diff --git a/.gitignore b/.gitignore index 1a277e8da..36caddb08 100644 --- a/.gitignore +++ b/.gitignore @@ -1,12 +1,10 @@ fedoraimaca.x509 -kernel-abi-stablelists-6.12.0-211.34.1.el10_2.tar.xz -kernel-kabi-dw-6.12.0-211.34.1.el10_2.tar.xz -linux-6.12.0-211.34.1.el10_2.tar.xz +kernel-abi-stablelists-6.12.0-211.37.1.el10_2.tar.xz +kernel-kabi-dw-6.12.0-211.37.1.el10_2.tar.xz +linux-6.12.0-211.37.1.el10_2.tar.xz nvidiabfdpu.x509 nvidiagpuoot001.x509 nvidiajetsonsoc.x509 -olima1.x509 -olimaca1.x509 redhatsecureboot501.cer redhatsecureboot504.cer redhatsecurebootca5.cer diff --git a/1100-nfsd-fix-secinfo-no-name-decode-error-cleanup.patch b/1100-nfsd-fix-secinfo-no-name-decode-error-cleanup.patch deleted file mode 100644 index 9c7a8eab7..000000000 --- a/1100-nfsd-fix-secinfo-no-name-decode-error-cleanup.patch +++ /dev/null @@ -1,51 +0,0 @@ -From 161d1aaeb04d620d3692639700512bb5038c1e10 Mon Sep 17 00:00:00 2001 -From: Guannan Wang -Date: Thu, 21 May 2026 16:03:32 +0800 -Subject: [PATCH] NFSD: Fix SECINFO_NO_NAME decode error cleanup - -commit 9e18e83b8846a5c3fe13fc8a464b4865d33996c6 upstream. - -CVE-2026-53398 -Backported-from linux-6.12.y commit 161d1aaeb04d620d3692639700512bb5038c1e10 - -nfsd4_decode_secinfo_no_name() currently initializes sin_exp after -decoding sin_style. If the XDR stream is truncated, the decoder returns -nfserr_bad_xdr before sin_exp is initialized. - -Since commit 3fdc54646234 ("NFSD: Reduce amount of struct -nfsd4_compoundargs that needs clearing"), the inline iops array is not -cleared between RPC calls. A failed SECINFO_NO_NAME decode can therefore -leave sin_exp holding stale union contents from a previous operation. - -The error response path still invokes nfsd4_secinfo_no_name_release(), -which calls exp_put() on a non-NULL sin_exp. - -Initialize sin_exp before the first failable decode step, matching -nfsd4_decode_secinfo(). - -Fixes: 3fdc54646234 ("NFSD: Reduce amount of struct nfsd4_compoundargs that needs clearing") -Cc: stable@vger.kernel.org -Signed-off-by: Guannan Wang -Signed-off-by: Chuck Lever -Signed-off-by: Greg Kroah-Hartman - -diff --git a/fs/nfsd/nfs4xdr.c b/fs/nfsd/nfs4xdr.c -index 8471371c6888..9c8767cab51d 100644 ---- a/fs/nfsd/nfs4xdr.c -+++ b/fs/nfsd/nfs4xdr.c -@@ -1849,10 +1849,11 @@ static __be32 nfsd4_decode_secinfo_no_name(struct nfsd4_compoundargs *argp, - union nfsd4_op_u *u) - { - struct nfsd4_secinfo_no_name *sin = &u->secinfo_no_name; -+ -+ sin->sin_exp = NULL; - if (xdr_stream_decode_u32(argp->xdr, &sin->sin_style) < 0) - return nfserr_bad_xdr; - -- sin->sin_exp = NULL; - return nfs_ok; - } - --- -2.50.1 (Apple Git-155) - diff --git a/1101-nfsd-release-layout-stid-on-setlease-failure.patch b/1101-nfsd-release-layout-stid-on-setlease-failure.patch deleted file mode 100644 index f9aae63af..000000000 --- a/1101-nfsd-release-layout-stid-on-setlease-failure.patch +++ /dev/null @@ -1,78 +0,0 @@ -From 30d55c8aabb261bc3f427d6b9aae7ef6206063f9 Mon Sep 17 00:00:00 2001 -From: Chris Mason -Date: Mon, 18 May 2026 13:16:36 -0700 -Subject: [PATCH] nfsd: release layout stid on setlease failure - -commit 30d55c8aabb261bc3f427d6b9aae7ef6206063f9 upstream. - -nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via -idr_alloc_cyclic() under cl_lock before returning to -nfsd4_alloc_layout_stateid(). When nfsd4_layout_setlease() then -fails, the error path frees the layout stateid directly with -kmem_cache_free() without ever calling idr_remove(), leaving the -IDR slot pointing at freed slab memory. Any subsequent IDR walker -(states_show, client teardown) dereferences the dangling pointer. - -The correct teardown for an IDR-published stid is nfs4_put_stid(), -which removes the IDR slot under cl_lock, dispatches sc_free -(nfsd4_free_layout_stateid) to release ls->ls_file via -nfsd4_close_layout(), and drops the nfs4_file reference in its -tail. - -A second issue blocks that switch: nfsd4_free_layout_stateid() -unconditionally inspects ls->ls_fence_work via -delayed_work_pending() under ls_lock, but -INIT_DELAYED_WORK(&ls->ls_fence_work, ...) currently runs only -after the setlease call. On the setlease-failure path the -destructor would touch an uninitialized delayed_work. - - nfsd4_alloc_layout_stateid() - nfs4_alloc_stid() /* idr_alloc_cyclic under cl_lock */ - nfsd4_layout_setlease() /* fails */ - nfs4_put_stid() - nfsd4_free_layout_stateid() - delayed_work_pending(&ls->ls_fence_work) /* needs INIT */ - nfsd4_close_layout() /* nfsd_file_put(ls->ls_file) */ - put_nfs4_file() - -Fix by hoisting the ls_fenced / ls_fence_delay / INIT_DELAYED_WORK -initialization above the nfsd4_layout_setlease() call, and replace -the manual nfsd_file_put + put_nfs4_file + kmem_cache_free cleanup -with a single nfs4_put_stid(stp). - -Fixes: c5c707f96fc9 ("nfsd: implement pNFS layout recalls") -Cc: stable@vger.kernel.org -Assisted-by: kres (claude-opus-4-7) -Signed-off-by: Chris Mason -Reviewed-by: Jeff Layton -Signed-off-by: Chuck Lever - -CVE-2026-53399 - -[ Backported from mainline commit 30d55c8aabb261bc3f427d6b9aae7ef6206063f9. - The a10 struct nfs4_layout_stateid has no ls_fenced / ls_fence_delay / - ls_fence_work fields (layout fencing was introduced upstream after 6.12), - and nfsd4_free_layout_stateid() never touches a delayed_work, so the - "second issue" does not exist here. Only the core hunk applies: replace - the manual nfsd_file_put + put_nfs4_file + kmem_cache_free cleanup on the - setlease-failure path with a single nfs4_put_stid(stp), which performs - idr_remove() under cl_lock and the full teardown. ] -Signed-off-by: Andrew Lukoshko ---- -diff --git a/fs/nfsd/nfs4layouts.c b/fs/nfsd/nfs4layouts.c -index 683bd11..62762e4 100644 ---- a/fs/nfsd/nfs4layouts.c -+++ b/fs/nfsd/nfs4layouts.c -@@ -256,9 +256,7 @@ nfsd4_alloc_layout_stateid(struct nfsd4_compound_state *cstate, - BUG_ON(!ls->ls_file); - - if (nfsd4_layout_setlease(ls)) { -- nfsd_file_put(ls->ls_file); -- put_nfs4_file(fp); -- kmem_cache_free(nfs4_layout_stateid_cache, ls); -+ nfs4_put_stid(stp); - return NULL; - } - --- -2.47.3 diff --git a/1102-kvm-svm-fix-page-overflow-in-sev-dbg-crypt-for-encrypt.patch b/1102-kvm-svm-fix-page-overflow-in-sev-dbg-crypt-for-encrypt.patch deleted file mode 100644 index 8cf31fda5..000000000 --- a/1102-kvm-svm-fix-page-overflow-in-sev-dbg-crypt-for-encrypt.patch +++ /dev/null @@ -1,97 +0,0 @@ -From e1a0fe288dee07b7da25a71e007c1ecd1080315b Mon Sep 17 00:00:00 2001 -From: Ashutosh Desai -Date: Fri, 1 May 2026 13:35:32 -0700 -Subject: [PATCH] KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT - path - -commit 78ee2d50185a037b3d2452a97f3dad69c3f7f389 upstream. - -CVE-2026-63794 -Backported-from linux-6.12.y commit e1a0fe288dee07b7da25a71e007c1ecd1080315b - -In sev_dbg_crypt(), the per-iteration transfer length is bounded by -the source page offset (PAGE_SIZE - s_off) but not by the destination -page offset (PAGE_SIZE - d_off). When d_off > s_off, the encrypt -path (__sev_dbg_encrypt_user) performs a read-modify-write using a -single-page intermediate buffer (dst_tpage): - - 1. __sev_dbg_decrypt() expands the size to round_up(len + (d_off & 15), 16) - before issuing the PSP command. If len + (d_off & 15) > PAGE_SIZE, - the PSP writes beyond the end of the 4096-byte dst_tpage allocation. - - 2. The subsequent memcpy()/copy_from_user() into - page_address(dst_tpage) + (d_off & 15) of 'len' bytes overflows - by up to 15 bytes under the same condition. - -Trigger example: s_off = 0, d_off = 1, debug.len = PAGE_SIZE - -the PSP is instructed to write round_up(4097, 16) = 4112 bytes to -a 4096-byte buffer. - -Fix by also bounding len by (PAGE_SIZE - d_off), the same check that -sev_send_update_data() already performs for its single-page guest -region. - - ================================================================== - BUG: KASAN: slab-use-after-free in sev_dbg_crypt+0x993/0xd10 [kvm_amd] - Write of size 4095 at addr ff110062293bb009 by task sev_dbg_test/228214 - - CPU: 96 UID: 0 PID: 228214 Comm: sev_dbg_test Tainted: G U W 7.0.0-smp--5ce9b0c48211-dbg #156 PREEMPTLAZY - Tainted: [U]=USER, [W]=WARN - Hardware name: Google Astoria/astoria, BIOS 0.20250817.1-0 08/25/2025 - Call Trace: - - dump_stack_lvl+0x54/0x70 - print_report+0xbc/0x260 - kasan_report+0xa2/0xd0 - kasan_check_range+0x25f/0x2c0 - __asan_memcpy+0x40/0x70 - sev_dbg_crypt+0x993/0xd10 [kvm_amd] - sev_mem_enc_ioctl+0x33c/0x450 [kvm_amd] - kvm_vm_ioctl+0x65d/0x6d0 [kvm] - __se_sys_ioctl+0xb2/0x100 - do_syscall_64+0xe8/0x870 - entry_SYSCALL_64_after_hwframe+0x4b/0x53 - - - The buggy address belongs to the physical page: - page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x7fe72b6a0 pfn:0x62293bb - memcg:ff11000112827d82 - flags: 0x1400000000000000(node=1|zone=1) - raw: 1400000000000000 0000000000000000 dead000000000122 0000000000000000 - raw: 00000007fe72b6a0 0000000000000000 00000001ffffffff ff11000112827d82 - page dumped because: kasan: bad access detected - - Memory state around the buggy address: - ff110062293bbf00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 - ff110062293bbf80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 - >ff110062293bc000: fa fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc - ^ - ff110062293bc080: fa fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc - ff110062293bc100: fa fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc - ================================================================== - Disabling lock debugging due to kernel taint - -Fixes: 24f41fb23a39 ("KVM: SVM: Add support for SEV DEBUG_DECRYPT command") -Fixes: 7d1594f5d94b ("KVM: SVM: Add support for SEV DEBUG_ENCRYPT command") -Cc: stable@vger.kernel.org -Signed-off-by: Ashutosh Desai -[sean: add sample KASAN splat, Fixes, and stable@] -Link: https://patch.msgid.link/20260501203537.2120074-2-seanjc@google.com -Signed-off-by: Sean Christopherson -Signed-off-by: Greg Kroah-Hartman - -diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c -index 6032d7e69a20..ccfa4924196a 100644 ---- a/arch/x86/kvm/svm/sev.c -+++ b/arch/x86/kvm/svm/sev.c -@@ -1280,6 +1280,7 @@ static int sev_dbg_crypt(struct kvm *kvm, struct kvm_sev_cmd *argp, bool dec) - s_off = vaddr & ~PAGE_MASK; - d_off = dst_vaddr & ~PAGE_MASK; - len = min_t(size_t, (PAGE_SIZE - s_off), size); -+ len = min_t(size_t, len, PAGE_SIZE - d_off); - - if (dec) - ret = __sev_dbg_decrypt_user(kvm, --- -2.50.1 (Apple Git-155) - diff --git a/1103-rpmsg-char-fix-use-after-free-on-probe-error-path.patch b/1103-rpmsg-char-fix-use-after-free-on-probe-error-path.patch deleted file mode 100644 index 3ebb4fba1..000000000 --- a/1103-rpmsg-char-fix-use-after-free-on-probe-error-path.patch +++ /dev/null @@ -1,84 +0,0 @@ -From c5ebb06c7e24d531b68707168e04698859d642bc Mon Sep 17 00:00:00 2001 -From: Yuho Choi -Date: Mon, 1 Jun 2026 14:32:47 -0400 -Subject: [PATCH] rpmsg: char: Fix use-after-free on probe error path - -commit 1ff3f528e67d20e2b1483dcaba899dc7832b2e6b upstream. - -CVE-2026-63797 -Backported-from linux-6.12.y commit c5ebb06c7e24d531b68707168e04698859d642bc - -rpmsg_chrdev_probe() stores the newly allocated eptdev in the default -endpoint's priv pointer before calling rpmsg_chrdev_eptdev_add(). If -rpmsg_chrdev_eptdev_add() then fails, its error path frees eptdev while -the default endpoint may still dispatch callbacks with the stale priv -pointer. - -Avoid publishing eptdev through the default endpoint until -rpmsg_chrdev_eptdev_add() succeeds. Messages received before the priv -pointer is published should be ignored by rpmsg_ept_cb(). Flow-control -updates can hit rpmsg_ept_flow_cb() in the same window, so make both -callbacks return success when priv is NULL. - -Fixes: bc69d1066569 ("rpmsg: char: Introduce the "rpmsg-raw" channel") -Signed-off-by: Yuho Choi -Cc: stable@vger.kernel.org -Link: https://lore.kernel.org/r/20260601183247.1962010-1-dbgh9129@gmail.com -Signed-off-by: Mathieu Poirier -Signed-off-by: Greg Kroah-Hartman - -diff --git a/drivers/rpmsg/rpmsg_char.c b/drivers/rpmsg/rpmsg_char.c -index 96fcdd2d7093..d918cb30db9b 100644 ---- a/drivers/rpmsg/rpmsg_char.c -+++ b/drivers/rpmsg/rpmsg_char.c -@@ -104,6 +104,9 @@ static int rpmsg_ept_cb(struct rpmsg_device *rpdev, void *buf, int len, - struct rpmsg_eptdev *eptdev = priv; - struct sk_buff *skb; - -+ if (!eptdev) -+ return 0; -+ - skb = alloc_skb(len, GFP_ATOMIC); - if (!skb) - return -ENOMEM; -@@ -124,6 +127,9 @@ static int rpmsg_ept_flow_cb(struct rpmsg_device *rpdev, void *priv, bool enable - { - struct rpmsg_eptdev *eptdev = priv; - -+ if (!eptdev) -+ return 0; -+ - eptdev->remote_flow_restricted = enable; - eptdev->remote_flow_updated = true; - -@@ -490,6 +496,7 @@ static int rpmsg_chrdev_probe(struct rpmsg_device *rpdev) - struct rpmsg_channel_info chinfo; - struct rpmsg_eptdev *eptdev; - struct device *dev = &rpdev->dev; -+ int ret; - - memcpy(chinfo.name, rpdev->id.name, RPMSG_NAME_SIZE); - chinfo.src = rpdev->src; -@@ -502,13 +509,17 @@ static int rpmsg_chrdev_probe(struct rpmsg_device *rpdev) - /* Set the default_ept to the rpmsg device endpoint */ - eptdev->default_ept = rpdev->ept; - -+ ret = rpmsg_chrdev_eptdev_add(eptdev, chinfo); -+ -+ if (ret) -+ return ret; - /* - * The rpmsg_ept_cb uses *priv parameter to get its rpmsg_eptdev context. -- * Storedit in default_ept *priv field. -+ * Stored it in default_ept *priv field. - */ - eptdev->default_ept->priv = eptdev; - -- return rpmsg_chrdev_eptdev_add(eptdev, chinfo); -+ return 0; - } - - static void rpmsg_chrdev_remove(struct rpmsg_device *rpdev) --- -2.50.1 (Apple Git-155) - diff --git a/1104-keys-fix-overflow-in-keyctl-pkey-params-get-2.patch b/1104-keys-fix-overflow-in-keyctl-pkey-params-get-2.patch deleted file mode 100644 index a452fa0bd..000000000 --- a/1104-keys-fix-overflow-in-keyctl-pkey-params-get-2.patch +++ /dev/null @@ -1,68 +0,0 @@ -From 5165f1cc727f1322456735df212d8e26ec237a8d Mon Sep 17 00:00:00 2001 -From: Jarkko Sakkinen -Date: Mon, 1 Jun 2026 23:11:54 +0300 -Subject: [PATCH] KEYS: fix overflow in keyctl_pkey_params_get_2() - -commit cb481e59ea6cae3b7796ac1d7a22b6b24c3f3c0b upstream. - -CVE-2026-63824 -Backported-from linux-6.12.y commit 5165f1cc727f1322456735df212d8e26ec237a8d - -The length for the internal output buffer is calculated incorrectly, which -can result overflow when a too small buffer is provided. - -Fix the bug by allocating internal output with the size of the maximum -length of the cryptographic primitive instead of caller provided size. - -Link: https://lore.kernel.org/keyrings/20260531024914.3712130-1-jarkko@kernel.org/ -Cc: stable@vger.kernel.org # v4.20+ -Fixes: 00d60fd3b932 ("KEYS: Provide keyctls to drive the new key type ops for asymmetric keys [ver #2]") -Reported-by: Alessandro Groppo -Tested-by: Alessandro Groppo -Signed-off-by: Jarkko Sakkinen -Signed-off-by: Greg Kroah-Hartman - -diff --git a/security/keys/keyctl_pkey.c b/security/keys/keyctl_pkey.c -index 97bc27bbf079..ba150ee2d4a3 100644 ---- a/security/keys/keyctl_pkey.c -+++ b/security/keys/keyctl_pkey.c -@@ -138,28 +138,35 @@ static int keyctl_pkey_params_get_2(const struct keyctl_pkey_params __user *_par - if (uparams.in_len > info.max_dec_size || - uparams.out_len > info.max_enc_size) - return -EINVAL; -+ -+ params->out_len = info.max_enc_size; - break; - case KEYCTL_PKEY_DECRYPT: - if (uparams.in_len > info.max_enc_size || - uparams.out_len > info.max_dec_size) - return -EINVAL; -+ -+ params->out_len = info.max_dec_size; - break; - case KEYCTL_PKEY_SIGN: - if (uparams.in_len > info.max_data_size || - uparams.out_len > info.max_sig_size) - return -EINVAL; -+ -+ params->out_len = info.max_sig_size; - break; - case KEYCTL_PKEY_VERIFY: - if (uparams.in_len > info.max_data_size || - uparams.in2_len > info.max_sig_size) - return -EINVAL; -+ -+ params->out_len = info.max_sig_size; - break; - default: - BUG(); - } - - params->in_len = uparams.in_len; -- params->out_len = uparams.out_len; /* Note: same as in2_len */ - return 0; - } - --- -2.50.1 (Apple Git-155) - diff --git a/1105-net-ip-gre-require-cap-net-admin-in-the-device-netns-fo.patch b/1105-net-ip-gre-require-cap-net-admin-in-the-device-netns-fo.patch deleted file mode 100644 index 1abfbf1ec..000000000 --- a/1105-net-ip-gre-require-cap-net-admin-in-the-device-netns-fo.patch +++ /dev/null @@ -1,101 +0,0 @@ -From 9831bc9ecb402957810c2045c663fbfe9b09e296 Mon Sep 17 00:00:00 2001 -From: Maoyi Xie -Date: Fri, 12 Jun 2026 16:59:35 +0800 -Subject: [PATCH] net: ip_gre: require CAP_NET_ADMIN in the device netns for - changelink - -commit 8165f7ff57d9667d2bb477ef6af83ede7fed4ad7 upstream. - -CVE-2026-63829 -Backported-from linux-6.12.y commit 9831bc9ecb402957810c2045c663fbfe9b09e296 - -A tunnel changelink() operates on at most two netns, dev_net(dev) and -the tunnel link netns t->net. They differ once the device is created in -or moved to a netns other than the one the request runs in. The rtnl -changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a -caller privileged there but not in t->net can rewrite a tunnel that -lives in t->net. - -Add rtnl_dev_link_net_capable() next to rtnl_get_net_ns_capable() in -net/core/rtnetlink.c. It requires CAP_NET_ADMIN in the link netns and is -skipped when the link netns is dev_net(dev), where the rtnl path already -checked it. The