proposed tracker
description: updated
description: updated
Stefan Bader (smb)
tags: added: kernel-unblock-derivatives
removed: kernel-block-derivatives
description: updated
description: updated
description: updated
Andy Whitcroft (apw)
tags: added: kernel-signing-bot
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Stefan Bader (smb) wrote :

Good enough for the small change.

tags: added: boot-testing-passed
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Stefan Bader (smb) wrote :

ADT looks ok (just the usual random failures).

tags: added: automated-testing-passed
description: updated
Revision history for this message
Kleber Sacilotto de Souza (kleber-souza) wrote :

Security fixes successfully verified by @cascardo.

tags: added: verification-testing-passed
description: updated
Revision history for this message
Stefan Bader (smb) wrote :

Looks good to go.

description: updated
description: updated
Revision history for this message
Thadeu Lima de Souza Cascardo (cascardo) wrote :

Tested reproducer for CVE-2022-29581 and CVE-2022-30594. Tests passed. Also tested ext4 truncate BUG_ON and passed.

Stefan Bader (smb)
tags: added: kernel-override-hold-promote-to-updates
description: updated
description: updated
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux - 5.15.0-33.34

---------------
linux (5.15.0-33.34) jammy; urgency=medium

  * jammy/linux: 5.15.0-33.34 -proposed tracker (LP: #1973924)

  * CVE-2022-29581
    - net/sched: cls_u32: fix netns refcount changes in u32_change()

  * ext4: limit length to bitmap_maxbytes (LP: #1972281)
    - ext4: limit length to bitmap_maxbytes - blocksize in punch_hole

  * Unprivileged users may use PTRACE_SEIZE to set PTRACE_O_SUSPEND_SECCOMP
    option (LP: #1972740)
    - ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE

 -- Stefan Bader <email address hidden> Wed, 18 May 2022 15:11:00 +0200

Changed in linux (Ubuntu Jammy):
status: New → Fix Released
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Ubuntu Kernel Bot (ubuntu-kernel-bot) wrote : Workflow done!

All tasks have been completed and the bug is being set to Fix Released

Changed in kernel-sru-workflow:
status: In Progress → Fix Released
tags: removed: kernel-release-tracking-bug-live
description: updated
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.