Precise update to 3.2.75 stable release

Bug #1530842 reported by Luis Henriques
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
Invalid
Undecided
Unassigned
Precise
Fix Released
Undecided
Unassigned

Bug Description

SRU Justification

    Impact:
       The upstream process for stable tree updates is quite similar
       in scope to the Ubuntu SRU process, e.g., each patch has to
       demonstrably fix a bug, and each patch is vetted by upstream
       by originating either directly from Linus' tree or in a minimally
       backported form of that patch. The 3.2.75 upstream stable
       patch set is now available. It should be included in the Ubuntu
       kernel as well.

       git://git.kernel.org/

    TEST CASE: TBD

       The following patches are in the 3.2.75 stable release:

fuse: break infinite loop in fuse_fill_write_pages()
sctp: translate host order to network order when setting a hmacid
ALSA: usb-audio: add packet size quirk for the Medeli DD305
ALSA: usb-audio: prevent CH345 multiport output SysEx corruption
ALSA: usb-audio: work around CH345 input SysEx corruption
USB: serial: option: add support for Novatel MiFi USB620L
USB: serial: ti_usb_3410_5052: add Abbott strip port ID to combined table as well.
USB: ti_usb_3410_502: Fix ID table size
USB: ti_usb_3410_5052: Add Honeywell HGI80 ID
usb: musb: core: fix order of arguments to ulpi write callback
ASoC: wm8962: correct addresses for HPF_C_0/1
net: fix __netdev_update_features return on ndo_set_features failure
FS-Cache: Add missing initialization of ret in cachefiles_write_page()
mac80211: mesh: fix call_rcu() usage
macvlan: fix leak in macvlan_handle_frame
xhci: Add XHCI_INTEL_HOST quirk
xhci: Workaround to get Intel xHCI reset working more reliably
USB: option: add XS Stick W100-2 from 4G Systems
usblp: do not set TASK_INTERRUPTIBLE before lock
mac: validate mac_partition is within sector
ip6mr: call del_timer_sync() in ip6mr_free_table()
net: ip6mr: fix static mfc/dev leaks on table destruction
can: sja1000: clear interrupts on start
USB: cp210x: Remove CP2110 ID from compatibility list
USB: cdc-acm - Add IGNORE_DEVICE quirk
USB: cdc_acm: Ignore Infineon Flash Loader utility
unix: avoid use-after-free in ep_remove_wait_queue
fix sysvfs symlinks
vfs: Make sendfile(2) killable even better
vfs: Avoid softlockups with sendfile(2)
broadcom: fix PHY_ID_BCM5481 entry in the id table
ring-buffer: Update read stamp with first real commit on page
ext4: Fix handling of extended tv_sec
jbd2: Fix unreclaimed pages after truncate in data=journal mode
RDS: fix race condition when sending a message on unbound socket
nfs: if we have no valid attrs, then don't declare the attribute cache valid
drm/ttm: Fixed a read/write lock imbalance
AHCI: Fix softreset failed issue of Port Multiplier
sata_sil: disable trim
wan/x25: Fix use-after-free in x25_asy_open_tty()
USB: whci-hcd: add check for dma mapping error
usb: Use the USB_SS_MULT() macro to decode burst multiplier for log message
dm btree: fix leak of bufio-backed block in btree_split_sibling error path
ipv4: igmp: Allow removing groups from a removed interface
locking: Add WARN_ON_ONCE lock assertion
drm: Fix an unwanted master inheritance v2
sched/core: Remove false-positive warning from wake_up_process()
sched/core: Clear the root_domain cpumasks in init_rootdomain()
usb: xhci: fix config fail of FS hub behind a HS hub with MTT
ALSA: rme96: Fix unexpected volume reset after rate changes
9p: ->evict_inode() should kick out ->i_data, not ->i_mapping
ipmi: move timer init to before irq is setup
dm btree: fix bufio buffer leaks in dm_btree_del() error path
vgaarb: fix signal handling in vga_get()
parisc iommu: fix panic due to trying to allocate too large region
mm, vmstat: allow WQ concurrency to discover memory reclaim doesn't make any progress
mm: hugetlb: call huge_pte_alloc() only if ptep is null
sh64: fix __NR_fgetxattr
snmp: Remove duplicate OUTMCAST stat increment
tcp: initialize tp->copied_seq in case of cross SYN connection
net, scm: fix PaX detected msg_controllen overflow in scm_detach_fds
net: ipmr: fix static mfc/dev leaks on table destruction
ipv6: distinguish frag queues by device for multicast and link-local packets
dccp: remove unnecessary codes in ipv6.c
ipv6: add complete rcu protection around np->opt
ipv6: sctp: implement sctp_v6_destroy_sock()
atl1c: Improve driver not to do order 4 GFP_ATOMIC allocation
sctp: update the netstamp_needed counter when copying sockets
ipv6: sctp: clone options to avoid use after free
net: add validation for the socket syscall protocol argument
sh_eth: fix kernel oops in skb_put()
pptp: verify sockaddr_len in pptp_bind() and pptp_connect()
bluetooth: Validate socket address length in sco_sock_bind().
af_unix: Revert 'lock_interruptible' in stream receive code
af_unix: fix a fatal race with bit fields
isdn_ppp: Add checks for allocation failure in isdn_ppp_open()
ppp, slip: Validate VJ compression slot parameters completely
Linux 3.2.75