other patches in this series use the same helper. - -Gate ipgre_changelink() and erspan_changelink() with it, at the top of -the op before any attribute is parsed, because the parsers update live -tunnel fields first. ipgre_netlink_parms() sets t->collect_md before -ip_tunnel_changelink() runs. - -Commit 8b484efd5cb4 ("ip6: vti: Use ip6_tnl.net in -vti6_siocdevprivate().") added the same check on the ioctl path. This -adds it on RTM_NEWLINK. - -Reported-by: Xiao Liang -Closes: https://lore.kernel.org/netdev/CABAhCOSzP1vaThGV35_VnsRCb=87_CPjPVsTHbq905k8A+BuUg@mail.gmail.com/ -Fixes: b57708add314 ("gre: add x-netns support") -Cc: stable@vger.kernel.org -Signed-off-by: Maoyi Xie -Reviewed-by: Kuniyuki Iwashima -Link: https://patch.msgid.link/20260612085941.3158249-2-maoyixie.tju@gmail.com -Signed-off-by: Jakub Kicinski -Signed-off-by: Greg Kroah-Hartman - -diff --git a/include/net/rtnetlink.h b/include/net/rtnetlink.h -index 2d3eb7cb4dff..7c057611f4ab 100644 ---- a/include/net/rtnetlink.h -+++ b/include/net/rtnetlink.h -@@ -212,6 +212,8 @@ int rtnl_configure_link(struct net_device *dev, const struct ifinfomsg *ifm, - int rtnl_nla_parse_ifinfomsg(struct nlattr **tb, const struct nlattr *nla_peer, - struct netlink_ext_ack *exterr); - struct net *rtnl_get_net_ns_capable(struct sock *sk, int netnsid); -+bool rtnl_dev_link_net_capable(const struct net_device *dev, -+ const struct net *link_net); - - #define MODULE_ALIAS_RTNL_LINK(kind) MODULE_ALIAS("rtnl-link-" kind) - -diff --git a/net/core/rtnetlink.c b/net/core/rtnetlink.c -index 2176cd1bc765..118612325ce9 100644 ---- a/net/core/rtnetlink.c -+++ b/net/core/rtnetlink.c -@@ -2205,6 +2205,14 @@ struct net *rtnl_get_net_ns_capable(struct sock *sk, int netnsid) - } - EXPORT_SYMBOL_GPL(rtnl_get_net_ns_capable); - -+bool rtnl_dev_link_net_capable(const struct net_device *dev, -+ const struct net *link_net) -+{ -+ return net_eq(link_net, dev_net(dev)) || -+ ns_capable(link_net->user_ns, CAP_NET_ADMIN); -+} -+EXPORT_SYMBOL_GPL(rtnl_dev_link_net_capable); -+ - static int rtnl_valid_dump_ifinfo_req(const struct nlmsghdr *nlh, - bool strict_check, struct nlattr **tb, - struct netlink_ext_ack *extack) -diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c -index 084556b03a2e..ffad16b023ad 100644 ---- a/net/ipv4/ip_gre.c -+++ b/net/ipv4/ip_gre.c -@@ -1446,6 +1446,9 @@ static int ipgre_changelink(struct net_device *dev, struct nlattr *tb[], - __u32 fwmark = t->fwmark; - int err; - -+ if (!rtnl_dev_link_net_capable(dev, t->net)) -+ return -EPERM; -+ - err = ipgre_newlink_encap_setup(dev, data); - if (err) - return err; -@@ -1475,6 +1478,9 @@ static int erspan_changelink(struct net_device *dev, struct nlattr *tb[], - __u32 fwmark = t->fwmark; - int err; - -+ if (!rtnl_dev_link_net_capable(dev, t->net)) -+ return -EPERM; -+ - err = ipgre_newlink_encap_setup(dev, data); - if (err) - return err; --- -2.50.1 (Apple Git-155) - diff --git a/1106-wifi-iwlwifi-mld-fix-tso-segmentation-explosion-when-am.patch b/1106-wifi-iwlwifi-mld-fix-tso-segmentation-explosion-when-am.patch deleted file mode 100644 index f8b423678..000000000 --- a/1106-wifi-iwlwifi-mld-fix-tso-segmentation-explosion-when-am.patch +++ /dev/null @@ -1,77 +0,0 @@ -From 92cee08dc4f00e77fd1317e4343c5d458b0abab7 Mon Sep 17 00:00:00 2001 -From: Cole Leavitt -Date: Sat, 4 Apr 2026 22:41:44 -0700 -Subject: [PATCH] wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU - is disabled - -commit 92cee08dc4f00e77fd1317e4343c5d458b0abab7 upstream. - -When the TLC notification disables AMSDU for a TID, the MLD driver sets -max_tid_amsdu_len to the sentinel value 1. The TSO segmentation path in -iwl_mld_tx_tso_segment() checks for zero but not for this sentinel, -allowing it to reach the num_subframes calculation: - - num_subframes = (max_tid_amsdu_len + pad) / (subf_len + pad) - = (1 + 2) / (1534 + 2) = 0 - -This zero propagates to iwl_tx_tso_segment() which sets: - - gso_size = num_subframes * mss = 0 - -Calling skb_gso_segment() with gso_size=0 creates over 32000 tiny -segments from a single GSO skb. This floods the TX ring with ~1024 -micro-frames (the rest are purged), creating a massive burst of TX -completion events that can lead to memory corruption and a subsequent -use-after-free in TCP's retransmit queue (refcount underflow in -tcp_shifted_skb, NULL deref in tcp_rack_detect_loss). - -The MVM driver is immune because it checks mvmsta->amsdu_enabled before -reaching the num_subframes calculation. The MLD driver has no equivalent -bitmap check and relies solely on max_tid_amsdu_len, which does not -catch the sentinel value. - -Fix this by detecting the sentinel value (max_tid_amsdu_len == 1) at the -existing check and falling back to non-AMSDU TSO segmentation. Also add -a WARN_ON_ONCE guard after the num_subframes division as defense-in-depth -to catch any future code paths that produce zero through a different -mechanism. - -Suggested-by: Miriam Rachel Korenblit -Fixes: d1e879ec600f ("wifi: iwlwifi: add iwlmld sub-driver") -Signed-off-by: Cole Leavitt -Link: https://patch.msgid.link/20260405054145.1064152-3-cole@unwrap.rs -Signed-off-by: Miri Korenblit - -CVE-2026-64037 - -Backported from mainline commit 92cee08dc4f00e77fd1317e4343c5d458b0abab7. -The iwlmld sub-driver (drivers/net/wireless/intel/iwlwifi/mld/) is present -in the a10 kernel-6.12.0-211.34.1.el10_2 tree and iwl_mld_tx_tso_segment() carries the vulnerable -pre-image verbatim, so the change applies cleanly, zero-fuzz (line offset only). - -diff --git a/drivers/net/wireless/intel/iwlwifi/mld/tx.c b/drivers/net/wireless/intel/iwlwifi/mld/tx.c -index 546d09a38dab..094a28f75559 100644 ---- a/drivers/net/wireless/intel/iwlwifi/mld/tx.c -+++ b/drivers/net/wireless/intel/iwlwifi/mld/tx.c -@@ -834,7 +834,7 @@ static int iwl_mld_tx_tso_segment(struct iwl_mld *mld, struct sk_buff *skb, - return -EINVAL; - - max_tid_amsdu_len = sta->cur->max_tid_amsdu_len[tid]; -- if (!max_tid_amsdu_len) -+ if (!max_tid_amsdu_len || max_tid_amsdu_len == 1) - return iwl_tx_tso_segment(skb, 1, netdev_flags, mpdus_skbs); - - /* Sub frame header + SNAP + IP header + TCP header + MSS */ -@@ -846,6 +846,9 @@ static int iwl_mld_tx_tso_segment(struct iwl_mld *mld, struct sk_buff *skb, - */ - num_subframes = (max_tid_amsdu_len + pad) / (subf_len + pad); - -+ if (WARN_ON_ONCE(!num_subframes)) -+ return iwl_tx_tso_segment(skb, 1, netdev_flags, mpdus_skbs); -+ - if (sta->max_amsdu_subframes && - num_subframes > sta->max_amsdu_subframes) - num_subframes = sta->max_amsdu_subframes; --- -2.50.1 (Apple Git-155) - diff --git a/1107-vfio-pci-check-bar-resources-before-exporting-a-dmabuf.patch b/1107-vfio-pci-check-bar-resources-before-exporting-a-dmabuf.patch deleted file mode 100644 index 312454956..000000000 --- a/1107-vfio-pci-check-bar-resources-before-exporting-a-dmabuf.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 702809dabdecca807bdd50cfdcc1c980feb2ba62 Mon Sep 17 00:00:00 2001 -From: Matt Evans -Date: Mon, 11 May 2026 07:58:24 -0700 -Subject: [PATCH] vfio/pci: Check BAR resources before exporting a DMABUF - -commit 702809dabdecca807bdd50cfdcc1c980feb2ba62 upstream. - -A DMABUF exports access to BAR resources and, although they are -requested at startup time, we need to ensure they really were reserved -before exporting. Otherwise, it's possible to access unreserved -resources through the export. - -Add a check to the DMABUF-creation path. - -Fixes: 5d74781ebc86c ("vfio/pci: Add dma-buf export support for MMIO regions") -Signed-off-by: Matt Evans -Link: https://lore.kernel.org/r/20260511145829.2993601-3-mattev@meta.com -Signed-off-by: Alex Williamson - -CVE-2026-64042 - -Backported from mainline commit 702809dabdecca807bdd50cfdcc1c980feb2ba62. -drivers/vfio/pci/vfio_pci_dmabuf.c is present in the a10 kernel-6.12.0-211.34.1.el10_2 tree and the -exported helper vfio_pci_core_setup_barmap() exists; the vulnerable pre-image -matches verbatim, so the change applies cleanly, zero-fuzz (line offset only). - -diff --git a/drivers/vfio/pci/vfio_pci_dmabuf.c b/drivers/vfio/pci/vfio_pci_dmabuf.c -index fdc22e8b4656..1a177ce7de54 100644 ---- a/drivers/vfio/pci/vfio_pci_dmabuf.c -+++ b/drivers/vfio/pci/vfio_pci_dmabuf.c -@@ -244,9 +244,11 @@ int vfio_pci_core_feature_dma_buf(struct vfio_pci_core_device *vdev, u32 flags, - return -EINVAL; - - /* -- * For PCI the region_index is the BAR number like everything else. -+ * For PCI the region_index is the BAR number like everything -+ * else. Check that PCI resources have been claimed for it. - */ -- if (get_dma_buf.region_index >= VFIO_PCI_ROM_REGION_INDEX) -+ if (get_dma_buf.region_index >= VFIO_PCI_ROM_REGION_INDEX || -+ vfio_pci_core_setup_barmap(vdev, get_dma_buf.region_index)) - return -ENODEV; - - dma_ranges = memdup_array_user(&arg->dma_ranges, get_dma_buf.nr_ranges, --- -2.50.1 (Apple Git-155) - diff --git a/1108-accel-qaic-add-overflow-check-to-remap-pfn-range-during.patch b/1108-accel-qaic-add-overflow-check-to-remap-pfn-range-during.patch deleted file mode 100644 index c782c1ddc..000000000 --- a/1108-accel-qaic-add-overflow-check-to-remap-pfn-range-during.patch +++ /dev/null @@ -1,79 +0,0 @@ -From aa16b2bc0f02709919e2435f531406531e5bcc69 Mon Sep 17 00:00:00 2001 -From: Zack McKevitt -Date: Thu, 30 Apr 2026 12:39:01 -0700 -Subject: [PATCH] accel/qaic: Add overflow check to remap_pfn_range during mmap - -commit aa16b2bc0f02709919e2435f531406531e5bcc69 upstream. - -The call to remap_pfn_range in qaic_gem_object_mmap is susceptible to -(re)mapping beyond the VMA if the BO is too large. This can cause use -after free issues when munmap() unmaps only the VMA region and not the -additional mappings. To prevent this, check the remaining size of the -VMA before remapping and truncate the remapped length if sg->length is -too large. - -Reported-by: Lukas Maar -Fixes: ff13be830333 ("accel/qaic: Add datapath") -Reviewed-by: Karol Wachowski -Signed-off-by: Zack McKevitt -Reviewed-by: Jeff Hugo -[jhugo: fix braces from checkpatch --strict] -Signed-off-by: Jeff Hugo -Link: https://patch.msgid.link/20260430193858.1178641-1-zachary.mckevitt@oss.qualcomm.com -Signed-off-by: Sasha Levin - -CVE-2026-64051 - -[ Adjusted context: the a10 tree uses drm_gem_is_imported(obj) in place of - obj->import_attach; the code change is otherwise identical to the upstream - stable commit 8dd6edbe26770df147136c3f2ac976c873b82650 (linux-6.12.y). ] -Signed-off-by: Andrew Lukoshko ---- -diff --git a/drivers/accel/qaic/qaic_data.c b/drivers/accel/qaic/qaic_data.c -index 60cb4d6..46f2b41 100644 ---- a/drivers/accel/qaic/qaic_data.c -+++ b/drivers/accel/qaic/qaic_data.c -@@ -606,8 +606,11 @@ static const struct vm_operations_struct drm_vm_ops = { - static int qaic_gem_object_mmap(struct drm_gem_object *obj, struct vm_area_struct *vma) - { - struct qaic_bo *bo = to_qaic_bo(obj); -+ unsigned long remap_start; - unsigned long offset = 0; -+ unsigned long remap_end; - struct scatterlist *sg; -+ unsigned long length; - int ret = 0; - - if (drm_gem_is_imported(obj)) -@@ -615,11 +618,27 @@ static int qaic_gem_object_mmap(struct drm_gem_object *obj, struct vm_area_struc - - for (sg = bo->sgt->sgl; sg; sg = sg_next(sg)) { - if (sg_page(sg)) { -+ /* if sg is too large for the VMA, so truncate it to fit */ -+ if (check_add_overflow(vma->vm_start, offset, &remap_start)) -+ return -EINVAL; -+ if (check_add_overflow(remap_start, sg->length, &remap_end)) -+ return -EINVAL; -+ -+ if (remap_end > vma->vm_end) { -+ if (check_sub_overflow(vma->vm_end, remap_start, &length)) -+ return -EINVAL; -+ } else { -+ length = sg->length; -+ } -+ -+ if (length == 0) -+ goto out; -+ - ret = remap_pfn_range(vma, vma->vm_start + offset, page_to_pfn(sg_page(sg)), -- sg->length, vma->vm_page_prot); -+ length, vma->vm_page_prot); - if (ret) - goto out; -- offset += sg->length; -+ offset += length; - } - } - --- -2.47.3 diff --git a/1109-netfs-fix-early-put-of-sink-folio-in-netfs-read-gaps.patch b/1109-netfs-fix-early-put-of-sink-folio-in-netfs-read-gaps.patch deleted file mode 100644 index 0e8da05f6..000000000 --- a/1109-netfs-fix-early-put-of-sink-folio-in-netfs-read-gaps.patch +++ /dev/null @@ -1,83 +0,0 @@ -From 3e5dd91b87a8b1450217b56a336bee315f40da7d Mon Sep 17 00:00:00 2001 -From: David Howells -Date: Tue, 12 May 2026 13:33:54 +0100 -Subject: [PATCH] netfs: Fix early put of sink folio in netfs_read_gaps() - -commit 3e5dd91b87a8b1450217b56a336bee315f40da7d upstream. - -Fix netfs_read_gaps() to release the sink page it uses after waiting for -the request to complete. The way the sink page is used is that an -ITER_BVEC-class iterator is created that has the gaps from the target folio -at either end, but has the sink page tiled over the middle so that a single -read op can fill in both gaps. - -The bug was found by KASAN detecting a UAF on the generic/075 xfstest in -the cifsd kernel thread that handles reception of data from the TCP socket: - - BUG: KASAN: use-after-free in _copy_to_iter+0x48a/0xa20 - Write of size 885 at addr ffff888107f92000 by task cifsd/1285 - CPU: 2 UID: 0 PID: 1285 Comm: cifsd Not tainted 7.0.0 #6 PREEMPT(lazy) - Call Trace: - dump_stack_lvl+0x5d/0x80 - print_report+0x17f/0x4f1 - kasan_report+0x100/0x1e0 - kasan_check_range+0x10f/0x1e0 - __asan_memcpy+0x3c/0x60 - _copy_to_iter+0x48a/0xa20 - __skb_datagram_iter+0x2c9/0x430 - skb_copy_datagram_iter+0x6e/0x160 - tcp_recvmsg_locked+0xce0/0x1130 - tcp_recvmsg+0xeb/0x300 - inet_recvmsg+0xcf/0x3a0 - sock_recvmsg+0xea/0x100 - cifs_readv_from_socket+0x3a6/0x4d0 [cifs] - cifs_read_iter_from_socket+0xdd/0x130 [cifs] - cifs_readv_receive+0xaad/0xb10 [cifs] - cifs_demultiplex_thread+0x1148/0x1740 [cifs] - kthread+0x1cf/0x210 - -Fixes: ee4cdf7ba857 ("netfs: Speed up buffered reading") -Reported-by: Steve French -Signed-off-by: David Howells -Link: https://patch.msgid.link/20260512123404.719402-18-dhowells@redhat.com -Reviewed-by: Paulo Alcantara (Red Hat) -cc: Paulo Alcantara -cc: Matthew Wilcox -cc: netfs@lists.linux.dev -cc: linux-fsdevel@vger.kernel.org -Signed-off-by: Christian Brauner -Signed-off-by: Sasha Levin - -CVE-2026-64061 - -[ Adjusted context to the a10 netfs_read_gaps(): it predates the upstream - "if (group)" block, so the sink folio_put is moved to just before - folio_unlock(), immediately after the ret>=0 uptodate block. Semantically - identical to stable commit d4f4bc87c76511cf2532448b0fa40c25e894bd7d - (linux-6.12.y). ] -Signed-off-by: Andrew Lukoshko ---- -diff --git a/fs/netfs/buffered_read.c b/fs/netfs/buffered_read.c -index 37ab6f2..8bfdef9 100644 ---- a/fs/netfs/buffered_read.c -+++ b/fs/netfs/buffered_read.c -@@ -459,14 +459,14 @@ static int netfs_read_gaps(struct file *file, struct folio *folio) - - netfs_read_to_pagecache(rreq, NULL); - -- if (sink) -- folio_put(sink); -- - ret = netfs_wait_for_read(rreq); - if (ret >= 0) { - flush_dcache_folio(folio); - folio_mark_uptodate(folio); - } -+ -+ if (sink) -+ folio_put(sink); - folio_unlock(folio); - netfs_put_request(rreq, netfs_rreq_trace_put_return); - return ret < 0 ? ret : 0; --- -2.47.3 diff --git a/1110-ixgbevf-fix-use-after-free-in-vepa-multicast-source-pru.patch b/1110-ixgbevf-fix-use-after-free-in-vepa-multicast-source-pru.patch deleted file mode 100644 index a3d3b9f43..000000000 --- a/1110-ixgbevf-fix-use-after-free-in-vepa-multicast-source-pru.patch +++ /dev/null @@ -1,68 +0,0 @@ -From a244395d8c563ed1bb26c3ef708db6aeeaa08084 Mon Sep 17 00:00:00 2001 -From: Michael Bommarito -Date: Fri, 15 May 2026 11:24:14 -0700 -Subject: [PATCH] ixgbevf: fix use-after-free in VEPA multicast source pruning - -commit 5d49b568c188dc77199d8d2b959c91da8cc27cf1 upstream. - -ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's -own address (VEPA multicast workaround) by freeing the skb and -continuing to the next descriptor: - - dev_kfree_skb_irq(skb); - continue; - -The skb pointer is declared outside the while loop and persists across -iterations. Because the continue skips the "skb = NULL" reset at the -bottom of the loop, the next iteration enters the "else if (skb)" path -and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing -skb_shinfo(skb)->nr_frags - a use-after-free in NAPI softirq context. - -The sibling driver iavf already handles this correctly by nulling the -pointer before continuing. Apply the same pattern here. - -I do not have ixgbevf hardware; the bug was found by static analysis -(scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool -corroboration with the highest score in the scan). The UAF was confirmed -under KASAN by loading a test module that reproduces the exact code -pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)->nr_frags): - - BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000 - Read of size 8 at addr 000000006163ae78 by task insmod/30 - freed 208-byte region [000000006163adc0, 000000006163ae90) - -QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF -driver does not include the VEPA source pruning path, so a full -end-to-end reproduction with emulated hardware was not possible. - -Fixes: bad17234ba70 ("ixgbevf: Change receive model to use double buffered page based receives") -Cc: stable@vger.kernel.org -Signed-off-by: Michael Bommarito -Reviewed-by: Simon Horman -Tested-by: Rafal Romanowski -Signed-off-by: Tony Nguyen -Link: https://patch.msgid.link/20260515182419.1597859-8-anthony.l.nguyen@intel.com -Signed-off-by: Jakub Kicinski -Signed-off-by: Greg Kroah-Hartman - -CVE-2026-64113 - -Backported from linux-6.12.y commit a244395d8c563ed1bb26c3ef708db6aeeaa08084 -(mainline 5d49b568c188dc77199d8d2b959c91da8cc27cf1); applies cleanly to the -a10 kernel-6.12.0-211.34.1.el10_2 tree, zero-fuzz (line offset only). - -diff --git a/drivers/net/ethernet/intel/ixgbevf/ixgbevf_main.c b/drivers/net/ethernet/intel/ixgbevf/ixgbevf_main.c -index a2a7cb6d8ea1..73225f59cd6c 100644 ---- a/drivers/net/ethernet/intel/ixgbevf/ixgbevf_main.c -+++ b/drivers/net/ethernet/intel/ixgbevf/ixgbevf_main.c -@@ -1224,6 +1224,7 @@ static int ixgbevf_clean_rx_irq(struct ixgbevf_q_vector *q_vector, - ether_addr_equal(rx_ring->netdev->dev_addr, - eth_hdr(skb)->h_source)) { - dev_kfree_skb_irq(skb); -+ skb = NULL; - continue; - } - --- -2.50.1 (Apple Git-155) - diff --git a/1111-ipv6-ioam-refresh-hdr-pointer-before-ioam6-event.patch b/1111-ipv6-ioam-refresh-hdr-pointer-before-ioam6-event.patch deleted file mode 100644 index a47ad2671..000000000 --- a/1111-ipv6-ioam-refresh-hdr-pointer-before-ioam6-event.patch +++ /dev/null @@ -1,68 +0,0 @@ -From 769723124b7c3b2bfea4cf68ad292698b87c8d01 Mon Sep 17 00:00:00 2001 -From: Justin Iurman -Date: Wed, 20 May 2026 14:42:42 +0200 -Subject: [PATCH] ipv6: ioam: refresh hdr pointer before ioam6_event() - -commit e46e6bc97fb1f339730ff1ba74267fbf48e7a422 upstream. - -Reported by Sashiko: - -In ipv6_hop_ioam(), the hdr pointer is initialized to point into the -skb's linear data buffer. Later, the code calls skb_ensure_writable(), -which might reallocate the buffer: - - if (skb_ensure_writable(skb, optoff + 2 + hdr->opt_len)) - goto drop; - - /* Trace pointer may have changed */ - trace = (struct ioam6_trace_hdr *)(skb_network_header(skb) - + optoff + sizeof(*hdr)); - - ioam6_fill_trace_data(skb, ns, trace, true); - - ioam6_event(IOAM6_EVENT_TRACE, dev_net(skb->dev), - GFP_ATOMIC, (void *)trace, hdr->opt_len - 2); - -If the skb is cloned or lacks sufficient linear headroom, -skb_ensure_writable() will invoke pskb_expand_head(), which reallocates -the skb's data buffer and frees the old one, invalidating pointers to -it. While the code recalculates the trace pointer immediately after the -call to skb_ensure_writable(), it fails to recalculate the hdr pointer. - -This patch fixes the above by recalculating the hdr pointer before -passing hdr->opt_len to ioam6_event(), so that we avoid any UaF. - -Fixes: f655c78d6225 ("net: exthdrs: ioam6: send trace event") -Cc: stable@vger.kernel.org -Signed-off-by: Justin Iurman -Reviewed-by: Ido Schimmel -Link: https://patch.msgid.link/20260520124242.32320-1-justin.iurman@gmail.com -Signed-off-by: Jakub Kicinski -Signed-off-by: Greg Kroah-Hartman - -CVE-2026-64132 - -Backported from linux-6.12.y commit 769723124b7c3b2bfea4cf68ad292698b87c8d01 -(mainline e46e6bc97fb1f339730ff1ba74267fbf48e7a422); applies cleanly to the -a10 kernel-6.12.0-211.34.1.el10_2 tree, zero-fuzz (line offset only). - -diff --git a/net/ipv6/exthdrs.c b/net/ipv6/exthdrs.c -index d09ae48030b3..a330aaf70b5a 100644 ---- a/net/ipv6/exthdrs.c -+++ b/net/ipv6/exthdrs.c -@@ -957,9 +957,9 @@ static bool ipv6_hop_ioam(struct sk_buff *skb, int optoff) - if (skb_ensure_writable(skb, optoff + 2 + hdr->opt_len)) - goto drop; - -- /* Trace pointer may have changed */ -- trace = (struct ioam6_trace_hdr *)(skb_network_header(skb) -- + optoff + sizeof(*hdr)); -+ /* Trace and hdr pointers may have changed */ -+ hdr = (struct ioam6_hdr *)(skb_network_header(skb) + optoff); -+ trace = (struct ioam6_trace_hdr *)((u8 *)hdr + sizeof(*hdr)); - - ioam6_fill_trace_data(skb, ns, trace, true); - --- -2.50.1 (Apple Git-155) - diff --git a/1112-i2c-stub-reject-i2c-block-transfers-with-invalid-length.patch b/1112-i2c-stub-reject-i2c-block-transfers-with-invalid-length.patch deleted file mode 100644 index b35d84dee..000000000 --- a/1112-i2c-stub-reject-i2c-block-transfers-with-invalid-length.patch +++ /dev/null @@ -1,77 +0,0 @@ -From 4bd8635f28c135a08aac6badcd7d9b5cdb34335f Mon Sep 17 00:00:00 2001 -From: Weiming Shi -Date: Wed, 15 Apr 2026 01:23:39 +0800 -Subject: [PATCH] i2c: stub: Reject I2C block transfers with invalid length - -commit 6036b5067a8199ba7a2dc7b377d4b9dd276d5f9e upstream. - -The I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0] -as the transfer length. The existing check only clamps it to avoid -overrunning the chip->words[256] register array, but does not validate -it against I2C_SMBUS_BLOCK_MAX (32), which is the limit of the union -i2c_smbus_data.block buffer (34 bytes total). The driver is a -development/test tool (CONFIG_I2C_STUB=m, not built by default) -that must be loaded with a chip_addr= parameter. - -A local user with access to /dev/i2c-* can issue an I2C_SMBUS ioctl -with I2C_SMBUS_I2C_BLOCK_DATA and data->block[0] > 32, causing -stub_xfer() to read or write past the end of the union -i2c_smbus_data.block buffer: - - BUG: KASAN: stack-out-of-bounds in stub_xfer (drivers/i2c/i2c-stub.c:223) - Read of size 1 at addr ffff88800abcfd92 by task exploit/81 - Call Trace: - - stub_xfer (drivers/i2c/i2c-stub.c:223) - __i2c_smbus_xfer (drivers/i2c/i2c-core-smbus.c:593) - i2c_smbus_xfer (drivers/i2c/i2c-core-smbus.c:536) - i2cdev_ioctl_smbus (drivers/i2c/i2c-dev.c:391) - i2cdev_ioctl (drivers/i2c/i2c-dev.c:478) - __x64_sys_ioctl (fs/ioctl.c:583) - do_syscall_64 (arch/x86/entry/syscall_64.c:94) - entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) - - -The bug exists because i2c-stub implements .smbus_xfer directly, -bypassing the I2C_SMBUS_BLOCK_MAX validation in -i2c_smbus_xfer_emulated(). The I2C_SMBUS_BLOCK_DATA case in the same -function correctly validates against I2C_SMBUS_BLOCK_MAX, but the -I2C_SMBUS_I2C_BLOCK_DATA case does not. - -Fix by rejecting transfers with data->block[0] == 0 or -data->block[0] > I2C_SMBUS_BLOCK_MAX with -EINVAL, consistent with -both the I2C_SMBUS_BLOCK_DATA case in the same function and the -I2C_SMBUS_I2C_BLOCK_DATA validation in i2c_smbus_xfer_emulated(). - -Fixes: 4710317891e4 ("i2c-stub: Implement I2C block support") -Reported-by: Xiang Mei -Signed-off-by: Weiming Shi -Reviewed-by: Jean Delvare -Signed-off-by: Wolfram Sang -Signed-off-by: Greg Kroah-Hartman - -CVE-2026-64191 - -Backported from linux-6.12.y commit 4bd8635f28c135a08aac6badcd7d9b5cdb34335f -(mainline 6036b5067a8199ba7a2dc7b377d4b9dd276d5f9e); applies cleanly to the -a10 kernel-6.12.0-211.34.1.el10_2 tree, zero-fuzz (line offset only). - -diff --git a/drivers/i2c/i2c-stub.c b/drivers/i2c/i2c-stub.c -index 09e7b7bf4c5f..a6e2ce4360ca 100644 ---- a/drivers/i2c/i2c-stub.c -+++ b/drivers/i2c/i2c-stub.c -@@ -214,6 +214,11 @@ static s32 stub_xfer(struct i2c_adapter *adap, u16 addr, unsigned short flags, - * We ignore banks here, because banked chips don't use I2C - * block transfers - */ -+ if (data->block[0] == 0 || -+ data->block[0] > I2C_SMBUS_BLOCK_MAX) { -+ ret = -EINVAL; -+ break; -+ } - if (data->block[0] > 256 - command) /* Avoid overrun */ - data->block[0] = 256 - command; - len = data->block[0]; --- -2.50.1 (Apple Git-155) - diff --git a/1113-scsi-target-iscsi-validate-chap-r-length-before-base.patch b/1113-scsi-target-iscsi-validate-chap-r-length-before-base.patch deleted file mode 100644 index aaea4621b..000000000 --- a/1113-scsi-target-iscsi-validate-chap-r-length-before-base.patch +++ /dev/null @@ -1,95 +0,0 @@ -From bf154c657828ed05399bca5d98cf1611bb048b12 Mon Sep 17 00:00:00 2001 -From: Alexandru Hossu -Date: Thu, 21 May 2026 17:11:21 +0200 -Subject: [PATCH] scsi: target: iscsi: Validate CHAP_R length before base64 - decode - -commit 85db7391310b1304d2dc8ae3b0b12105a9567147 upstream. - -chap_server_compute_hash() allocates client_digest as -kzalloc(chap->digest_size) and then, for BASE64-encoded responses, -passes chap_r directly to chap_base64_decode() without checking whether -the input length could produce more than digest_size bytes of output. - -chap_base64_decode() writes to the destination unconditionally as long -as there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and -the "0b" prefix stripped by extract_param(), up to 127 base64 characters -can reach the decoder. 127 characters decode to 95 bytes. For SHA-256 -(digest_size=32) this overflows client_digest by 63 bytes; for MD5 -(digest_size=16) the overflow is 79 bytes. - -The length check at line 344 fires after the write has already happened. - -The HEX branch in the same switch statement already validates the length -up front. Apply the same approach to the BASE64 branch: strip trailing -base64 padding characters, then reject any input whose data length -exceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder. - -Stripping trailing '=' before the comparison handles both padded and -unpadded encodings. chap_base64_decode() already returns early on '=', -so the full original string is still passed to the decoder unchanged. - -The mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is -kzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg at -CHAP_CHALLENGE_STR_LEN characters, so at most CHAP_CHALLENGE_STR_LEN-1 -base64 characters reach the decoder. The maximum decoded size, -DIV_ROUND_UP((CHAP_CHALLENGE_STR_LEN-1) * 3, 4), is less than -CHAP_CHALLENGE_STR_LEN, so no overflow is possible there. A comment is -added at the call site to document this. - -Fixes: 1e5733883421 ("scsi: target: iscsi: Support base64 in CHAP") -Cc: stable@vger.kernel.org -Signed-off-by: Alexandru Hossu -Reviewed-by: David Disseldorp -Link: https://patch.msgid.link/20260521151121.808477-1-hossu.alexandru@gmail.com -Signed-off-by: Martin K. Petersen -Signed-off-by: Greg Kroah-Hartman - -[ CVE-2026-63886: backported to AlmaLinux 10 (kernel-6.12.0-211.34.1.el10_2) from linux-6.12.y commit bf154c657828ed05399bca5d98cf1611bb048b12; applies cleanly, zero-fuzz. ] - -diff --git a/drivers/target/iscsi/iscsi_target_auth.c b/drivers/target/iscsi/iscsi_target_auth.c -index c8a248bd11be..02a4c9aff98d 100644 ---- a/drivers/target/iscsi/iscsi_target_auth.c -+++ b/drivers/target/iscsi/iscsi_target_auth.c -@@ -339,13 +339,22 @@ static int chap_server_compute_hash( - goto out; - } - break; -- case BASE64: -+ case BASE64: { -+ size_t r_len = strlen(chap_r); -+ -+ while (r_len > 0 && chap_r[r_len - 1] == '=') -+ r_len--; -+ if (r_len > DIV_ROUND_UP(chap->digest_size * 4, 3)) { -+ pr_err("Malformed CHAP_R: base64 payload too long\n"); -+ goto out; -+ } - if (chap_base64_decode(client_digest, chap_r, strlen(chap_r)) != - chap->digest_size) { - pr_err("Malformed CHAP_R: invalid BASE64\n"); - goto out; - } - break; -+ } - default: - pr_err("Could not find CHAP_R\n"); - goto out; -@@ -472,6 +481,14 @@ static int chap_server_compute_hash( - } - break; - case BASE64: -+ /* -+ * No overflow check needed: initiatorchg_binhex is -+ * CHAP_CHALLENGE_STR_LEN bytes and extract_param() caps -+ * initiatorchg at CHAP_CHALLENGE_STR_LEN characters, so -+ * the decoded output is at most DIV_ROUND_UP( -+ * (CHAP_CHALLENGE_STR_LEN - 1) * 3, 4) bytes, which is -+ * less than CHAP_CHALLENGE_STR_LEN. -+ */ - initiatorchg_len = chap_base64_decode(initiatorchg_binhex, - initiatorchg, - strlen(initiatorchg)); --- -2.50.1 (Apple Git-155) - diff --git a/1114-scsi-target-iscsi-bound-iscsi-encode-text-output-app.patch b/1114-scsi-target-iscsi-bound-iscsi-encode-text-output-app.patch deleted file mode 100644 index 296004e11..000000000 --- a/1114-scsi-target-iscsi-bound-iscsi-encode-text-output-app.patch +++ /dev/null @@ -1,204 +0,0 @@ -From 30bf335e8fe170322080ee001f05ca29c50680b3 Mon Sep 17 00:00:00 2001 -From: Michael Bommarito -Date: Mon, 11 May 2026 14:49:14 -0400 -Subject: [PATCH] scsi: target: iscsi: Bound iscsi_encode_text_output() appends - to rsp_buf - -commit bf33e01f88388c43e285492a63e539df6ffed64c upstream. - -iscsi_encode_text_output() concatenates "key=value\0" records into -login->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer -allocated in iscsit_alloc_login_setup_buffer(). The three sprintf() call -sites in this function (lines 1398, 1411, 1424 in v7.1-rc2) never check -the remaining buffer capacity: - - *length += sprintf(output_buf, "%s=%s", er->key, er->value); - *length += 1; - output_buf = textbuf + *length; - -The 8192-byte ceiling at iscsi_target_check_login_request() bounds the -*input* Login PDU payload, but a single PDU can carry up to 2048 minimal -four-byte "a=b\0" pairs, each unknown key expanding to a 16-byte -"a=NotUnderstood\0" output record via iscsi_add_notunderstood_response(). -2048 * 16 = 32 KiB of output into an 8 KiB buffer, producing a ~24 KiB -heap overrun in the kmalloc-8k slab. - -The fix introduces a static iscsi_encode_text_record() helper that uses -snprintf() with a per-call bounds check against the remaining buffer, -and threads a u32 textbuf_size parameter through -iscsi_encode_text_output(). Both call sites in -iscsi_target_handle_csg_zero() (PHASE_SECURITY) and -iscsi_target_handle_csg_one() (PHASE_OPERATIONAL) pass -MAX_KEY_VALUE_PAIRS. On overflow the encoder logs the condition, calls -iscsi_release_extra_responses() to drop queued records, and returns -1; -both caller sites now emit ISCSI_STATUS_CLS_INITIATOR_ERR / -ISCSI_LOGIN_STATUS_INIT_ERR via iscsit_tx_login_rsp() before returning, -so the initiator sees an explicit failed-login response rather than a -silent connection drop. (Prior to this patch only the PHASE_OPERATIONAL -caller did that; the PHASE_SECURITY caller is converted to the same -shape.) - -Fixes: e48354ce078c ("iscsi-target: Add iSCSI fabric support for target v4.1") -Cc: stable@vger.kernel.org -Assisted-by: Claude:claude-opus-4-7 -Signed-off-by: Michael Bommarito -Tested-by: John Garry -Reviewed-by: John Garry -Signed-off-by: Martin K. Petersen -Signed-off-by: Greg Kroah-Hartman - -[ CVE-2026-63887: backported to AlmaLinux 10 (kernel-6.12.0-211.34.1.el10_2) from linux-6.12.y commit 30bf335e8fe170322080ee001f05ca29c50680b3; applies cleanly, zero-fuzz. ] - -diff --git a/drivers/target/iscsi/iscsi_target_nego.c b/drivers/target/iscsi/iscsi_target_nego.c -index fa3fb5f4e6bc..f98734524693 100644 ---- a/drivers/target/iscsi/iscsi_target_nego.c -+++ b/drivers/target/iscsi/iscsi_target_nego.c -@@ -899,10 +899,14 @@ static int iscsi_target_handle_csg_zero( - SENDER_TARGET, - login->rsp_buf, - &login->rsp_length, -+ MAX_KEY_VALUE_PAIRS, - conn->param_list, - conn->tpg->tpg_attrib.login_keys_workaround); -- if (ret < 0) -+ if (ret < 0) { -+ iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR, -+ ISCSI_LOGIN_STATUS_INIT_ERR); - return -1; -+ } - - if (!iscsi_check_negotiated_keys(conn->param_list)) { - bool auth_required = iscsi_conn_auth_required(conn); -@@ -986,6 +990,7 @@ static int iscsi_target_handle_csg_one(struct iscsit_conn *conn, struct iscsi_lo - SENDER_TARGET, - login->rsp_buf, - &login->rsp_length, -+ MAX_KEY_VALUE_PAIRS, - conn->param_list, - conn->tpg->tpg_attrib.login_keys_workaround); - if (ret < 0) { -diff --git a/drivers/target/iscsi/iscsi_target_parameters.c b/drivers/target/iscsi/iscsi_target_parameters.c -index 5b90c22ee3dc..5e15c2ea7d65 100644 ---- a/drivers/target/iscsi/iscsi_target_parameters.c -+++ b/drivers/target/iscsi/iscsi_target_parameters.c -@@ -1419,19 +1419,42 @@ int iscsi_decode_text_input( - return -1; - } - -+/* -+ * Append "key=value" plus a trailing NUL into @textbuf at *@length. -+ * Returns 0 on success and advances *@length, or -EMSGSIZE if the -+ * record (including the NUL) would not fit in the remaining buffer. -+ */ -+static int iscsi_encode_text_record(char *textbuf, u32 *length, -+ u32 textbuf_size, -+ const char *key, const char *value) -+{ -+ int n; -+ u32 avail; -+ -+ if (*length >= textbuf_size) -+ return -EMSGSIZE; -+ -+ avail = textbuf_size - *length; -+ n = snprintf(textbuf + *length, avail, "%s=%s", key, value); -+ if (n < 0 || (u32)n + 1 > avail) -+ return -EMSGSIZE; -+ -+ *length += n + 1; -+ return 0; -+} -+ - int iscsi_encode_text_output( - u8 phase, - u8 sender, - char *textbuf, - u32 *length, -+ u32 textbuf_size, - struct iscsi_param_list *param_list, - bool keys_workaround) - { -- char *output_buf = NULL; - struct iscsi_extra_response *er; - struct iscsi_param *param; -- -- output_buf = textbuf + *length; -+ int ret; - - if (iscsi_enforce_integrity_rules(phase, param_list) < 0) - return -1; -@@ -1443,10 +1466,12 @@ int iscsi_encode_text_output( - !IS_PSTATE_RESPONSE_SENT(param) && - !IS_PSTATE_REPLY_OPTIONAL(param) && - (param->phase & phase)) { -- *length += sprintf(output_buf, "%s=%s", -- param->name, param->value); -- *length += 1; -- output_buf = textbuf + *length; -+ ret = iscsi_encode_text_record(textbuf, length, -+ textbuf_size, -+ param->name, -+ param->value); -+ if (ret < 0) -+ goto err_overflow; - SET_PSTATE_RESPONSE_SENT(param); - pr_debug("Sending key: %s=%s\n", - param->name, param->value); -@@ -1456,10 +1481,12 @@ int iscsi_encode_text_output( - !IS_PSTATE_ACCEPTOR(param) && - !IS_PSTATE_PROPOSER(param) && - (param->phase & phase)) { -- *length += sprintf(output_buf, "%s=%s", -- param->name, param->value); -- *length += 1; -- output_buf = textbuf + *length; -+ ret = iscsi_encode_text_record(textbuf, length, -+ textbuf_size, -+ param->name, -+ param->value); -+ if (ret < 0) -+ goto err_overflow; - SET_PSTATE_PROPOSER(param); - iscsi_check_proposer_for_optional_reply(param, - keys_workaround); -@@ -1469,14 +1496,21 @@ int iscsi_encode_text_output( - } - - list_for_each_entry(er, ¶m_list->extra_response_list, er_list) { -- *length += sprintf(output_buf, "%s=%s", er->key, er->value); -- *length += 1; -- output_buf = textbuf + *length; -+ ret = iscsi_encode_text_record(textbuf, length, textbuf_size, -+ er->key, er->value); -+ if (ret < 0) -+ goto err_overflow; - pr_debug("Sending key: %s=%s\n", er->key, er->value); - } - iscsi_release_extra_responses(param_list); - - return 0; -+ -+err_overflow: -+ pr_err("iSCSI login response buffer (%u bytes) exhausted, dropping login.