CVE References

Luis Henriques (henrix)
tags: added: kernel-stable-tracking-bug
Changed in linux (Ubuntu):
status: New → Invalid
description: updated
Luis Henriques (henrix)
Changed in linux (Ubuntu Precise):
status: New → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (10.4 KiB)

This bug was fixed in the package linux - 3.2.0-98.138

---------------
linux (3.2.0-98.138) precise; urgency=low

  [ Luis Henriques ]

  * Release Tracking Bug
    - LP: #1532774

  [ Upstream Kernel Changes ]

  * Revert "xhci: don't finish a TD if we get a short transfer event mid
    TD"
    - LP: #1529077
  * PCI: Fix devfn for VPD access through function 0
    - LP: #1524292
  * PCI: Use function 0 VPD for identical functions, regular VPD for others
    - LP: #1524292
  * mac80211: fix driver RSSI event calculations
    - LP: #1524292
  * HID: core: Avoid uninitialized buffer access
    - LP: #1524292
  * wm831x_power: Use IRQF_ONESHOT to request threaded IRQs
    - LP: #1524292
  * mwifiex: fix mwifiex_rdeeprom_read()
    - LP: #1524292
  * mtd: mtdpart: fix add_mtd_partitions error path
    - LP: #1524292
  * devres: fix a for loop bounds check
    - LP: #1524292
  * packet: fix match_fanout_group()
    - LP: #1524292
  * Btrfs: added helper btrfs_next_item()
    - LP: #1524292
  * Btrfs: fix file corruption and data loss after cloning inline extents
    - LP: #1524292
  * iommu/vt-d: Fix ATSR handling for Root-Complex integrated endpoints
    - LP: #1524292
  * ARM: pxa: remove incorrect __init annotation on pxa27x_set_pwrmode
    - LP: #1524292
  * Btrfs: don't use ram_bytes for uncompressed inline items
    - LP: #1524292
  * Btrfs: fix truncation of compressed and inlined extents
    - LP: #1524292
  * ext4, jbd2: ensure entering into panic after recording an error in
    superblock
    - LP: #1524292
  * Bluetooth: ath3k: Add new AR3012 0930:021c id
    - LP: #1502781, #1524292
  * Bluetooth: ath3k: Add support of AR3012 0cf3:817b device
    - LP: #1506615, #1524292
  * staging: rtl8712: Add device ID for Sitecom WLA2100
    - LP: #1524292
  * ACPI: Use correct IRQ when uninstalling ACPI interrupt handler
    - LP: #1524292
  * MIPS: atomic: Fix comment describing atomic64_add_unless's return
    value.
    - LP: #1524292
  * ALSA: hda - Disable 64bit address for Creative HDA controllers
    - LP: #1524292
  * megaraid_sas: Do not use PAGE_SIZE for max_sectors
    - LP: #1524292
  * can: Use correct type in sizeof() in nla_put()
    - LP: #1524292
  * mtd: blkdevs: fix potential deadlock + lockdep warnings
    - LP: #1524292
  * crypto: algif_hash - Only export and import on sockets with data
    - LP: #1524292
  * megaraid_sas : SMAP restriction--do not access user memory from IOCTL
    code
    - LP: #1524292
  * recordmcount: Fix endianness handling bug for nop_mcount
    - LP: #1524292
  * ipv6: fix tunnel error handling
    - LP: #1524292
  * ALSA: hda - Apply pin fixup for HP ProBook 6550b
    - LP: #1524292
  * firewire: ohci: fix JMicron JMB38x IT context discovery
    - LP: #1524292
  * scsi: restart list search after unlock in scsi_remove_target
    - LP: #1524292
  * x86/cpu: Call verify_cpu() after having entered long mode too
    - LP: #1524292
  * Btrfs: fix race leading to incorrect item deletion when dropping
    extents
    - LP: #1524292
  * Btrfs: fix race leading to BUG_ON when running delalloc for nodatacow
    - LP: #1524292
  * perf: Fix inherited events vs. tracepoint filters
    - LP: #1524292
  * scsi_s...

Changed in linux (Ubuntu Precise):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.