\n", -+ textbuf_size); -+ iscsi_release_extra_responses(param_list); -+ return -1; - } - - int iscsi_check_negotiated_keys(struct iscsi_param_list *param_list) -diff --git a/drivers/target/iscsi/iscsi_target_parameters.h b/drivers/target/iscsi/iscsi_target_parameters.h -index 00fbbebb8c75..d6cbe5dd4b00 100644 ---- a/drivers/target/iscsi/iscsi_target_parameters.h -+++ b/drivers/target/iscsi/iscsi_target_parameters.h -@@ -46,7 +46,7 @@ extern struct iscsi_param *iscsi_find_param_from_key(char *, struct iscsi_param_ - extern int iscsi_extract_key_value(char *, char **, char **); - extern int iscsi_update_param_value(struct iscsi_param *, char *); - extern int iscsi_decode_text_input(u8, u8, char *, u32, struct iscsit_conn *); --extern int iscsi_encode_text_output(u8, u8, char *, u32 *, -+extern int iscsi_encode_text_output(u8, u8, char *, u32 *, u32, - struct iscsi_param_list *, bool); - extern int iscsi_check_negotiated_keys(struct iscsi_param_list *); - extern void iscsi_set_connection_parameters(struct iscsi_conn_ops *, --- -2.50.1 (Apple Git-155) - diff --git a/1115-scsi-target-iscsi-fix-crc-overread-and-double-free-i.patch b/1115-scsi-target-iscsi-fix-crc-overread-and-double-free-i.patch deleted file mode 100644 index 9369d761c..000000000 --- a/1115-scsi-target-iscsi-fix-crc-overread-and-double-free-i.patch +++ /dev/null @@ -1,124 +0,0 @@ -From ec9f19d52074a191ed1756ed4a7d39fff1a2085c Mon Sep 17 00:00:00 2001 -From: Michael Bommarito -Date: Fri, 5 Jun 2026 22:47:23 -0400 -Subject: [PATCH] scsi: target: iscsi: Fix CRC overread and double-free in - iscsit_handle_text_cmd() - -[ Upstream commit 778c2ab142c625a8a8afa570e0f9b7873f445d99 ] - -Two latent bugs in the Text-phase handler, both present since the -original LIO integration in commit e48354ce078c ("iscsi-target: Add -iSCSI fabric support for target v4.1"): - -1) DataDigest CRC buffer overread (4 bytes past text_in). - - text_in is kzalloc()'d at ALIGN(payload_length, 4). rx_size is then - incremented by ISCSI_CRC_LEN to make room for the received DataDigest - in the iovec, but the same (now-bumped) rx_size is passed as the - buffer length to iscsit_crc_buf(): - - if (conn->conn_ops->DataDigest) { - ... - rx_size += ISCSI_CRC_LEN; - } - ... - if (conn->conn_ops->DataDigest) { - data_crc = iscsit_crc_buf(text_in, rx_size, 0, NULL); - - iscsit_crc_buf() walks rx_size bytes of text_in with crc32c(), so - when DataDigest is negotiated it reads 4 bytes past the end of the - text_in allocation. KASAN reproduces this directly on the unpatched - mainline tree as slab-out-of-bounds in crc32c() called from the Text - PDU path. The OOB bytes feed crc32c() and are then compared against - the initiator-supplied checksum, so the value does not flow back to - the attacker, but the kernel does read past the buffer on every Text - PDU with DataDigest=CRC32C. - - Fix by passing the actual padded payload length - (ALIGN(payload_length, 4)) that was used for the kzalloc(). - -2) Stale cmd->text_in_ptr re-free (double-free) on ERL>0 bad DataDigest - drop. - - On DataDigest mismatch with ErrorRecoveryLevel > 0 the handler - silently drops the PDU and lets the initiator plug the CmdSN gap: - - kfree(text_in); - return 0; - - cmd->text_in_ptr still points at the freed buffer. The next Text - Request on the same ITT re-enters iscsit_setup_text_cmd(), which - unconditionally does - - kfree(cmd->text_in_ptr); - cmd->text_in_ptr = NULL; - - freeing the same pointer a second time. Session teardown via - iscsit_release_cmd() has the same shape and hits the same double-free - if the connection is dropped before a second Text Request arrives. - - On an unmodified mainline tree the bug-1 CRC overread fires first on - the initial valid Text Request and perturbs the subsequent state, so - #4 was isolated by building a kernel with only the bug-1 hunk of this - patch applied plus temporary printk() observability around the three - relevant kfree() sites. The observability prints are not part of - this patch. On that build, a three-PDU Text Request sequence after - login produces two back-to-back splats: - - BUG: KASAN: double-free in iscsit_setup_text_cmd+0x?? - BUG: KASAN: double-free in iscsit_release_cmd+0x?? - - showing the same pointer freed in the ERL>0 drop path and again in - iscsit_setup_text_cmd() (next Text Request on the same ITT) and once - more in iscsit_release_cmd() (session teardown). On distro kernels - with CONFIG_SLAB_FREELIST_HARDENED=y (default) the double-free - becomes a remote kernel BUG(); on non-hardened kernels it corrupts - the slab freelist. - - Fix by clearing cmd->text_in_ptr after the kfree() in the ERL>0 drop - path. With both hunks applied #4 is directly observable on the stock - tree without observability printks; fixing bug-1 alone would mask #4 - less, not more, so the hunks are submitted together. - -Both fixes are one-liners. The Text PDU state machine is unchanged and -the wire protocol is unaffected. - -Fixes: e48354ce078c ("iscsi-target: Add iSCSI fabric support for target v4.1") -Cc: stable@vger.kernel.org -Assisted-by: Claude:claude-opus-4-7 -Signed-off-by: Michael Bommarito -Tested-by: John Garry -Reviewed-by: John Garry -Signed-off-by: Martin K. Petersen -Signed-off-by: Sasha Levin -Signed-off-by: Greg Kroah-Hartman - -[ CVE-2026-63888: backported to AlmaLinux 10 (kernel-6.12.0-211.34.1.el10_2) from linux-6.12.y commit ec9f19d52074a191ed1756ed4a7d39fff1a2085c; applies cleanly, zero-fuzz. ] - -diff --git a/drivers/target/iscsi/iscsi_target.c b/drivers/target/iscsi/iscsi_target.c -index 68bbdf3ee101..8a7d308da991 100644 ---- a/drivers/target/iscsi/iscsi_target.c -+++ b/drivers/target/iscsi/iscsi_target.c -@@ -2329,8 +2329,9 @@ iscsit_handle_text_cmd(struct iscsit_conn *conn, struct iscsit_cmd *cmd, - - if (conn->conn_ops->DataDigest) { - iscsit_do_crypto_hash_buf(conn->conn_rx_hash, -- text_in, rx_size, 0, NULL, -- &data_crc); -+ text_in, -+ ALIGN(payload_length, 4), -+ 0, NULL, &data_crc); - - if (checksum != data_crc) { - pr_err("Text data CRC32C DataDigest" -@@ -2350,6 +2351,7 @@ iscsit_handle_text_cmd(struct iscsit_conn *conn, struct iscsit_cmd *cmd, - " Command CmdSN: 0x%08x due to" - " DataCRC error.\n", hdr->cmdsn); - kfree(text_in); -+ cmd->text_in_ptr = NULL; - return 0; - } - } else { --- -2.50.1 (Apple Git-155) - diff --git a/1116-usb-serial-mxuport-fix-memory-corruption-with-small.patch b/1116-usb-serial-mxuport-fix-memory-corruption-with-small.patch deleted file mode 100644 index 2ef449b32..000000000 --- a/1116-usb-serial-mxuport-fix-memory-corruption-with-small.patch +++ /dev/null @@ -1,45 +0,0 @@ -From e906545641d34fb1a09a65b4b5cfdff40eb09681 Mon Sep 17 00:00:00 2001 -From: Johan Hovold -Date: Fri, 22 May 2026 16:19:50 +0200 -Subject: [PATCH] USB: serial: mxuport: fix memory corruption with small - endpoint - -commit 4085f0dbb1ce2251c9a5938d693de6593f0ab2bd upstream. - -Make sure that the bulk-out endpoint max packet size is at least eight -bytes to avoid user-controlled slab corruption should a malicious device -report a smaller size. - -Fixes: ee467a1f2066 ("USB: serial: add Moxa UPORT 12XX/14XX/16XX driver") -Cc: stable@vger.kernel.org # 3.14 -Cc: Andrew Lunn -Reviewed-by: Greg Kroah-Hartman -Signed-off-by: Johan Hovold -Signed-off-by: Greg Kroah-Hartman - -CVE-2026-63899 - -[ Backported from linux-6.12.y commit e906545641d34fb1a09a65b4b5cfdff40eb09681 (mainline 4085f0dbb1ce2251c9a5938d693de6593f0ab2bd); applies cleanly to AlmaLinux 10 (kernel-6.12.0-211.34.1.el10_2), zero-fuzz. ] - -diff --git a/drivers/usb/serial/mxuport.c b/drivers/usb/serial/mxuport.c -index ad5fdf55a02e..c9b9928c473a 100644 ---- a/drivers/usb/serial/mxuport.c -+++ b/drivers/usb/serial/mxuport.c -@@ -962,6 +962,14 @@ static int mxuport_calc_num_ports(struct usb_serial *serial, - */ - BUILD_BUG_ON(ARRAY_SIZE(epds->bulk_out) < 16); - -+ /* -+ * The bulk-out buffers must be large enough for the four-byte header -+ * (and following data), but assume anything smaller than eight bytes -+ * is broken. -+ */ -+ if (usb_endpoint_maxp(epds->bulk_out[0]) < 8) -+ return -EINVAL; -+ - for (i = 1; i < num_ports; ++i) - epds->bulk_out[i] = epds->bulk_out[0]; - --- -2.50.1 (Apple Git-155) - diff --git a/1117-ip6-vti-use-ip6-tnl-net-in-vti6-changelink.patch b/1117-ip6-vti-use-ip6-tnl-net-in-vti6-changelink.patch deleted file mode 100644 index 9cc705137..000000000 --- a/1117-ip6-vti-use-ip6-tnl-net-in-vti6-changelink.patch +++ /dev/null @@ -1,78 +0,0 @@ -From 225b467e3b631f38be22e4b38062a1fed02fdd21 Mon Sep 17 00:00:00 2001 -From: Kuniyuki Iwashima -Date: Thu, 21 May 2026 21:05:54 +0800 -Subject: [PATCH] ip6: vti: Use ip6_tnl.net in vti6_changelink(). - -commit 11b326fb0a374f4654f9be22d0f0f7abd9f7d3fe upstream. - -ip netns add ns1 -ip netns add ns2 -ip -n ns1 link add vti6_test type vti6 remote ::1 local ::2 key 7 -ip -n ns1 link set vti6_test netns ns2 -ip -n ns2 link set vti6_test type vti6 remote ::3 local ::4 key 9 -ip netns del ns2 -ip netns del ns1 -[ 132.495484] ------------[ cut here ]------------ -[ 132.497609] kernel BUG at net/core/dev.c:12376! - -Commit 61220ab34948 ("vti6: Enable namespace changing") dropped -NETIF_F_NETNS_LOCAL from vti6 devices. A vti6 tunnel can then -move through IFLA_NET_NS_FD. After the move dev_net(dev) points -at the new netns while t->net stays at the creation netns. - -vti6_changelink() and vti6_update() still use dev_net(dev) and -dev_net(t->dev). They unlink from one per netns hash and relink -into another. The creation netns is left with a stale entry. -cleanup_net() of that netns later walks freed memory. - -Reachable from an unprivileged user namespace (unshare --user ---map-root-user --net). Cross tenant scope on container hosts. - -Fixes: 61220ab34948 ("vti6: Enable namespace changing") -Reported-by: Maoyi Xie -Reviewed-by: Eric Dumazet -Cc: stable@vger.kernel.org # v5.15+ -Signed-off-by: Kuniyuki Iwashima -Link: https://patch.msgid.link/20260521130555.3421684-2-maoyixie.tju@gmail.com -Signed-off-by: Paolo Abeni -Signed-off-by: Greg Kroah-Hartman - -[ CVE-2026-63917: backported to AlmaLinux 10 (kernel-6.12.0-211.34.1.el10_2) from linux-6.12.y commit 225b467e3b631f38be22e4b38062a1fed02fdd21; applies cleanly, zero-fuzz. ] - -diff --git a/net/ipv6/ip6_vti.c b/net/ipv6/ip6_vti.c -index b931092da512..2ac88593a954 100644 ---- a/net/ipv6/ip6_vti.c -+++ b/net/ipv6/ip6_vti.c -@@ -722,10 +722,11 @@ vti6_tnl_change(struct ip6_tnl *t, const struct __ip6_tnl_parm *p, - static int vti6_update(struct ip6_tnl *t, struct __ip6_tnl_parm *p, - bool keep_mtu) - { -- struct net *net = dev_net(t->dev); -- struct vti6_net *ip6n = net_generic(net, vti6_net_id); -+ struct net *net = t->net; -+ struct vti6_net *ip6n; - int err; - -+ ip6n = net_generic(net, vti6_net_id); - vti6_tnl_unlink(ip6n, t); - synchronize_net(); - err = vti6_tnl_change(t, p, keep_mtu); -@@ -1036,11 +1037,12 @@ static int vti6_changelink(struct net_device *dev, struct nlattr *tb[], - struct nlattr *data[], - struct netlink_ext_ack *extack) - { -- struct ip6_tnl *t; -+ struct ip6_tnl *t = netdev_priv(dev); -+ struct net *net = t->net; - struct __ip6_tnl_parm p; -- struct net *net = dev_net(dev); -- struct vti6_net *ip6n = net_generic(net, vti6_net_id); -+ struct vti6_net *ip6n; - -+ ip6n = net_generic(net, vti6_net_id); - if (dev == ip6n->fb_tnl_dev) - return -EINVAL; - --- -2.50.1 (Apple Git-155) - diff --git a/1118-ipv6-exthdrs-refresh-nh-pointer-after-ipv6-hop-jumbo.patch b/1118-ipv6-exthdrs-refresh-nh-pointer-after-ipv6-hop-jumbo.patch deleted file mode 100644 index 2f366c000..000000000 --- a/1118-ipv6-exthdrs-refresh-nh-pointer-after-ipv6-hop-jumbo.patch +++ /dev/null @@ -1,42 +0,0 @@ -From 72af7beae774e46ed543f3f2f267bf0a141bfcdd Mon Sep 17 00:00:00 2001 -From: Justin Iurman -Date: Fri, 22 May 2026 13:20:13 +0200 -Subject: [PATCH] ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() - -commit d47548a36639095939f4747d4c43f2271366f565 upstream. - -ipv6_hop_jumbo() calls pskb_trim_rcsum(), which can change skb pointers. -Let's recompute nh pointer to make sure any change won't mess things up. - -Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") -Cc: stable@vger.kernel.org -Signed-off-by: Justin Iurman -Reviewed-by: Ido Schimmel -Link: https://patch.msgid.link/20260522112013.12342-1-justin.iurman@gmail.com -Signed-off-by: Jakub Kicinski -Signed-off-by: Greg Kroah-Hartman - -CVE-2026-63924 - -Backported from linux-6.12.y commit 72af7beae774e46ed543f3f2f267bf0a141bfcdd -(mainline d47548a36639095939f4747d4c43f2271366f565); applies cleanly to the -a10 kernel-6.12.0-211.34.1.el10_2 tree, zero-fuzz (line offset only). Must be -applied before CVE-2026-63922 (HAO) and after the already-shipped -CVE-2026-64132 (1111, ipv6 ioam), matching upstream order. - -diff --git a/net/ipv6/exthdrs.c b/net/ipv6/exthdrs.c -index 43e34fe448ff..d179077a2955 100644 ---- a/net/ipv6/exthdrs.c -+++ b/net/ipv6/exthdrs.c -@@ -184,6 +184,8 @@ static bool ip6_parse_tlv(bool hopbyhop, - case IPV6_TLV_JUMBO: - if (!ipv6_hop_jumbo(skb, off)) - return false; -+ -+ nh = skb_network_header(skb); - break; - case IPV6_TLV_CALIPSO: - if (!ipv6_hop_calipso(skb, off)) --- -2.50.1 (Apple Git-155) - diff --git a/1119-ipv6-exthdrs-refresh-nh-after-handling-hao-option.patch b/1119-ipv6-exthdrs-refresh-nh-after-handling-hao-option.patch deleted file mode 100644 index 9e128133d..000000000 --- a/1119-ipv6-exthdrs-refresh-nh-after-handling-hao-option.patch +++ /dev/null @@ -1,56 +0,0 @@ -From ff375ed1cba81392346c5bfbf0bb7a13b2946f99 Mon Sep 17 00:00:00 2001 -From: Zhengchuan Liang -Date: Fri, 22 May 2026 17:42:26 +0800 -Subject: [PATCH] ipv6: exthdrs: refresh nh after handling HAO option - -commit f7b52afe3592eae66e160586b45a3f2242972c63 upstream. - -ip6_parse_tlv() caches skb_network_header(skb) in nh while walking -IPv6 TLVs. - -ipv6_dest_hao() may call pskb_expand_head() for a cloned skb, which can -move the skb head and invalidate the cached network header pointer. -Refresh nh after ipv6_dest_hao() returns so any trailing padding or TLVs -are parsed from the current skb head. - -This matches the existing pattern used in ip6_parse_tlv() after helpers -that can modify skb header storage. - -Fixes: a831f5bbc89a ("[IPV6] MIP6: Add inbound interface of home address option.") -Cc: stable@kernel.org -Reported-by: Yuan Tan -Reported-by: Xin Liu -Co-developed-by: Luxing Yin -Signed-off-by: Luxing Yin -Signed-off-by: Zhengchuan Liang -Signed-off-by: Ren Wei -Reviewed-by: Justin Iurman -Reviewed-by: Ido Schimmel -Link: https://patch.msgid.link/7aba1debc2196189172499e5769802b026f8caf8.1779247873.git.zcliangcn@gmail.com -Signed-off-by: Jakub Kicinski -Signed-off-by: Greg Kroah-Hartman - -CVE-2026-63922 - -Backported from linux-6.12.y commit ff375ed1cba81392346c5bfbf0bb7a13b2946f99 -(mainline f7b52afe3592eae66e160586b45a3f2242972c63); applies cleanly to the -a10 kernel-6.12.0-211.34.1.el10_2 tree, zero-fuzz (line offset only). Must be -applied after CVE-2026-63924 (JUMBO) and the already-shipped CVE-2026-64132 -(1111, ipv6 ioam), matching upstream order. - -diff --git a/net/ipv6/exthdrs.c b/net/ipv6/exthdrs.c -index d179077a2955..e91afe5ec0b5 100644 ---- a/net/ipv6/exthdrs.c -+++ b/net/ipv6/exthdrs.c -@@ -203,6 +203,8 @@ static bool ip6_parse_tlv(bool hopbyhop, - case IPV6_TLV_HAO: - if (!ipv6_dest_hao(skb, off)) - return false; -+ -+ nh = skb_network_header(skb); - break; - #endif - default: --- -2.50.1 (Apple Git-155) - diff --git a/1120-kvm-sev-compute-the-correct-max-length-of-the-in-ghc.patch b/1120-kvm-sev-compute-the-correct-max-length-of-the-in-ghc.patch deleted file mode 100644 index 6bbb2b883..000000000 --- a/1120-kvm-sev-compute-the-correct-max-length-of-the-in-ghc.patch +++ /dev/null @@ -1,109 +0,0 @@ -From 6ca9400d36005ffdca25f80186bea781c7e1dc4c Mon Sep 17 00:00:00 2001 -From: Sean Christopherson -Date: Fri, 1 May 2026 13:22:31 -0700 -Subject: [PATCH] KVM: SEV: Compute the correct max length of the in-GHCB - scratch area - -commit 5867d7e202e09f037cefe77f7af4413c7c0fa088 upstream. - -When setting the length of the GHCB scratch area, and the area is in the -GHCB shared buffer, set the effective length of the scratch area to the max -possible size given the start of the guest-provided pointer, and the end of -the shared buffer. - -The code was "fine" when first introduced, as KVM doesn't consult the -length of the buffer when emulating MMIO, because the passed in @len always -specifies the *max* size required. But for PSC requests, the incoming @len -is just the minimum length (to process the header), and KVM needs to know -the full size of the scratch area to avoid buffer overflows (spoiler alert). - -Opportunistically rename @len => @min_len to better reflect its role. - -Fixes: 9b54e248d264 ("KVM: SEV: Add support to handle Page State Change VMGEXIT") -Cc: stable@vger.kernel.org -Reviewed-by: Tom Lendacky -Reviewed-by: Michael Roth -Signed-off-by: Sean Christopherson -Message-ID: <20260501202250.2115252-7-seanjc@google.com> -Signed-off-by: Paolo Bonzini -Signed-off-by: Greg Kroah-Hartman - -CVE-2026-63939 - -Backported from linux-6.12.y commit 6ca9400d36005ffdca25f80186bea781c7e1dc4c -(mainline 5867d7e202e09f037cefe77f7af4413c7c0fa088). Adapted to the a10 -kernel-6.12.0-211.34.1.el10_2 tree: the hunk that adds the in-GHCB -ghcb_sa_len assignment had its trailing context adjusted because the a10 -setup_vmgexit_scratch() else-branch lacks the upstream "GHCB v2 requires the -scratch area to be within the GHCB" check. Applies on top of CVE-2026-63794 -(1102, sev_dbg_crypt) which touches a different function. Zero-fuzz. - -diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c -index 3ff71ce..d218568 100644 ---- a/arch/x86/kvm/svm/sev.c -+++ b/arch/x86/kvm/svm/sev.c -@@ -3521,7 +3521,7 @@ int pre_sev_run(struct vcpu_svm *svm, int cpu) - } - - #define GHCB_SCRATCH_AREA_LIMIT (16ULL * PAGE_SIZE) --static int setup_vmgexit_scratch(struct vcpu_svm *svm, bool sync, u64 len) -+static int setup_vmgexit_scratch(struct vcpu_svm *svm, bool sync, u64 min_len) - { - struct vmcb_control_area *control = &svm->vmcb->control; - u64 ghcb_scratch_beg, ghcb_scratch_end; -@@ -3534,10 +3534,10 @@ static int setup_vmgexit_scratch(struct vcpu_svm *svm, bool sync, u64 len) - goto e_scratch; - } - -- scratch_gpa_end = scratch_gpa_beg + len; -+ scratch_gpa_end = scratch_gpa_beg + min_len; - if (scratch_gpa_end < scratch_gpa_beg) { - pr_err("vmgexit: scratch length (%#llx) not valid for scratch address (%#llx)\n", -- len, scratch_gpa_beg); -+ min_len, scratch_gpa_beg); - goto e_scratch; - } - -@@ -3561,21 +3561,23 @@ static int setup_vmgexit_scratch(struct vcpu_svm *svm, bool sync, u64 len) - - scratch_va = (void *)svm->sev_es.ghcb; - scratch_va += (scratch_gpa_beg - control->ghcb_gpa); -+ -+ svm->sev_es.ghcb_sa_len = ghcb_scratch_end - scratch_gpa_beg; - } else { - /* - * The guest memory must be read into a kernel buffer, so - * limit the size - */ -- if (len > GHCB_SCRATCH_AREA_LIMIT) { -+ if (min_len > GHCB_SCRATCH_AREA_LIMIT) { - pr_err("vmgexit: scratch area exceeds KVM limits (%#llx requested, %#llx limit)\n", -- len, GHCB_SCRATCH_AREA_LIMIT); -+ min_len, GHCB_SCRATCH_AREA_LIMIT); - goto e_scratch; - } -- scratch_va = kvzalloc(len, GFP_KERNEL_ACCOUNT); -+ scratch_va = kvzalloc(min_len, GFP_KERNEL_ACCOUNT); - if (!scratch_va) - return -ENOMEM; - -- if (kvm_read_guest(svm->vcpu.kvm, scratch_gpa_beg, scratch_va, len)) { -+ if (kvm_read_guest(svm->vcpu.kvm, scratch_gpa_beg, scratch_va, min_len)) { - /* Unable to copy scratch area from guest */ - pr_err("vmgexit: kvm_read_guest for scratch area failed\n"); - -@@ -3591,11 +3593,10 @@ static int setup_vmgexit_scratch(struct vcpu_svm *svm, bool sync, u64 len) - */ - svm->sev_es.ghcb_sa_sync = sync; - svm->sev_es.ghcb_sa_free = true; -+ svm->sev_es.ghcb_sa_len = min_len; - } - - svm->sev_es.ghcb_sa = scratch_va; -- svm->sev_es.ghcb_sa_len = len; -- - return 0; - - e_scratch: --- -2.50.1 diff --git a/1122-usb-serial-cypress-m8-fix-memory-corruption-with-sma.patch b/1122-usb-serial-cypress-m8-fix-memory-corruption-with-sma.patch deleted file mode 100644 index 9d8077afb..000000000 --- a/1122-usb-serial-cypress-m8-fix-memory-corruption-with-sma.patch +++ /dev/null @@ -1,46 +0,0 @@ -From 1ef25704bd3b625fd151c09feee459479f71ee64 Mon Sep 17 00:00:00 2001 -From: Johan Hovold -Date: Thu, 4 Jun 2026 10:36:36 +0200 -Subject: [PATCH] USB: serial: cypress_m8: fix memory corruption with small - endpoint - -commit e1a9d791fd66ab2431b9e6f6f835823809869047 upstream. - -Make sure that the interrupt-out endpoint max packet size is at least -eight bytes to avoid user-controlled slab corruption or NULL-pointer -dereference should a malicious device report a smaller size. - -Fixes: 3416eaa1f8f8 ("USB: cypress_m8: Packet format is separate from characteristic size") -Cc: stable@vger.kernel.org # 2.6.26 -Reviewed-by: Greg Kroah-Hartman -Signed-off-by: Johan Hovold -[ johan: adjust context for 6.18 ] -Signed-off-by: Johan Hovold -Signed-off-by: Sasha Levin - -CVE-2026-63956 - -[ Backported from linux-6.12.y commit 1ef25704bd3b625fd151c09feee459479f71ee64 (mainline e1a9d791fd66ab2431b9e6f6f835823809869047); applies cleanly to AlmaLinux 10 (kernel-6.12.0-211.34.1.el10_2), zero-fuzz. ] - -diff --git a/drivers/usb/serial/cypress_m8.c b/drivers/usb/serial/cypress_m8.c -index eb47f35aab0c..905f6a560e04 100644 ---- a/drivers/usb/serial/cypress_m8.c -+++ b/drivers/usb/serial/cypress_m8.c -@@ -445,6 +445,14 @@ static int cypress_generic_port_probe(struct usb_serial_port *port) - return -ENODEV; - } - -+ /* -+ * The buffer must be large enough for the one or two-byte header (and -+ * following data), but assume anything smaller than eight bytes is -+ * broken. -+ */ -+ if (port->interrupt_out_size < 8) -+ return -EINVAL; -+ - priv = kzalloc(sizeof(struct cypress_private), GFP_KERNEL); - if (!priv) - return -ENOMEM; --- -2.50.1 (Apple Git-155) - diff --git a/1123-tunnels-load-network-headers-after-skb-cow-in.patch b/1123-tunnels-load-network-headers-after-skb-cow-in.patch deleted file mode 100644 index 6253fd567..000000000 --- a/1123-tunnels-load-network-headers-after-skb-cow-in.patch +++ /dev/null @@ -1,86 +0,0 @@ -From 50750d86a2e5266aba0c295483b3397843198b11 Mon Sep 17 00:00:00 2001 -From: Eric Dumazet -Date: Mon, 25 May 2026 20:13:35 +0000 -Subject: [PATCH] tunnels: load network headers after skb_cow() in - iptunnel_pmtud_build_icmp[v6]() - -[ Upstream commit b4bc94353050b1fa7b702bd4c6600710dd926cff ] - -Sashiko found that iptunnel_pmtud_build_icmp() and -iptunnel_pmtud_build_icmpv6() were caching ip_hdr() and ipv6_hdr() -before an skb_cow() call which can reallocate skb->head. - -Fix this possible UAF by initializing the local variables -after the skb_cow() call. - -Remove skb_reset_network_header() calls which were not needed. - -Fixes: 4cb47a8644cc ("tunnels: PMTU discovery support for directly bridged IP packets") -Signed-off-by: Eric Dumazet -Reviewed-by: Stefano Brivio -Link: https://patch.msgid.link/20260525201335.2361845-1-edumazet@google.com -Signed-off-by: Jakub Kicinski -Signed-off-by: Sasha Levin - -CVE-2026-63994 - -[ Backported from linux-6.12.y commit 50750d86a2e5266aba0c295483b3397843198b11 (mainline b4bc94353050b1fa7b702bd4c6600710dd926cff); applies cleanly to AlmaLinux 10 (kernel-6.12.0-211.34.1.el10_2), zero-fuzz. ] - -diff --git a/net/ipv4/ip_tunnel_core.c b/net/ipv4/ip_tunnel_core.c -index 507f2f9ec400..cf496644d3df 100644 ---- a/net/ipv4/ip_tunnel_core.c -+++ b/net/ipv4/ip_tunnel_core.c -@@ -210,7 +210,7 @@ EXPORT_SYMBOL_GPL(iptunnel_handle_offloads); - */ - static int iptunnel_pmtud_build_icmp(struct sk_buff *skb, int mtu) - { -- const struct iphdr *iph = ip_hdr(skb); -+ const struct iphdr *iph; - struct icmphdr *icmph; - struct iphdr *niph; - struct ethhdr eh; -@@ -224,7 +224,6 @@ static int iptunnel_pmtud_build_icmp(struct sk_buff *skb, int mtu) - - skb_copy_bits(skb, skb_mac_offset(skb), &eh, ETH_HLEN); - pskb_pull(skb, ETH_HLEN); -- skb_reset_network_header(skb); - - err = pskb_trim(skb, 576 - sizeof(*niph) - sizeof(*icmph)); - if (err) -@@ -234,7 +233,7 @@ static int iptunnel_pmtud_build_icmp(struct sk_buff *skb, int mtu) - err = skb_cow(skb, sizeof(*niph) + sizeof(*icmph) + ETH_HLEN); - if (err) - return err; -- -+ iph = ip_hdr(skb); - icmph = skb_push(skb, sizeof(*icmph)); - *icmph = (struct icmphdr) { - .type = ICMP_DEST_UNREACH, -@@ -306,7 +305,7 @@ static int iptunnel_pmtud_check_icmp(struct sk_buff *skb, int mtu) - */ - static int iptunnel_pmtud_build_icmpv6(struct sk_buff *skb, int mtu) - { -- const struct ipv6hdr *ip6h = ipv6_hdr(skb); -+ const struct ipv6hdr *ip6h; - struct icmp6hdr *icmp6h; - struct ipv6hdr *nip6h; - struct ethhdr eh; -@@ -321,7 +320,6 @@ static int iptunnel_pmtud_build_icmpv6(struct sk_buff *skb, int mtu) - - skb_copy_bits(skb, skb_mac_offset(skb), &eh, ETH_HLEN); - pskb_pull(skb, ETH_HLEN); -- skb_reset_network_header(skb); - - err = pskb_trim(skb, IPV6_MIN_MTU - sizeof(*nip6h) - sizeof(*icmp6h)); - if (err) -@@ -332,6 +330,7 @@ static int iptunnel_pmtud_build_icmpv6(struct sk_buff *skb, int mtu) - if (err) - return err; - -+ ip6h = ipv6_hdr(skb); - icmp6h = skb_push(skb, sizeof(*icmp6h)); - *icmp6h = (struct icmp6hdr) { - .icmp6_type = ICMPV6_PKT_TOOBIG, --- -2.50.1 (Apple Git-155) - diff --git a/1124-blk-mq-pop-cached-request-if-it-is-usable.patch b/1124-blk-mq-pop-cached-request-if-it-is-usable.patch deleted file mode 100644 index 99d0f81e0..000000000 --- a/1124-blk-mq-pop-cached-request-if-it-is-usable.patch +++ /dev/null @@ -1,115 +0,0 @@ -From dc278e9bf2b9513a763353e6b9cc21e0f532954e Mon Sep 17 00:00:00 2001 -From: Keith Busch -Date: Thu, 21 May 2026 12:02:53 -0700 -Subject: [PATCH] blk-mq: pop cached request if it is usable - -When submitting a bio to blk-mq, if the task should sleep after peeking -a cached request, but before it pops it, the plug flushes and calls -blk_mq_free_plug_rqs, freeing the cached_rqs. This creates a -use-after-free bug. Fix this by popping the cached request before any -possible blocking calls if it is suitable for use. - -Popping this request first holds a queue reference, so avoid any -serialization races with queue freezes and can safely proceed with -dispatching that request to the driver. This potentially increases a -timing window from when a driver wants to freeze its queue to when -requests stop being dispatched. That scenario is off the fast path -though, and drivers need to appropriately handle requests during a -freeze request anyway. - -The downside is the popped element needs to be individually freed when -we performed a bio plug merge. The cached request would have had to be -freed later anyway, but this patch does it inline with building the plug -list instead of after flushing it. - -Fixes: b0077e269f6c1 ("blk-mq: make sure active queue usage is held for bio_integrity_prep()") -Fixes: 7b4f36cd22a65 ("block: ensure we hold a queue reference when using queue limits") -Signed-off-by: Keith Busch -Link: https://patch.msgid.link/20260521190253.242065-1-kbusch@meta.com -Signed-off-by: Jens Axboe - -CVE-2026-64017 - -[ Backported from mainline commit dc278e9bf2b9513a763353e6b9cc21e0f532954e; applies cleanly to AlmaLinux 10 (kernel-6.12.0-211.34.1.el10_2), zero-fuzz. ] - -diff --git a/block/blk-mq.c b/block/blk-mq.c -index d0c37daf568f..28c2d931e75e 100644 ---- a/block/blk-mq.c -+++ b/block/blk-mq.c -@@ -3077,7 +3077,7 @@ static struct request *blk_mq_get_new_requests(struct request_queue *q, - /* - * Check if there is a suitable cached request and return it. - */ --static struct request *blk_mq_peek_cached_request(struct blk_plug *plug, -+static struct request *blk_mq_get_cached_request(struct blk_plug *plug, - struct request_queue *q, blk_opf_t opf) - { - enum hctx_type type = blk_mq_get_hctx_type(opf); -@@ -3093,27 +3093,10 @@ static struct request *blk_mq_peek_cached_request(struct blk_plug *plug, - return NULL; - if (op_is_flush(rq->cmd_flags) != op_is_flush(opf)) - return NULL; -+ rq_list_pop(&plug->cached_rqs); - return rq; - } - --static void blk_mq_use_cached_rq(struct request *rq, struct blk_plug *plug, -- struct bio *bio) --{ -- if (rq_list_pop(&plug->cached_rqs) != rq) -- WARN_ON_ONCE(1); -- -- /* -- * If any qos ->throttle() end up blocking, we will have flushed the -- * plug and hence killed the cached_rq list as well. Pop this entry -- * before we throttle. -- */ -- rq_qos_throttle(rq->q, bio); -- -- blk_mq_rq_time_init(rq, blk_time_get_ns()); -- rq->cmd_flags = bio->bi_opf; -- INIT_LIST_HEAD(&rq->queuelist); --} -- - static bool bio_unaligned(const struct bio *bio, struct request_queue *q) - { - unsigned int bs_mask = queue_logical_block_size(q) - 1; -@@ -3152,7 +3135,7 @@ void blk_mq_submit_bio(struct bio *bio) - /* - * If the plug has a cached request for this queue, try to use it. - */ -- rq = blk_mq_peek_cached_request(plug, q, bio->bi_opf); -+ rq = blk_mq_get_cached_request(plug, q, bio->bi_opf); - - /* - * A BIO that was released from a zone write plug has already been -@@ -3211,7 +3194,10 @@ void blk_mq_submit_bio(struct bio *bio) - - new_request: - if (rq) { -- blk_mq_use_cached_rq(rq, plug, bio); -+ rq_qos_throttle(rq->q, bio); -+ blk_mq_rq_time_init(rq, blk_time_get_ns()); -+ rq->cmd_flags = bio->bi_opf; -+ INIT_LIST_HEAD(&rq->queuelist); - } else { - rq = blk_mq_get_new_requests(q, plug, bio); - if (unlikely(!rq)) { -@@ -3257,12 +3243,10 @@ void blk_mq_submit_bio(struct bio *bio) - return; - - queue_exit: -- /* -- * Don't drop the queue reference if we were trying to use a cached -- * request and thus didn't acquire one. -- */ - if (!rq) - blk_queue_exit(q); -+ else -+ blk_mq_free_request(rq); - } - - #ifdef CONFIG_BLK_MQ_STACKING --- -2.50.1 (Apple Git-155) - diff --git a/1125-rxrpc-fix-data-decrypt-vs-splice-by-copying-data-to.patch b/1125-rxrpc-fix-data-decrypt-vs-splice-by-copying-data-to.patch deleted file mode 100644 index 03753614f..000000000 --- a/1125-rxrpc-fix-data-decrypt-vs-splice-by-copying-data-to.patch +++ /dev/null @@ -1,654 +0,0 @@ -From b94a6ccbaf1104dd980150a65fdeb2f69d17d2f5 Mon Sep 17 00:00:00 2001 -From: David Howells -Date: Fri, 29 May 2026 17:42:07 -0400 -Subject: [PATCH] rxrpc: Fix DATA decrypt vs splice() by copying data to buffer - in recvmsg - -[ Upstream commit d2bc90cf6c75cb96d2ce549be6c35efa3099d25b ] - -This improves the fix for CVE-2026-43500. - -Fix the pagecache corruption from in-place decryption of a DATA packet -transmitted locally by splice() by getting rid of the packet sharing in the -I/O thread and unconditionally extracting the packet content into a bounce -buffer in which the buffer is decrypted. recvmsg() (or the kernel -equivalent) then copies the data from the bounce buffer to the destination -buffer. The sk_buff then remains unmodified. - -This has an additional advantage in that the packet is then arranged in the -buffer with the correct alignment required for the crypto algorithms to -process directly. The performance of the crypto does seem to be a little -faster and, surprisingly, the unencrypted performance doesn't seem to -change much - possibly due to removing complexity from the I/O thread. - -Yet another advantage is that the I/O thread doesn't have to copy packets -which would slow down packet distribution, ACK generation, etc.. - -The buffer belongs to the call and is allocated initially at 2K, -sufficiently large to hold a whole jumbo subpacket, but the buffer will be -increased in size if needed. However, to take this work, MSG_PEEK may -cause a later packet to be decrypted into the buffer, in which case the -earlier one will need re-decrypting for a subsequent recvmsg(). - -Note that rx_pkt_offset may legitimately see 0 as a valid offset now, so -switch to using USHRT_MAX to indicate an invalid offset. - -Note also that I would generally prefer to replace the buffers of the -current sk_buff with a new kmalloc'd buffer of the right size, ditching the -old data and frags as this makes the handling of MSG_PEEK easier and -removes the re-decryption issue, but this looks like quite a complicated -thing to achieve. skb_morph() looks half way to what I want, but I don't -want to have to allocate a new sk_buff. - -Fixes: d0d5c0cd1e71 ("rxrpc: Use skb_unshare() rather than skb_cow_data()") -Reported-by: Hyunwoo Kim -Closes: https://lore.kernel.org/r/afKV2zGR6rrelPC7@v4bel/ -Signed-off-by: David Howells -cc: Simon Horman -cc: Jiayuan Chen -cc: linux-afs@lists.infradead.org -Reviewed-by: Jeffrey Altman -Tested-by: Marc Dionne -Link: https://patch.msgid.link/20260515230516.2718212-3-dhowells@redhat.com -Signed-off-by: Jakub Kicinski -Stable-dep-of: 8bfab4b6ffc2 ("rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer") -Signed-off-by: Sasha Levin -Signed-off-by: Greg Kroah-Hartman - -CVE-2026-64026 - -Backported from linux-6.12.y commit b94a6ccbaf1104dd980150a65fdeb2f69d17d2f5 -(mainline d2bc90cf6c75cb96d2ce549be6c35efa3099d25b). - -Adaptations for the a10 kernel-6.12.0-211.34.1.el10_2 tree: - - rxgk: The 6.12.y stable commit touches only 6 files because the yfs-rxgk - (GSSAPI) security class does not exist in 6.12.y stable. a10 DOES ship a - functional rxgk security class, so the rxgk.c and rxgk_common.h hunks from - the mainline commit are included as well (otherwise rxgk DATA would be read - undecrypted from the bounce buffer and remain vulnerable to the splice - corruption). rxgk_verify_packet_encrypted() is adapted to a10, which lacks - the upstream crypto_krb5_check_data_len() pre-check (separate commit). - - net/rxrpc/call_event.c: a10 carries the newer rx_queue batching rework, so - the packet-unshare block that this fix removes has a different shape - (skb_cloned() only, rxrpc_skb_put_call_rx); it is collapsed to a plain - rxrpc_input_call_packet(call, skb) as upstream does. - - net/rxrpc/rxkad.c: a10's rxkad_verify_packet_2() lacks the upstream - round_down() length alignment and the crypto_skcipher_decrypt() return-value - check (separate commits); those are preserved as-is (not introduced here). - - net/rxrpc/recvmsg.c: a10 lacks the upstream kdebug("verify = %d") line; - preserved as-is. - - net/rxrpc/ar-internal.h, call_object.c: context differs only by a10's extra - rx_queue field/init and the rxrpc_cleanup_rx_buffers() rename. - -Vulnerable pre-image confirmed present in a10 (in-place skb decryption via -skb_to_sgvec in rxkad/rxgk, RXRPC_RX_VERIFIED, rx_pkt_offset==0 recvmsg path, -call_event unshare copy). Applies zero-fuzz on the a10 tree. - -diff --git a/net/rxrpc/ar-internal.h b/net/rxrpc/ar-internal.h -index 2baa99b..a08e45c 100644 ---- a/net/rxrpc/ar-internal.h -+++ b/net/rxrpc/ar-internal.h -@@ -213,8 +213,6 @@ struct rxrpc_skb_priv { - struct { - u16 offset; /* Offset of data */ - u16 len; /* Length of data */ -- u8 flags; --#define RXRPC_RX_VERIFIED 0x01 - }; - struct { - rxrpc_seq_t first_ack; /* First packet in acks table */ -@@ -774,6 +772,11 @@ struct rxrpc_call { - struct sk_buff_head recvmsg_queue; /* Queue of packets ready for recvmsg() */ - struct sk_buff_head rx_queue; /* Queue of packets for this call to receive */ - struct sk_buff_head rx_oos_queue; /* Queue of out of sequence packets */ -+ void *rx_dec_buffer; /* Decryption buffer */ -+ unsigned short rx_dec_bsize; /* rx_dec_buffer size */ -+ unsigned short rx_dec_offset; /* Decrypted packet data offset */ -+ unsigned short rx_dec_len; /* Decrypted packet data len */ -+ rxrpc_seq_t rx_dec_seq; /* Packet in decryption buffer */ - - rxrpc_seq_t rx_highest_seq; /* Higest sequence number received */ - rxrpc_seq_t rx_consumed; /* Highest packet consumed */ -diff --git a/net/rxrpc/call_event.c b/net/rxrpc/call_event.c -index fdd6832..fec59d9 100644 ---- a/net/rxrpc/call_event.c -+++ b/net/rxrpc/call_event.c -@@ -332,25 +332,7 @@ bool rxrpc_input_call_event(struct rxrpc_call *call) - - saw_ack |= sp->hdr.type == RXRPC_PACKET_TYPE_ACK; - -- if (sp->hdr.type == RXRPC_PACKET_TYPE_DATA && -- sp->hdr.securityIndex != 0 && -- skb_cloned(skb)) { -- /* Unshare the packet so that it can be -- * modified by in-place decryption. -- */ -- struct sk_buff *nskb = skb_copy(skb, GFP_ATOMIC); -- -- if (nskb) { -- rxrpc_new_skb(nskb, rxrpc_skb_new_unshared); -- rxrpc_input_call_packet(call, nskb); -- rxrpc_free_skb(nskb, rxrpc_skb_put_call_rx); -- } else { -- /* OOM - Drop the packet. */ -- rxrpc_see_skb(skb, rxrpc_skb_see_unshare_nomem); -- } -- } else { -- rxrpc_input_call_packet(call, skb); -- } -+ rxrpc_input_call_packet(call, skb); - rxrpc_free_skb(skb, rxrpc_skb_put_call_rx); - did_receive = true; - } -diff --git a/net/rxrpc/call_object.c b/net/rxrpc/call_object.c -index 918f41d..ffe0a89 100644 ---- a/net/rxrpc/call_object.c -+++ b/net/rxrpc/call_object.c -@@ -152,6 +152,7 @@ struct rxrpc_call *rxrpc_alloc_call(struct rxrpc_sock *rx, gfp_t gfp, - spin_lock_init(&call->notify_lock); - refcount_set(&call->ref, 1); - call->debug_id = debug_id; -+ call->rx_pkt_offset = USHRT_MAX; - call->tx_total_len = -1; - call->tx_jumbo_max = 1; - call->next_rx_timo = 20 * HZ; -@@ -553,6 +554,7 @@ static void rxrpc_cleanup_rx_buffers(struct rxrpc_call *call) - rxrpc_purge_queue(&call->recvmsg_queue); - rxrpc_purge_queue(&call->rx_queue); - rxrpc_purge_queue(&call->rx_oos_queue); -+ kfree(call->rx_dec_buffer); - } - - /* -diff --git a/net/rxrpc/insecure.c b/net/rxrpc/insecure.c -index 0a260df..7a26c60 100644 ---- a/net/rxrpc/insecure.c -+++ b/net/rxrpc/insecure.c -@@ -32,9 +32,6 @@ static int none_secure_packet(struct rxrpc_call *call, struct rxrpc_txbuf *txb) - - static int none_verify_packet(struct rxrpc_call *call, struct sk_buff *skb) - { -- struct rxrpc_skb_priv *sp = rxrpc_skb(skb); -- -- sp->flags |= RXRPC_RX_VERIFIED; - return 0; - } - -diff --git a/net/rxrpc/recvmsg.c b/net/rxrpc/recvmsg.c -index 7fa7e77..fc01ee3 100644 ---- a/net/rxrpc/recvmsg.c -+++ b/net/rxrpc/recvmsg.c -@@ -147,15 +147,52 @@ static void rxrpc_rotate_rx_window(struct rxrpc_call *call) - } - - /* -- * Decrypt and verify a DATA packet. -+ * Decrypt and verify a DATA packet. The content of the packet is pulled out -+ * into a flat buffer rather than decrypting in place in the skbuff. This also -+ * has the advantage of aligning the buffer correctly for the crypto routines. -+ * -+ * We keep track of the sequence number of the packet currently decrypted into -+ * the buffer in ->rx_dec_seq. If MSG_PEEK is used and steps onto a new -+ * packet, subsequent recvmsg() calls will have to go back and re-decrypt the -+ * current packet. - */ - static int rxrpc_verify_data(struct rxrpc_call *call, struct sk_buff *skb) - { - struct rxrpc_skb_priv *sp = rxrpc_skb(skb); -+ int ret; - -- if (sp->flags & RXRPC_RX_VERIFIED) -- return 0; -- return call->security->verify_packet(call, skb); -+ if (sp->len > call->rx_dec_bsize) { -+ /* Make sure we can hold a 1412-byte jumbo subpacket and make -+ * sure that the buffer size is aligned to a crypto blocksize. -+ */ -+ size_t size = clamp(round_up(sp->len, 32), 2048, 65535); -+ void *buffer = krealloc(call->rx_dec_buffer, size, GFP_NOFS); -+ -+ if (!buffer) -+ return -ENOMEM; -+ call->rx_dec_buffer = buffer; -+ call->rx_dec_bsize = size; -+ } -+ -+ ret = -EFAULT; -+ if (skb_copy_bits(skb, sp->offset, call->rx_dec_buffer, sp->len) < 0) -+ goto err; -+ -+ call->rx_dec_offset = 0; -+ call->rx_dec_len = sp->len; -+ call->rx_dec_seq = sp->hdr.seq; -+ ret = call->security->verify_packet(call, skb); -+ if (ret < 0) -+ goto err; -+ return 0; -+ -+err: -+ kfree(call->rx_dec_buffer); -+ call->rx_dec_buffer = NULL; -+ call->rx_dec_bsize = 0; -+ call->rx_dec_offset = 0; -+ call->rx_dec_len = 0; -+ return ret; - } - - /* -@@ -283,16 +320,21 @@ static int rxrpc_recvmsg_data(struct socket *sock, struct rxrpc_call *call, - if (msg) - sock_recv_timestamp(msg, sock->sk, skb); - -- if (rx_pkt_offset == 0) { -+ if (call->rx_dec_seq != sp->hdr.seq || -+ !call->rx_dec_buffer) { - ret2 = rxrpc_verify_data(call, skb); - trace_rxrpc_recvdata(call, rxrpc_recvmsg_next, seq, -- sp->offset, sp->len, ret2); -+ call->rx_dec_offset, -+ call->rx_dec_len, ret2); - if (ret2 < 0) { - ret = ret2; - goto out; - } -- rx_pkt_offset = sp->offset; -- rx_pkt_len = sp->len; -+ } -+ -+ if (rx_pkt_offset == USHRT_MAX) { -+ rx_pkt_offset = call->rx_dec_offset; -+ rx_pkt_len = call->rx_dec_len; - } else { - trace_rxrpc_recvdata(call, rxrpc_recvmsg_cont, seq, - rx_pkt_offset, rx_pkt_len, 0); -@@ -304,10 +346,10 @@ static int rxrpc_recvmsg_data(struct socket *sock, struct rxrpc_call *call, - if (copy > remain) - copy = remain; - if (copy > 0) { -- ret2 = skb_copy_datagram_iter(skb, rx_pkt_offset, iter, -- copy); -- if (ret2 < 0) { -- ret = ret2; -+ ret2 = copy_to_iter(call->rx_dec_buffer + rx_pkt_offset, -+ copy, iter); -+ if (ret2 != copy) { -+ ret = -EFAULT; - goto out; - } - -@@ -328,7 +370,7 @@ static int rxrpc_recvmsg_data(struct socket *sock, struct rxrpc_call *call, - /* The whole packet has been transferred. */ - if (sp->hdr.flags & RXRPC_LAST_PACKET) - ret = 1; -- rx_pkt_offset = 0; -+ rx_pkt_offset = USHRT_MAX; - rx_pkt_len = 0; - - skb = skb_peek_next(skb, &call->recvmsg_queue); -diff --git a/net/rxrpc/rxgk.c b/net/rxrpc/rxgk.c -index 8d17b49..b9d2da9 100644 ---- a/net/rxrpc/rxgk.c -+++ b/net/rxrpc/rxgk.c -@@ -473,8 +473,9 @@ static int rxgk_verify_packet_integrity(struct rxrpc_call *call, - struct rxrpc_skb_priv *sp = rxrpc_skb(skb); - struct rxgk_header *hdr; - struct krb5_buffer metadata; -- unsigned int offset = sp->offset, len = sp->len; -+ unsigned int len = call->rx_dec_len; - size_t data_offset = 0, data_len = len; -+ void *data = call->rx_dec_buffer, *p = data; - u32 ac = 0; - int ret = -ENOMEM; - -@@ -496,16 +497,15 @@ static int rxgk_verify_packet_integrity(struct rxrpc_call *call, - - metadata.len = sizeof(*hdr); - metadata.data = hdr; -- ret = rxgk_verify_mic_skb(gk->krb5, gk->rx_Kc, &metadata, -- skb, &offset, &len, &ac); -+ ret = rxgk_verify_mic(gk->krb5, gk->rx_Kc, &metadata, &p, &len, &ac); - kfree(hdr); - if (ret < 0) { - if (ret != -ENOMEM) - rxrpc_abort_eproto(call, skb, ac, - rxgk_abort_1_verify_mic_eproto); - } else { -- sp->offset = offset; -- sp->len = len; -+ call->rx_dec_offset = p - data; -+ call->rx_dec_len = len; - } - - put_gk: -@@ -522,49 +522,46 @@ static int rxgk_verify_packet_encrypted(struct rxrpc_call *call, - struct sk_buff *skb) - { - struct rxrpc_skb_priv *sp = rxrpc_skb(skb); -- struct rxgk_header hdr; -- unsigned int offset = sp->offset, len = sp->len; -+ struct rxgk_header *hdr; -+ unsigned int offset = 0, len = call->rx_dec_len; -+ void *data = call->rx_dec_buffer, *p = data; - int ret; - u32 ac = 0; - - _enter(""); - -- ret = rxgk_decrypt_skb(gk->krb5, gk->rx_enc, skb, &offset, &len, &ac); -+ ret = rxgk_decrypt(gk->krb5, gk->rx_enc, &p, &len, &ac); - if (ret < 0) { - if (ret != -ENOMEM) - rxrpc_abort_eproto(call, skb, ac, rxgk_abort_2_decrypt_eproto); - goto error; - } -+ offset = p - data; - -- if (len < sizeof(hdr)) { -+ if (len < sizeof(*hdr)) { - ret = rxrpc_abort_eproto(call, skb, RXGK_PACKETSHORT, - rxgk_abort_2_short_header); - goto error; - } - - /* Extract the header from the skb */ -- ret = skb_copy_bits(skb, offset, &hdr, sizeof(hdr)); -- if (ret < 0) { -- ret = rxrpc_abort_eproto(call, skb, RXGK_PACKETSHORT, -- rxgk_abort_2_short_encdata); -- goto error; -- } -- offset += sizeof(hdr); -- len -= sizeof(hdr); -- -- if (ntohl(hdr.epoch) != call->conn->proto.epoch || -- ntohl(hdr.cid) != call->cid || -- ntohl(hdr.call_number) != call->call_id || -- ntohl(hdr.seq) != sp->hdr.seq || -- ntohl(hdr.sec_index) != call->security_ix || -- ntohl(hdr.data_len) > len) { -+ hdr = data + offset; -+ offset += sizeof(*hdr); -+ len -= sizeof(*hdr); -+ -+ if (ntohl(hdr->epoch) != call->conn->proto.epoch || -+ ntohl(hdr->cid) != call->cid || -+ ntohl(hdr->call_number) != call->call_id || -+ ntohl(hdr->seq) != sp->hdr.seq || -+ ntohl(hdr->sec_index) != call->security_ix || -+ ntohl(hdr->data_len) > len) { - ret = rxrpc_abort_eproto(call, skb, RXGK_SEALEDINCON, - rxgk_abort_2_short_data); - goto error; - } - -- sp->offset = offset; -- sp->len = ntohl(hdr.data_len); -+ call->rx_dec_offset = offset; -+ call->rx_dec_len = ntohl(hdr->data_len); - ret = 0; - error: - rxgk_put(gk); -diff --git a/net/rxrpc/rxgk_common.h b/net/rxrpc/rxgk_common.h -index 80164d8..bae8b98 100644 ---- a/net/rxrpc/rxgk_common.h -+++ b/net/rxrpc/rxgk_common.h -@@ -104,6 +104,49 @@ int rxgk_decrypt_skb(const struct krb5_enctype *krb5, - return ret; - } - -+/* -+ * Apply decryption and checksumming functions a flat data buffer. The data -+ * point and length are updated to reflect the actual content of the encrypted -+ * region. -+ */ -+static inline int rxgk_decrypt(const struct krb5_enctype *krb5, -+ struct crypto_aead *aead, -+ void **_data, unsigned int *_len, -+ int *_error_code) -+{ -+ struct scatterlist sg[1]; -+ size_t offset = 0, len = *_len; -+ int ret; -+ -+ sg_init_one(sg, *_data, len); -+ -+ ret = crypto_krb5_decrypt(krb5, aead, sg, 1, &offset, &len); -+ switch (ret) { -+ case 0: -+ if (offset & 3) { -+ *_error_code = RXGK_INCONSISTENCY; -+ ret = -EPROTO; -+ break; -+ } -+ *_data += offset; -+ *_len = len; -+ break; -+ case -EBADMSG: /* Checksum mismatch. */ -+ case -EPROTO: -+ *_error_code = RXGK_SEALEDINCON; -+ break; -+ case -EMSGSIZE: -+ *_error_code = RXGK_PACKETSHORT; -+ break; -+ case -ENOPKG: /* Would prefer RXGK_BADETYPE, but not available for YFS. */ -+ default: -+ *_error_code = RXGK_INCONSISTENCY; -+ break; -+ } -+ -+ return ret; -+} -+ - /* - * Check the MIC on a region of an skbuff. The offset and length are updated - * to reflect the actual content of the secure region. -@@ -147,3 +190,42 @@ int rxgk_verify_mic_skb(const struct krb5_enctype *krb5, - - return ret; - } -+ -+/* -+ * Check the MIC on a flat buffer. The data pointer and length are updated to -+ * reflect the actual content of the secure region. -+ */ -+static inline -+int rxgk_verify_mic(const struct krb5_enctype *krb5, -+ struct crypto_shash *shash, -+ const struct krb5_buffer *metadata, -+ void **_data, unsigned int *_len, -+ u32 *_error_code) -+{ -+ struct scatterlist sg[1]; -+ size_t offset = 0, len = *_len; -+ int ret; -+ -+ sg_init_one(sg, *_data, len); -+ -+ ret = crypto_krb5_verify_mic(krb5, shash, metadata, sg, 1, &offset, &len); -+ switch (ret) { -+ case 0: -+ *_data += offset; -+ *_len = len; -+ break; -+ case -EBADMSG: /* Checksum mismatch */ -+ case -EPROTO: -+ *_error_code = RXGK_SEALEDINCON; -+ break; -+ case -EMSGSIZE: -+ *_error_code = RXGK_PACKETSHORT; -+ break; -+ case -ENOPKG: /* Would prefer RXGK_BADETYPE, but not available for YFS. */ -+ default: -+ *_error_code = RXGK_INCONSISTENCY; -+ break; -+ } -+ -+ return ret; -+} -diff --git a/net/rxrpc/rxkad.c b/net/rxrpc/rxkad.c -index 3657c06..cf780ba 100644 ---- a/net/rxrpc/rxkad.c -+++ b/net/rxrpc/rxkad.c -@@ -425,27 +425,24 @@ static int rxkad_verify_packet_1(struct rxrpc_call *call, struct sk_buff *skb, - rxrpc_seq_t seq, - struct skcipher_request *req) - { -- struct rxkad_level1_hdr sechdr; -+ struct rxkad_level1_hdr *sechdr; - struct rxrpc_skb_priv *sp = rxrpc_skb(skb); - struct rxrpc_crypt iv; -- struct scatterlist sg[16]; -- u32 data_size, buf; -+ struct scatterlist sg[1]; -+ void *data = call->rx_dec_buffer; -+ u32 len = sp->len, data_size, buf; - u16 check; -- int ret; - - _enter(""); - -- if (sp->len < 8) -+ if (len < 8) - return rxrpc_abort_eproto(call, skb, RXKADSEALEDINCON, - rxkad_abort_1_short_header); - - /* Decrypt the skbuff in-place. TODO: We really want to decrypt - * directly into the target buffer. - */ -- sg_init_table(sg, ARRAY_SIZE(sg)); -- ret = skb_to_sgvec(skb, sg, sp->offset, 8); -- if (unlikely(ret < 0)) -- return ret; -+ sg_init_one(sg, data, len); - - /* start the decryption afresh */ - memset(&iv, 0, sizeof(iv)); -@@ -457,13 +454,11 @@ static int rxkad_verify_packet_1(struct rxrpc_call *call, struct sk_buff *skb, - skcipher_request_zero(req); - - /* Extract the decrypted packet length */ -- if (skb_copy_bits(skb, sp->offset, &sechdr, sizeof(sechdr)) < 0) -- return rxrpc_abort_eproto(call, skb, RXKADDATALEN, -- rxkad_abort_1_short_encdata); -- sp->offset += sizeof(sechdr); -- sp->len -= sizeof(sechdr); -+ sechdr = data; -+ call->rx_dec_offset = sizeof(*sechdr); -+ len -= sizeof(*sechdr); - -- buf = ntohl(sechdr.data_size); -+ buf = ntohl(sechdr->data_size); - data_size = buf & 0xffff; - - check = buf >> 16; -@@ -472,10 +467,10 @@ static int rxkad_verify_packet_1(struct rxrpc_call *call, struct sk_buff *skb, - if (check != 0) - return rxrpc_abort_eproto(call, skb, RXKADSEALEDINCON, - rxkad_abort_1_short_check); -- if (data_size > sp->len) -+ if (data_size > len) - return rxrpc_abort_eproto(call, skb, RXKADDATALEN, - rxkad_abort_1_short_data); -- sp->len = data_size; -+ call->rx_dec_len = data_size; - - _leave(" = 0 [dlen=%x]", data_size); - return 0; -@@ -489,40 +484,24 @@ static int rxkad_verify_packet_2(struct rxrpc_call *call, struct sk_buff *skb, - struct skcipher_request *req) - { - const struct rxrpc_key_token *token; -- struct rxkad_level2_hdr sechdr; -+ struct rxkad_level2_hdr *sechdr; - struct rxrpc_skb_priv *sp = rxrpc_skb(skb); - struct rxrpc_crypt iv; -- struct scatterlist _sg[4], *sg; -- u32 data_size, buf; -+ struct scatterlist sg[1]; -+ void *data = call->rx_dec_buffer; -+ u32 len = sp->len, data_size, buf; - u16 check; -- int nsg, ret; - -- _enter(",{%d}", sp->len); -+ _enter(",{%d}", len); - -- if (sp->len < 8) -+ if (len < 8) - return rxrpc_abort_eproto(call, skb, RXKADSEALEDINCON, - rxkad_abort_2_short_header); - -- /* Decrypt the skbuff in-place. TODO: We really want to decrypt -- * directly into the target buffer. -+ /* Decrypt in place in the call's decryption buffer. TODO: We really -+ * want to decrypt directly into the target buffer. - */ -- sg = _sg; -- nsg = skb_shinfo(skb)->nr_frags + 1; -- if (nsg <= 4) { -- nsg = 4; -- } else { -- sg = kmalloc_array(nsg, sizeof(*sg), GFP_NOIO); -- if (!sg) -- return -ENOMEM; -- } -- -- sg_init_table(sg, nsg); -- ret = skb_to_sgvec(skb, sg, sp->offset, sp->len); -- if (unlikely(ret < 0)) { -- if (sg != _sg) -- kfree(sg); -- return ret; -- } -+ sg_init_one(sg, data, len); - - /* decrypt from the session key */ - token = call->conn->key->payload.data[0]; -@@ -530,20 +509,16 @@ static int rxkad_verify_packet_2(struct rxrpc_call *call, struct sk_buff *skb, - - skcipher_request_set_sync_tfm(req, call->conn->rxkad.cipher); - skcipher_request_set_callback(req, 0, NULL, NULL); -- skcipher_request_set_crypt(req, sg, sg, sp->len, iv.x); -+ skcipher_request_set_crypt(req, sg, sg, len, iv.x); - crypto_skcipher_decrypt(req); - skcipher_request_zero(req); -- if (sg != _sg) -- kfree(sg); - - /* Extract the decrypted packet length */ -- if (skb_copy_bits(skb, sp->offset, &sechdr, sizeof(sechdr)) < 0) -- return rxrpc_abort_eproto(call, skb, RXKADDATALEN, -- rxkad_abort_2_short_len); -- sp->offset += sizeof(sechdr); -- sp->len -= sizeof(sechdr); -+ sechdr = data; -+ call->rx_dec_offset = sizeof(*sechdr); -+ len -= sizeof(*sechdr); - -- buf = ntohl(sechdr.data_size); -+ buf = ntohl(sechdr->data_size); - data_size = buf & 0xffff; - - check = buf >> 16; -@@ -553,17 +528,18 @@ static int rxkad_verify_packet_2(struct rxrpc_call *call, struct sk_buff *skb, - return rxrpc_abort_eproto(call, skb, RXKADSEALEDINCON, - rxkad_abort_2_short_check); - -- if (data_size > sp->len) -+ if (data_size > len) - return rxrpc_abort_eproto(call, skb, RXKADDATALEN, - rxkad_abort_2_short_data); - -- sp->len = data_size; -+ call->rx_dec_len = data_size; - _leave(" = 0 [dlen=%x]", data_size); - return 0; - } - - /* -- * Verify the security on a received packet and the subpackets therein. -+ * Verify the security on a received (sub)packet. If the packet needs -+ * modifying (e.g. decrypting), it must be copied. - */ - static int rxkad_verify_packet(struct rxrpc_call *call, struct sk_buff *skb) - { diff --git a/1126-wifi-mac80211-bounds-check-link-id-in-ieee80211-ml-e.patch b/1126-wifi-mac80211-bounds-check-link-id-in-ieee80211-ml-e.patch deleted file mode 100644 index e5fea0ecc..000000000 --- a/1126-wifi-mac80211-bounds-check-link-id-in-ieee80211-ml-e.patch +++ /dev/null @@ -1,51 +0,0 @@ -From f718506edd2d9c6a308ded9d13c632bf7b7d5a2c Mon Sep 17 00:00:00 2001 -From: Alexandru Hossu -Date: Fri, 15 May 2026 12:29:08 +0200 -Subject: [PATCH] wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs - -IEEE80211_MLE_STA_EPCS_CONTROL_LINK_ID is 0x000f, so link_id extracted -from a PRIO_ACCESS ML element PER_STA_PROFILE subelement can be 0..15. -sdata->link[] has IEEE80211_MLD_MAX_NUM_LINKS (15) entries (indices 0..14), -making index 15 out-of-bounds. - -A connected WiFi 7 AP can trigger this by sending an EPCS Enable Response -action frame with a PER_STA_PROFILE subelement where link_id = 15. The -unsolicited-notification path (dialog_token = 0) is reachable any time -EPCS is already enabled, without any prior client request. - -sdata->link[15] reads into the first word of sdata->activate_links_work -(a wiphy_work whose embedded list_head is non-NULL after INIT_LIST_HEAD), -so the NULL check on the result does not catch the invalid access. The -garbage pointer is then passed to ieee80211_sta_wmm_params(), which -dereferences link->sdata and crashes the kernel. - -The same class of bug was fixed for ieee80211_ml_reconfiguration() by -commit 162d331d833d ("wifi: mac80211: bounds-check link_id in -ieee80211_ml_reconfiguration"). - -Fixes: de86c5f60839 ("wifi: mac80211: Add support for EPCS configuration") -Signed-off-by: Alexandru Hossu -Link: https://patch.msgid.link/20260515102908.1653088-1-hossu.alexandru@gmail.com -Signed-off-by: Johannes Berg - -CVE-2026-64030 - -[ Backported from mainline commit f718506edd2d9c6a308ded9d13c632bf7b7d5a2c; applies cleanly to AlmaLinux 10 (kernel-6.12.0-211.34.1.el10_2), zero-fuzz. ] - -diff --git a/net/mac80211/mlme.c b/net/mac80211/mlme.c -index 0a0f27836d57..ca1d29daf019 100644 ---- a/net/mac80211/mlme.c -+++ b/net/mac80211/mlme.c -@@ -11232,6 +11232,9 @@ static void ieee80211_ml_epcs(struct ieee80211_sub_if_data *sdata, - control = get_unaligned_le16(pos); - link_id = control & IEEE80211_MLE_STA_EPCS_CONTROL_LINK_ID; - -+ if (link_id >= IEEE80211_MLD_MAX_NUM_LINKS) -+ continue; -+ - link = sdata_dereference(sdata->link[link_id], sdata); - if (!link) - continue; --- -2.50.1 (Apple Git-155) - diff --git a/Makefile.rhelver b/Makefile.rhelver index d1c9acc5b..8193ded8d 100644 --- a/Makefile.rhelver +++ b/Makefile.rhelver @@ -12,7 +12,7 @@ RHEL_MINOR = 2 # # Use this spot to avoid future merge conflicts. # Do not trim this comment. -RHEL_RELEASE = 211.34.1 +RHEL_RELEASE = 211.37.1 # # RHEL_REBASE_NUM diff --git a/kernel-aarch64-64k-debug-rhel.config b/kernel-aarch64-64k-debug-rhel.config index c3d04da0d..7625c3f9c 100644 --- a/kernel-aarch64-64k-debug-rhel.config +++ b/kernel-aarch64-64k-debug-rhel.config @@ -5350,7 +5350,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK_QORIQ=m CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC_MMIO is not set CONFIG_PVPANIC_PCI=m diff --git a/kernel-aarch64-64k-rhel.config b/kernel-aarch64-64k-rhel.config index fd97f2e1e..791bffceb 100644 --- a/kernel-aarch64-64k-rhel.config +++ b/kernel-aarch64-64k-rhel.config @@ -5327,7 +5327,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK_QORIQ=m CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC_MMIO is not set CONFIG_PVPANIC_PCI=m diff --git a/kernel-aarch64-debug-rhel.config b/kernel-aarch64-debug-rhel.config index 711135f90..ab1058710 100644 --- a/kernel-aarch64-debug-rhel.config +++ b/kernel-aarch64-debug-rhel.config @@ -5346,7 +5346,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK_QORIQ=m CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC_MMIO is not set CONFIG_PVPANIC_PCI=m diff --git a/kernel-aarch64-rhel.config b/kernel-aarch64-rhel.config index f058db44d..6a7cf61dd 100644 --- a/kernel-aarch64-rhel.config +++ b/kernel-aarch64-rhel.config @@ -5323,7 +5323,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK_QORIQ=m CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC_MMIO is not set CONFIG_PVPANIC_PCI=m diff --git a/kernel-aarch64-rt-64k-debug-rhel.config b/kernel-aarch64-rt-64k-debug-rhel.config index 027682b3f..c1d17dcaa 100644 --- a/kernel-aarch64-rt-64k-debug-rhel.config +++ b/kernel-aarch64-rt-64k-debug-rhel.config @@ -5394,7 +5394,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK_QORIQ=m CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC_MMIO is not set CONFIG_PVPANIC_PCI=m diff --git a/kernel-aarch64-rt-64k-rhel.config b/kernel-aarch64-rt-64k-rhel.config index 26f715829..8697078ea 100644 --- a/kernel-aarch64-rt-64k-rhel.config +++ b/kernel-aarch64-rt-64k-rhel.config @@ -5371,7 +5371,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK_QORIQ=m CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC_MMIO is not set CONFIG_PVPANIC_PCI=m diff --git a/kernel-aarch64-rt-debug-rhel.config b/kernel-aarch64-rt-debug-rhel.config index ce65e735e..5beca56ef 100644 --- a/kernel-aarch64-rt-debug-rhel.config +++ b/kernel-aarch64-rt-debug-rhel.config @@ -5390,7 +5390,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK_QORIQ=m CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC_MMIO is not set CONFIG_PVPANIC_PCI=m diff --git a/kernel-aarch64-rt-rhel.config b/kernel-aarch64-rt-rhel.config index 61cce3368..feb71294d 100644 --- a/kernel-aarch64-rt-rhel.config +++ b/kernel-aarch64-rt-rhel.config @@ -5367,7 +5367,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK_QORIQ=m CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC_MMIO is not set CONFIG_PVPANIC_PCI=m diff --git a/kernel-ppc64le-debug-rhel.config b/kernel-ppc64le-debug-rhel.config index ec81925bd..cec2dca53 100644 --- a/kernel-ppc64le-debug-rhel.config +++ b/kernel-ppc64le-debug-rhel.config @@ -4915,7 +4915,7 @@ CONFIG_PTP_1588_CLOCK_KVM=m CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC is not set # CONFIG_PVPANIC_MMIO is not set diff --git a/kernel-ppc64le-rhel.config b/kernel-ppc64le-rhel.config index c74c8e76b..ce118921a 100644 --- a/kernel-ppc64le-rhel.config +++ b/kernel-ppc64le-rhel.config @@ -4894,7 +4894,7 @@ CONFIG_PTP_1588_CLOCK_KVM=m CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC is not set # CONFIG_PVPANIC_MMIO is not set diff --git a/kernel-riscv64-debug-rhel.config b/kernel-riscv64-debug-rhel.config index 46313f93c..f37b6ccd7 100644 --- a/kernel-riscv64-debug-rhel.config +++ b/kernel-riscv64-debug-rhel.config @@ -4829,7 +4829,7 @@ CONFIG_PTP_1588_CLOCK_KVM=m CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC is not set # CONFIG_PVPANIC_MMIO is not set diff --git a/kernel-riscv64-rhel.config b/kernel-riscv64-rhel.config index 55f7fb93a..09256840f 100644 --- a/kernel-riscv64-rhel.config +++ b/kernel-riscv64-rhel.config @@ -4808,7 +4808,7 @@ CONFIG_PTP_1588_CLOCK_KVM=m CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC is not set # CONFIG_PVPANIC_MMIO is not set diff --git a/kernel-s390x-debug-rhel.config b/kernel-s390x-debug-rhel.config index 0b882731e..fff4f61bb 100644 --- a/kernel-s390x-debug-rhel.config +++ b/kernel-s390x-debug-rhel.config @@ -4852,7 +4852,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK=y CONFIG_PTP_S390=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC is not set # CONFIG_PVPANIC_MMIO is not set diff --git a/kernel-s390x-rhel.config b/kernel-s390x-rhel.config index 8f7e98843..35b2258a9 100644 --- a/kernel-s390x-rhel.config +++ b/kernel-s390x-rhel.config @@ -4831,7 +4831,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK=y CONFIG_PTP_S390=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC is not set # CONFIG_PVPANIC_MMIO is not set diff --git a/kernel-s390x-zfcpdump-rhel.config b/kernel-s390x-zfcpdump-rhel.config index 5484d69ba..c1cf0f9f0 100644 --- a/kernel-s390x-zfcpdump-rhel.config +++ b/kernel-s390x-zfcpdump-rhel.config @@ -4842,7 +4842,7 @@ CONFIG_PTP_1588_CLOCK_KVM=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK=y # CONFIG_PTP_S390 is not set -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set # CONFIG_PVPANIC is not set # CONFIG_PVPANIC_MMIO is not set diff --git a/kernel-x86_64-debug-rhel.config b/kernel-x86_64-debug-rhel.config index ac77779b5..176f595d7 100644 --- a/kernel-x86_64-debug-rhel.config +++ b/kernel-x86_64-debug-rhel.config @@ -5191,7 +5191,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK_VMW=m CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set CONFIG_PVH=y CONFIG_PVPANIC_MMIO=m diff --git a/kernel-x86_64-rhel.config b/kernel-x86_64-rhel.config index 217178f90..ef58c77a5 100644 --- a/kernel-x86_64-rhel.config +++ b/kernel-x86_64-rhel.config @@ -5169,7 +5169,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK_VMW=m CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set CONFIG_PVH=y CONFIG_PVPANIC_MMIO=m diff --git a/kernel-x86_64-rt-debug-rhel.config b/kernel-x86_64-rt-debug-rhel.config index 0ad2c14fe..aac3e1377 100644 --- a/kernel-x86_64-rt-debug-rhel.config +++ b/kernel-x86_64-rt-debug-rhel.config @@ -5235,7 +5235,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK_VMW=m CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set CONFIG_PVH=y CONFIG_PVPANIC_MMIO=m diff --git a/kernel-x86_64-rt-rhel.config b/kernel-x86_64-rt-rhel.config index 5593efb6e..9808411be 100644 --- a/kernel-x86_64-rt-rhel.config +++ b/kernel-x86_64-rt-rhel.config @@ -5213,7 +5213,7 @@ CONFIG_PTP_1588_CLOCK_MOCK=m # CONFIG_PTP_1588_CLOCK_OCP is not set CONFIG_PTP_1588_CLOCK_VMW=m CONFIG_PTP_1588_CLOCK=y -CONFIG_PT_RECLAIM=y +# CONFIG_PT_RECLAIM is not set # CONFIG_PUNIT_ATOM_DEBUG is not set CONFIG_PVH=y CONFIG_PVPANIC_MMIO=m diff --git a/kernel.changelog b/kernel.changelog index 7b520ed97..d00cd8062 100644 --- a/kernel.changelog +++ b/kernel.changelog @@ -1,4 +1,75 @@ -* Mon Jul 13 2026 CKI KWF Bot [6.12.0-211.34.1.el10_2] +* Tue Jul 21 2026 CKI KWF Bot [6.12.0-211.37.1.el10_2] +- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (CKI Backport Bot) [RHEL-212681] +- fanotify: fix false positive on permission events (CKI Backport Bot) [RHEL-180076] {CVE-2026-46150} +Resolves: RHEL-180076, RHEL-212681 + +* Mon Jul 20 2026 CKI KWF Bot [6.12.0-211.36.1.el10_2] +- ice: fix double-free of tx_buf skb (Jakub Ramaseuski) [RHEL-191324 RHEL-192200] {CVE-2026-53009} +- ice: fix double free in ice_sf_eth_activate() error path (Jakub Ramaseuski) [RHEL-191324] {CVE-2026-46162} +- ice: update PCS latency settings for E825 10G/25Gb modes (Jakub Ramaseuski) [RHEL-191324] +- ice: fix 'adjust' timer programming for E830 devices (Jakub Ramaseuski) [RHEL-191324] +- ice: use bitmap_empty() in ice_vf_has_no_qs_ena (Jakub Ramaseuski) [RHEL-191324] +- ice: use bitmap_weighted_xor() in ice_find_free_recp_res_idx() (Jakub Ramaseuski) [RHEL-191324] +- ice: Make name member of struct ice_cgu_pin_desc const (Jakub Ramaseuski) [RHEL-191324] +- ice: fix PTP timestamping broken by SyncE code on E825C (Jakub Ramaseuski) [RHEL-191324] +- ice: ptp: don't WARN when controlling PF is unavailable (Jakub Ramaseuski) [RHEL-191324] {CVE-2026-43346} +- ice: use ice_update_eth_stats() for representor stats (Jakub Ramaseuski) [RHEL-191324] +- ice: fix inverted ready check for VF representors (Jakub Ramaseuski) [RHEL-191324] +- drivers: net: ice: fix devlink parameters get without irdma (Jakub Ramaseuski) [RHEL-191324] +- ice: fix rxq info registering in mbuf packets (Jakub Ramaseuski) [RHEL-191324] +- ice: fix retry for AQ command 0x06EE (Jakub Ramaseuski) [RHEL-191324] +- ice: reintroduce retry mechanism for indirect AQ (Jakub Ramaseuski) [RHEL-191324] +- ice: fix adding AQ LLDP filter for VF (Jakub Ramaseuski) [RHEL-191324] +- ice: recap the VSI and QoS info after rebuild (Jakub Ramaseuski) [RHEL-191324] +- ice: fix missing TX timestamps interrupts on E825 devices (Jakub Ramaseuski) [RHEL-191324] +- ice: stop counting UDP csum mismatch as rx_errors (Jakub Ramaseuski) [RHEL-191324] +- ice: reshuffle and group Rx and Tx queue fields by cachelines (Jakub Ramaseuski) [RHEL-191324] +- ice: convert all ring stats to u64_stats_t (Jakub Ramaseuski) [RHEL-191324] +- ice: shorten ring stat names and add accessors (Jakub Ramaseuski) [RHEL-191324] +- ice: use u64_stats API to access pkts/bytes in dim sample (Jakub Ramaseuski) [RHEL-191324] +- ice: remove ice_q_stats struct and use struct_group (Jakub Ramaseuski) [RHEL-191324] +- ice: pass pointer to ice_fetch_u64_stats_per_ring (Jakub Ramaseuski) [RHEL-191324] +- ice: unify PHY FW loading status handler for E800 devices (Jakub Ramaseuski) [RHEL-191324] +- ice: Fix NULL pointer dereference in ice_vsi_set_napi_queues (Jakub Ramaseuski) [RHEL-191324] {CVE-2026-23166} +- bitmap: introduce bitmap_weighted_xor() (Jakub Ramaseuski) [RHEL-191324] +- bitmap: add test_zero_nbits() (Jakub Ramaseuski) [RHEL-191324] +- bitmap: exclude nbits == 0 cases from bitmap test (Jakub Ramaseuski) [RHEL-191324] +- bitmap: test bitmap_weight() for more (Jakub Ramaseuski) [RHEL-191324] +- bitmap: add bitmap_weight_from() (Jakub Ramaseuski) [RHEL-191324] +- bitmap: align test_bitmap output (Jakub Ramaseuski) [RHEL-191324] +- bitmap: switch test to scnprintf("%%*pbl") (Jakub Ramaseuski) [RHEL-191324] +- bitmap: Add test for out-of-boundary modifications for scatter & gather (Jakub Ramaseuski) [RHEL-191324] +- cpumask: Introduce cpumask_weighted_or() (Jakub Ramaseuski) [RHEL-191324] +- bitmap: Align documentation between bitmap_gather() and bitmap_scatter() (Jakub Ramaseuski) [RHEL-191324] +- bitmap: remove _check_eq_u32_array (Jakub Ramaseuski) [RHEL-191324] +- include: update references to include/asm- (Jakub Ramaseuski) [RHEL-191324] +- KEYS: trusted: Fix a memory leak in tpm2_load_cmd (CKI Backport Bot) [RHEL-189604] {CVE-2025-71147} +- crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CKI Backport Bot) [RHEL-189576] {CVE-2025-71113} +- drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CKI Backport Bot) [RHEL-188644] {CVE-2026-52976} +- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (Sabrina Dubroca) [RHEL-180167] {CVE-2026-46116} +Resolves: RHEL-180167, RHEL-188644, RHEL-189576, RHEL-189604, RHEL-191324, RHEL-192200 + +* Thu Jul 16 2026 CKI KWF Bot [6.12.0-211.35.1.el10_2] +- drm/xe/dma-buf: fix UAF with retry loop (Karol Herbst) [RHEL-192232] {CVE-2026-52950} +- drm/xe/dma-buf: handle empty bo and UAF races (Karol Herbst) [RHEL-192232] +- drm/xe: Fix bo leak in xe_dma_buf_init_obj() on allocation failure (Karol Herbst) [RHEL-192232] +- drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (Karol Herbst) [RHEL-192232] +- nfsd: cancel async COPY operations when admin revokes filesystem state (Olga Kornievskaia) [RHEL-173103] +- nfsd: use correct loop termination in nfsd4_revoke_states() (Olga Kornievskaia) [RHEL-173103] +- nfsd: check that server is running in unlock_filesystem (Olga Kornievskaia) [RHEL-173103] +- drm/gem: Try to fix change_handle ioctl, attempt 4 (Jocelyn Falempe) [RHEL-179887] +- drm/gem: fix race between change_handle and handle_delete (Jocelyn Falempe) [RHEL-179887] +- drm: Replace old pointer to new idr (Jocelyn Falempe) [RHEL-179887] +- drm: Set old handle to NULL before prime swap in change_handle (Jocelyn Falempe) [RHEL-179887] {CVE-2026-46215} +- drm: Do not allow userspace to trigger kernel warnings in drm_gem_change_handle_ioctl() (Jocelyn Falempe) [RHEL-179887] +- cxl/port: Fix use after free of parent_port in cxl_detach_ep() (Myron Stowe) [RHEL-180697] {CVE-2026-31530} +- flex_proportions: make fprop_new_period() hardirq safe (CKI Backport Bot) [RHEL-189658] {CVE-2026-23168} +- Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CKI Backport Bot) [RHEL-188331] {CVE-2026-53071} +- redhat/configs: disable CONFIG_PT_RECLAIM (Luiz Capitulino) [RHEL-186311] +- libperf build: Always place libperf includes first (Michael Petlan) [RHEL-183975] +Resolves: RHEL-173103, RHEL-179887, RHEL-180697, RHEL-183975, RHEL-186311, RHEL-188331, RHEL-189658, RHEL-192232 + +* Tue Jul 14 2026 Jan Stancek [6.12.0-211.34.1.el10_2] - crypto: ccp - copy IV using skcipher ivsize (CKI Backport Bot) [RHEL-188463] {CVE-2026-53016} - xfs: resample the data fork mapping after cycling ILOCK (Carlos Maiolino) [RHEL-193945] - xfrm: esp: restore combined single-frag length gate (CKI Backport Bot) [RHEL-178326] diff --git a/kernel.spec b/kernel.spec index d140ae69a..03d56d26e 100644 --- a/kernel.spec +++ b/kernel.spec @@ -176,15 +176,15 @@ Summary: The Linux kernel %define specrpmversion 6.12.0 %define specversion 6.12.0 %define patchversion 6.12 -%define pkgrelease 211.34.3 +%define pkgrelease 211.37.1 %define kversion 6 -%define tarfile_release 6.12.0-211.34.1.el10_2 +%define tarfile_release 6.12.0-211.37.1.el10_2 # This is needed to do merge window version magic %define patchlevel 12 # This allows pkg_release to have configurable %%{?dist} tag -%define specrelease 211.34.3%{?buildid}%{?dist} +%define specrelease 211.37.1%{?buildid}%{?dist} # This defines the kabi tarball version -%define kabiversion 6.12.0-211.34.1.el10_2 +%define kabiversion 6.12.0-211.37.1.el10_2 # If this variable is set to 1, a bpf selftests build failure will cause a # fatal kernel package build error @@ -1139,32 +1139,6 @@ Patch2008: 0008-Bring-back-deprecated-pci-ids-to-megaraid_sas-driver.patch Patch2009: 0009-Bring-back-deprecated-pci-ids-to-mpt3sas-driver.patch Patch2010: 0001-Keep-fs-btrfs-files-in-modules-package.patch -Patch1100: 1100-nfsd-fix-secinfo-no-name-decode-error-cleanup.patch -Patch1101: 1101-nfsd-release-layout-stid-on-setlease-failure.patch -Patch1102: 1102-kvm-svm-fix-page-overflow-in-sev-dbg-crypt-for-encrypt.patch -Patch1103: 1103-rpmsg-char-fix-use-after-free-on-probe-error-path.patch -Patch1104: 1104-keys-fix-overflow-in-keyctl-pkey-params-get-2.patch -Patch1105: 1105-net-ip-gre-require-cap-net-admin-in-the-device-netns-fo.patch -Patch1106: 1106-wifi-iwlwifi-mld-fix-tso-segmentation-explosion-when-am.patch -Patch1107: 1107-vfio-pci-check-bar-resources-before-exporting-a-dmabuf.patch -Patch1108: 1108-accel-qaic-add-overflow-check-to-remap-pfn-range-during.patch -Patch1109: 1109-netfs-fix-early-put-of-sink-folio-in-netfs-read-gaps.patch -Patch1110: 1110-ixgbevf-fix-use-after-free-in-vepa-multicast-source-pru.patch -Patch1111: 1111-ipv6-ioam-refresh-hdr-pointer-before-ioam6-event.patch -Patch1112: 1112-i2c-stub-reject-i2c-block-transfers-with-invalid-length.patch -Patch1113: 1113-scsi-target-iscsi-validate-chap-r-length-before-base.patch -Patch1114: 1114-scsi-target-iscsi-bound-iscsi-encode-text-output-app.patch -Patch1115: 1115-scsi-target-iscsi-fix-crc-overread-and-double-free-i.patch -Patch1116: 1116-usb-serial-mxuport-fix-memory-corruption-with-small.patch -Patch1117: 1117-ip6-vti-use-ip6-tnl-net-in-vti6-changelink.patch -Patch1118: 1118-ipv6-exthdrs-refresh-nh-pointer-after-ipv6-hop-jumbo.patch -Patch1119: 1119-ipv6-exthdrs-refresh-nh-after-handling-hao-option.patch -Patch1120: 1120-kvm-sev-compute-the-correct-max-length-of-the-in-ghc.patch -Patch1122: 1122-usb-serial-cypress-m8-fix-memory-corruption-with-sma.patch -Patch1123: 1123-tunnels-load-network-headers-after-skb-cow-in.patch -Patch1124: 1124-blk-mq-pop-cached-request-if-it-is-usable.patch -Patch1125: 1125-rxrpc-fix-data-decrypt-vs-splice-by-copying-data-to.patch -Patch1126: 1126-wifi-mac80211-bounds-check-link-id-in-ieee80211-ml-e.patch # END OF PATCH DEFINITIONS %description @@ -2026,32 +2000,6 @@ ApplyPatch 0009-Bring-back-deprecated-pci-ids-to-mpt3sas-driver.patch ApplyPatch 0001-Keep-fs-btrfs-files-in-modules-package.patch %{log_msg "End of patch applications"} -ApplyPatch 1100-nfsd-fix-secinfo-no-name-decode-error-cleanup.patch -ApplyPatch 1101-nfsd-release-layout-stid-on-setlease-failure.patch -ApplyPatch 1102-kvm-svm-fix-page-overflow-in-sev-dbg-crypt-for-encrypt.patch -ApplyPatch 1103-rpmsg-char-fix-use-after-free-on-probe-error-path.patch -ApplyPatch 1104-keys-fix-overflow-in-keyctl-pkey-params-get-2.patch -ApplyPatch 1105-net-ip-gre-require-cap-net-admin-in-the-device-netns-fo.patch -ApplyPatch 1106-wifi-iwlwifi-mld-fix-tso-segmentation-explosion-when-am.patch -ApplyPatch 1107-vfio-pci-check-bar-resources-before-exporting-a-dmabuf.patch -ApplyPatch 1108-accel-qaic-add-overflow-check-to-remap-pfn-range-during.patch -ApplyPatch 1109-netfs-fix-early-put-of-sink-folio-in-netfs-read-gaps.patch -ApplyPatch 1110-ixgbevf-fix-use-after-free-in-vepa-multicast-source-pru.patch -ApplyPatch 1111-ipv6-ioam-refresh-hdr-pointer-before-ioam6-event.patch -ApplyPatch 1112-i2c-stub-reject-i2c-block-transfers-with-invalid-length.patch -ApplyPatch 1113-scsi-target-iscsi-validate-chap-r-length-before-base.patch -ApplyPatch 1114-scsi-target-iscsi-bound-iscsi-encode-text-output-app.patch -ApplyPatch 1115-scsi-target-iscsi-fix-crc-overread-and-double-free-i.patch -ApplyPatch 1116-usb-serial-mxuport-fix-memory-corruption-with-small.patch -ApplyPatch 1117-ip6-vti-use-ip6-tnl-net-in-vti6-changelink.patch -ApplyPatch 1118-ipv6-exthdrs-refresh-nh-pointer-after-ipv6-hop-jumbo.patch -ApplyPatch 1119-ipv6-exthdrs-refresh-nh-after-handling-hao-option.patch -ApplyPatch 1120-kvm-sev-compute-the-correct-max-length-of-the-in-ghc.patch -ApplyPatch 1122-usb-serial-cypress-m8-fix-memory-corruption-with-sma.patch -ApplyPatch 1123-tunnels-load-network-headers-after-skb-cow-in.patch -ApplyPatch 1124-blk-mq-pop-cached-request-if-it-is-usable.patch -ApplyPatch 1125-rxrpc-fix-data-decrypt-vs-splice-by-copying-data-to.patch -ApplyPatch 1126-wifi-mac80211-bounds-check-link-id-in-ieee80211-ml-e.patch # END OF PATCH APPLICATIONS # Any further pre-build tree manipulations happen here. @@ -4563,44 +4511,14 @@ fi\ # # %changelog -* Wed Jul 22 2026 Andrew Lukoshko - 6.12.0-211.34.3 -- scsi: target: iscsi: Validate CHAP_R length before base64 decode (Alexandru Hossu) {CVE-2026-63886} -- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito) {CVE-2026-63887} -- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito) {CVE-2026-63888} -- USB: serial: mxuport: fix memory corruption with small endpoint (Johan Hovold) {CVE-2026-63899} -- ip6: vti: Use ip6_tnl.net in vti6_changelink() (Kuniyuki Iwashima) {CVE-2026-63917} -- ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() (Justin Iurman) {CVE-2026-63924} -- ipv6: exthdrs: refresh nh after handling HAO option (Zhengchuan Liang) {CVE-2026-63922} -- KVM: SEV: Compute the correct max length of the in-GHCB scratch area (Sean Christopherson) {CVE-2026-63939} -- USB: serial: cypress_m8: fix memory corruption with small endpoint (Johan Hovold) {CVE-2026-63956} -- tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (Eric Dumazet) {CVE-2026-63994} -- blk-mq: pop cached request if it is usable (Keith Busch) {CVE-2026-64017} -- rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg (David Howells) {CVE-2026-64026} -- wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs (Alexandru Hossu) {CVE-2026-64030} - -* Tue Jul 21 2026 Andrew Lukoshko - 6.12.0-211.34.2 -- NFSD: Fix SECINFO_NO_NAME decode error cleanup (Guannan Wang) {CVE-2026-53398} -- nfsd: release layout stid on setlease failure (Chris Mason) {CVE-2026-53399} -- KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (Ashutosh Desai) {CVE-2026-63794} -- rpmsg: char: Fix use-after-free on probe error path (Yuho Choi) {CVE-2026-63797} -- KEYS: fix overflow in keyctl_pkey_params_get_2() (Jarkko Sakkinen) {CVE-2026-63824} -- net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) {CVE-2026-63829} -- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Cole Leavitt) {CVE-2026-64037} -- vfio/pci: Check BAR resources before exporting a DMABUF (Matt Evans) {CVE-2026-64042} -- accel/qaic: Add overflow check to remap_pfn_range during mmap (Zack McKevitt) {CVE-2026-64051} -- netfs: Fix early put of sink folio in netfs_read_gaps() (David Howells) {CVE-2026-64061} -- ixgbevf: fix use-after-free in VEPA multicast source pruning (Michael Bommarito) {CVE-2026-64113} -- ipv6: ioam: refresh hdr pointer before ioam6_event() (Justin Iurman) {CVE-2026-64132} -- i2c: stub: Reject I2C block transfers with invalid length (Weiming Shi) {CVE-2026-64191} - -* Fri Jul 17 2026 Eduard Abdullin - 6.12.0-211.34.1 +* Thu Jul 23 2026 Eduard Abdullin - 6.12.0-211.37.1 - Debrand for AlmaLinux OS - Use AlmaLinux OS secure boot cert -* Fri Jul 17 2026 Neal Gompa - 6.12.0-211.34.1 +* Thu Jul 23 2026 Neal Gompa - 6.12.0-211.37.1 - Enable Btrfs support for all kernel variants -* Fri Jul 17 2026 Andrew Lukoshko - 6.12.0-211.34.1 +* Thu Jul 23 2026 Andrew Lukoshko - 6.12.0-211.37.1 - hpsa: bring back deprecated PCI ids #CFHack #CFHack2024 - mptsas: bring back deprecated PCI ids #CFHack #CFHack2024 - megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024 @@ -4610,7 +4528,75 @@ fi\ - kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained -* Mon Jul 13 2026 CKI KWF Bot [6.12.0-211.34.1.el10_2] +* Tue Jul 21 2026 CKI KWF Bot [6.12.0-211.37.1.el10_2] +- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (CKI Backport Bot) [RHEL-212681] +- fanotify: fix false positive on permission events (CKI Backport Bot) [RHEL-180076] {CVE-2026-46150} + +* Mon Jul 20 2026 CKI KWF Bot [6.12.0-211.36.1.el10_2] +- ice: fix double-free of tx_buf skb (Jakub Ramaseuski) [RHEL-191324 RHEL-192200] {CVE-2026-53009} +- ice: fix double free in ice_sf_eth_activate() error path (Jakub Ramaseuski) [RHEL-191324] {CVE-2026-46162} +- ice: update PCS latency settings for E825 10G/25Gb modes (Jakub Ramaseuski) [RHEL-191324] +- ice: fix 'adjust' timer programming for E830 devices (Jakub Ramaseuski) [RHEL-191324] +- ice: use bitmap_empty() in ice_vf_has_no_qs_ena (Jakub Ramaseuski) [RHEL-191324] +- ice: use bitmap_weighted_xor() in ice_find_free_recp_res_idx() (Jakub Ramaseuski) [RHEL-191324] +- ice: Make name member of struct ice_cgu_pin_desc const (Jakub Ramaseuski) [RHEL-191324] +- ice: fix PTP timestamping broken by SyncE code on E825C (Jakub Ramaseuski) [RHEL-191324] +- ice: ptp: don't WARN when controlling PF is unavailable (Jakub Ramaseuski) [RHEL-191324] {CVE-2026-43346} +- ice: use ice_update_eth_stats() for representor stats (Jakub Ramaseuski) [RHEL-191324] +- ice: fix inverted ready check for VF representors (Jakub Ramaseuski) [RHEL-191324] +- drivers: net: ice: fix devlink parameters get without irdma (Jakub Ramaseuski) [RHEL-191324] +- ice: fix rxq info registering in mbuf packets (Jakub Ramaseuski) [RHEL-191324] +- ice: fix retry for AQ command 0x06EE (Jakub Ramaseuski) [RHEL-191324] +- ice: reintroduce retry mechanism for indirect AQ (Jakub Ramaseuski) [RHEL-191324] +- ice: fix adding AQ LLDP filter for VF (Jakub Ramaseuski) [RHEL-191324] +- ice: recap the VSI and QoS info after rebuild (Jakub Ramaseuski) [RHEL-191324] +- ice: fix missing TX timestamps interrupts on E825 devices (Jakub Ramaseuski) [RHEL-191324] +- ice: stop counting UDP csum mismatch as rx_errors (Jakub Ramaseuski) [RHEL-191324] +- ice: reshuffle and group Rx and Tx queue fields by cachelines (Jakub Ramaseuski) [RHEL-191324] +- ice: convert all ring stats to u64_stats_t (Jakub Ramaseuski) [RHEL-191324] +- ice: shorten ring stat names and add accessors (Jakub Ramaseuski) [RHEL-191324] +- ice: use u64_stats API to access pkts/bytes in dim sample (Jakub Ramaseuski) [RHEL-191324] +- ice: remove ice_q_stats struct and use struct_group (Jakub Ramaseuski) [RHEL-191324] +- ice: pass pointer to ice_fetch_u64_stats_per_ring (Jakub Ramaseuski) [RHEL-191324] +- ice: unify PHY FW loading status handler for E800 devices (Jakub Ramaseuski) [RHEL-191324] +- ice: Fix NULL pointer dereference in ice_vsi_set_napi_queues (Jakub Ramaseuski) [RHEL-191324] {CVE-2026-23166} +- bitmap: introduce bitmap_weighted_xor() (Jakub Ramaseuski) [RHEL-191324] +- bitmap: add test_zero_nbits() (Jakub Ramaseuski) [RHEL-191324] +- bitmap: exclude nbits == 0 cases from bitmap test (Jakub Ramaseuski) [RHEL-191324] +- bitmap: test bitmap_weight() for more (Jakub Ramaseuski) [RHEL-191324] +- bitmap: add bitmap_weight_from() (Jakub Ramaseuski) [RHEL-191324] +- bitmap: align test_bitmap output (Jakub Ramaseuski) [RHEL-191324] +- bitmap: switch test to scnprintf("%%*pbl") (Jakub Ramaseuski) [RHEL-191324] +- bitmap: Add test for out-of-boundary modifications for scatter & gather (Jakub Ramaseuski) [RHEL-191324] +- cpumask: Introduce cpumask_weighted_or() (Jakub Ramaseuski) [RHEL-191324] +- bitmap: Align documentation between bitmap_gather() and bitmap_scatter() (Jakub Ramaseuski) [RHEL-191324] +- bitmap: remove _check_eq_u32_array (Jakub Ramaseuski) [RHEL-191324] +- include: update references to include/asm- (Jakub Ramaseuski) [RHEL-191324] +- KEYS: trusted: Fix a memory leak in tpm2_load_cmd (CKI Backport Bot) [RHEL-189604] {CVE-2025-71147} +- crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CKI Backport Bot) [RHEL-189576] {CVE-2025-71113} +- drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CKI Backport Bot) [RHEL-188644] {CVE-2026-52976} +- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (Sabrina Dubroca) [RHEL-180167] {CVE-2026-46116} + +* Thu Jul 16 2026 CKI KWF Bot [6.12.0-211.35.1.el10_2] +- drm/xe/dma-buf: fix UAF with retry loop (Karol Herbst) [RHEL-192232] {CVE-2026-52950} +- drm/xe/dma-buf: handle empty bo and UAF races (Karol Herbst) [RHEL-192232] +- drm/xe: Fix bo leak in xe_dma_buf_init_obj() on allocation failure (Karol Herbst) [RHEL-192232] +- drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (Karol Herbst) [RHEL-192232] +- nfsd: cancel async COPY operations when admin revokes filesystem state (Olga Kornievskaia) [RHEL-173103] +- nfsd: use correct loop termination in nfsd4_revoke_states() (Olga Kornievskaia) [RHEL-173103] +- nfsd: check that server is running in unlock_filesystem (Olga Kornievskaia) [RHEL-173103] +- drm/gem: Try to fix change_handle ioctl, attempt 4 (Jocelyn Falempe) [RHEL-179887] +- drm/gem: fix race between change_handle and handle_delete (Jocelyn Falempe) [RHEL-179887] +- drm: Replace old pointer to new idr (Jocelyn Falempe) [RHEL-179887] +- drm: Set old handle to NULL before prime swap in change_handle (Jocelyn Falempe) [RHEL-179887] {CVE-2026-46215} +- drm: Do not allow userspace to trigger kernel warnings in drm_gem_change_handle_ioctl() (Jocelyn Falempe) [RHEL-179887] +- cxl/port: Fix use after free of parent_port in cxl_detach_ep() (Myron Stowe) [RHEL-180697] {CVE-2026-31530} +- flex_proportions: make fprop_new_period() hardirq safe (CKI Backport Bot) [RHEL-189658] {CVE-2026-23168} +- Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CKI Backport Bot) [RHEL-188331] {CVE-2026-53071} +- redhat/configs: disable CONFIG_PT_RECLAIM (Luiz Capitulino) [RHEL-186311] +- libperf build: Always place libperf includes first (Michael Petlan) [RHEL-183975] + +* Tue Jul 14 2026 Jan Stancek [6.12.0-211.34.1.el10_2] - crypto: ccp - copy IV using skcipher ivsize (CKI Backport Bot) [RHEL-188463] {CVE-2026-53016} - xfs: resample the data fork mapping after cycling ILOCK (Carlos Maiolino) [RHEL-193945] - xfrm: esp: restore combined single-frag length gate (CKI Backport Bot) [RHEL-178326] diff --git a/sources b/sources index ec2ca6966..54870529b 100644 --- a/sources +++ b/sources @@ -1,12 +1,10 @@ SHA512 (fedoraimaca.x509) = e04809394f4472c17e86d7024dee34f03fb68e82a85502fd5b00535202c72e57626a8376b2cf991b7e1e46404aa5ab8d189ebf320e0dd37d49e7efbc925c7a2e -SHA512 (kernel-abi-stablelists-6.12.0-211.34.1.el10_2.tar.xz) = 3866e09c54c7fda99741913617c9000b11d1e1555d584d3a72cf021d02fc81e89e1fd1cfbdd91d2ad1648da9d8fd07ab17d352a726f650eb2195f7cdcc5f3962 -SHA512 (kernel-kabi-dw-6.12.0-211.34.1.el10_2.tar.xz) = 7f89e69f121aa3cad12a639cda10c7ac19ba4e65882da631481ce36684048d22e97b1be80ad96bde03467223093977abc293232c134d50023a3ee8ee9aeb2aec -SHA512 (linux-6.12.0-211.34.1.el10_2.tar.xz) = 19fef0fe35ef9e377e9b8673cd3e5faacd4936d7c2b0acec38f2a06e6d9d3164199c49f85b161b9dc41776440e02a0fd4e7bec8fc70e7088d1b699ccea86ca4e +SHA512 (kernel-abi-stablelists-6.12.0-211.37.1.el10_2.tar.xz) = 5517b9dcf4db6381f0d576a6160e1bd9b1c4d4c314fd432b15497c8b75ef370b6a8e973912b81f3164c8951d65e89f0ec3b8fc1e5e32fdf399ede683968bcd5b +SHA512 (kernel-kabi-dw-6.12.0-211.37.1.el10_2.tar.xz) = 57aaae94c0eb6ea3a675becaa3eb8a7ec80873ac8b98a6ce2713e2d13e33a4b2b641e93411da06b3b7e2ae9249dc506a64a2796baa37013542a7a7ed97610078 +SHA512 (linux-6.12.0-211.37.1.el10_2.tar.xz) = 93c3524ed4c49c814f58aca7ea6bc72f94fd523083c6afc0671caea64817ecb82ed6688866d851cccc98e495cd3b566c4de5baed7e2e5067036ab01cefabf3ec SHA512 (nvidiabfdpu.x509) = d9f4fbafcec66803c5944df1f97d4348968141c968e6537252c9854c89dca8ea3be225a9c40abbbf2b7d4d3cfd8c5012cd2d34d90443fbc0277b7a018622ac4f SHA512 (nvidiagpuoot001.x509) = b42f836e1cfa07890cb6ca13de9c3950e306c9ec7686c4c09f050bb68869f5d82962b2cd5f3aa0eb7a0f3a3ae54e9c480eafbac5df53aa92c295ff511a8c59fe SHA512 (nvidiajetsonsoc.x509) = 3c6d4f0800b3fae3c3cc3e5361de31df233e230ea96f0fdd3dcc713e6a71e27309f60e7a98d1a4a90d470f336ce311f22fcc88f219429272e96339717fe001dd -SHA512 (olima1.x509) = 123c26c1d698cc8523845c6e1103b9c72abf855acd225d37baf1f3388a47f912166d6d786fb367fe46de39e011b586ad7f3963aa2e8923da30a6ea9ae0d76ad3 -SHA512 (olimaca1.x509) = 3a779415fad29d6f7250ec97ab1f0a5eb62c351b724feee06b22e17f065bf74a558f32cc524d3222c4485635ae5b9cd5287855c94010fe743b51a4d954340c4c SHA512 (redhatsecureboot501.cer) = eb2c2d342680d4c3453d3e4f30abdd1f6b0e98292e1be0410d0163afd01552a863b70ffaabeecd6e3981cd4d167198091a837c7d70f96a3a06de2d28b3355308 SHA512 (redhatsecurebootca5.cer) = 0285fd7cb1755b399cdd2d848d9eba51b72ef2dd8ea5d40d7061c29685a12e15bf8eb083cb2f8c14eb69d248cb3af2c2332e06f80e19ed4cc029070198c0d522 SHA512 (rheldup3.x509) = ebf56d821acb5c17bb1842a8ddc8f1014a9e112ef7569531eedbabc82c6b5740e2709f96c5ebc87ba837e8085d0b090a9e63ddd06507692b41dae54a2b48d21b