* Fri Aug 21 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-263.el10]
- mm: consider non-anon swap cache folios in folio_expected_ref_count() (Gavin Shan) [RHEL-224504]
- dm cache policy smq: check allocation under invalidate lock (Benjamin Marzinski) [RHEL-231823] {CVE-2026-53062}
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Ricardo Robaina) [RHEL-226716] {CVE-2026-43493}
- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CKI Backport Bot) [RHEL-231458] {CVE-2026-64277}
- iommu/vt-d: Avoid WARNING in sva unbind path (Jerry Snitselaar) [RHEL-213791]
- iommufd/selftest: Add invalidation entry_num and entry_len boundary tests (Jerry Snitselaar) [RHEL-213791]
- iommufd/selftest: Cover invalid read counts on vEVENTQ FD (Jerry Snitselaar) [RHEL-213791]
- iommufd/selftest: Add boundary tests for veventq_depth (Jerry Snitselaar) [RHEL-213791]
- iommufd: Set upper bounds on cache invalidation entry_num and entry_len (Jerry Snitselaar) [RHEL-213791]
- iommufd: Clarify IOAS_MAP_FILE dma-buf support (Jerry Snitselaar) [RHEL-213791]
- iommufd: Destroy the pages content after detaching from dmabuf (Jerry Snitselaar) [RHEL-213791]
- iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read() (Jerry Snitselaar) [RHEL-213791]
- iommufd: Break the loop on failure in iommufd_fault_fops_read() (Jerry Snitselaar) [RHEL-213791]
- iommufd: Reject invalid read count in iommufd_fault_fops_read() (Jerry Snitselaar) [RHEL-213791]
- iommufd: Propagate allocation failure in iommufd_veventq_deliver_fetch() (Jerry Snitselaar) [RHEL-213791]
- iommufd: Reject invalid read count in iommufd_veventq_fops_read() (Jerry Snitselaar) [RHEL-213791]
- iommufd: Rewind header length in done if iommufd_veventq_fops_read() fails (Jerry Snitselaar) [RHEL-213791]
- iommufd: Set veventq_depth upper bound (Jerry Snitselaar) [RHEL-213791]
- iommufd: Move vevent memory allocation outside spinlock (Jerry Snitselaar) [RHEL-213791]
- iommupt: Fix the end_index calculation in __map_range_leaf() (Jerry Snitselaar) [RHEL-213791]
- iommu: Handle unmap error when iommu_debug is enabled (Jerry Snitselaar) [RHEL-213791] {CVE-2026-64152}
- iommu: Fix up map/unmap debugging for iommupt domains (Jerry Snitselaar) [RHEL-213791]
- iommu: Fix loss of errno on map failure for classic ops (Jerry Snitselaar) [RHEL-213791]
- iommu: Ensure .iotlb_sync is called correctly (Jerry Snitselaar) [RHEL-213791]
- iommu: Do not call drivers for empty gathers (Jerry Snitselaar) [RHEL-213791]
- iommupt: Check for missing PAGE_SIZE in the pgsize_bitmap (Jerry Snitselaar) [RHEL-213791] {CVE-2026-64151}
- iommu/vt-d: Restore IOMMU_CAP_CACHE_COHERENCY (Jerry Snitselaar) [RHEL-213791]
- iommu/dma: Always allow DMA-FQ when iommupt provides the iommu_domain (Jerry Snitselaar) [RHEL-213791]
- iommupt: Avoid rewalking during map (Jerry Snitselaar) [RHEL-213791]
- iommupt: Directly call iommupt's unmap_range() (Jerry Snitselaar) [RHEL-213791]
- iommu/iova: Add NULL check in iova_magazine_free() (Jerry Snitselaar) [RHEL-213791]
- iommupt: Optimize the gather processing for DMA-FQ mode (Jerry Snitselaar) [RHEL-213791]
- iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs (Jerry Snitselaar) [RHEL-213791] {CVE-2026-64186}
- iommu/amd: Fix illegal cap/mmio access in IOMMU debugfs (Jerry Snitselaar) [RHEL-213791]
- iommu/amd: Fix illegal device-id access in IOMMU debugfs (Jerry Snitselaar) [RHEL-213791]
- of: reserved_mem: Allow reserved_mem framework detect "cma=" kernel param (Jerry Snitselaar) [RHEL-213791]
- iommu: Avoid copying the user array twice in the full-array copy helper (Jerry Snitselaar) [RHEL-213791]
- iommu/dma: Do not try to iommu_map a 0 length region in swiotlb (Jerry Snitselaar) [RHEL-213791] {CVE-2026-53164}
- iommu/vt-d: Fix RB-tree corruption in probe error path (Jerry Snitselaar) [RHEL-213791]
- iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry (Jerry Snitselaar) [RHEL-213791]
- iommu/amd: Don't split flush for amd_iommu_domain_flush_all() (Jerry Snitselaar) [RHEL-213791]
- iommufd: Fix data_len byte-count vs element-count mismatch (Jerry Snitselaar) [RHEL-213791]
- drm/tegra: Fix iommu_map_sgtable() return value check (Jerry Snitselaar) [RHEL-213791]
- gpu: host1x: Fix iommu_map_sgtable() return value check (Jerry Snitselaar) [RHEL-213791]
- iommu/amd: Fix premature break in init_iommu_one() (Jerry Snitselaar) [RHEL-213791]
- iommu/arm-smmu-qcom: Fix fastrpc compatible string in ACTLR client match table (Jerry Snitselaar) [RHEL-213791]
- iommu/vt-d: Disable DMAR for Intel Q35 IGFX (Jerry Snitselaar) [RHEL-213791]
- iommu/amd: Bounds-check devid in __rlookup_amd_iommu() (Jerry Snitselaar) [RHEL-213791] {CVE-2026-53283}
- iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read (Jerry Snitselaar) [RHEL-213791]
- dma: contiguous: Check return value of dma_contiguous_reserve_area() (Jerry Snitselaar) [RHEL-213791]
- iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path (Jerry Snitselaar) [RHEL-213791]
- dma-debug: fix physical address retrieval in debug_dma_sync_sg_for_device (Jerry Snitselaar) [RHEL-213791]
- dma-mapping: direct: fix missing mapping for THRU_HOST_BRIDGE segments (Jerry Snitselaar) [RHEL-213791]
- dma-mapping: move dma_map_resource() sanity check into debug code (Jerry Snitselaar) [RHEL-213791] {CVE-2026-64149}
- iommu/amd: Fix precedence order in set_dte_passthrough() (Jerry Snitselaar) [RHEL-213791]
- iommu/pages: Fix iommu_pages_flush_incoherent() for non-x86 (Jerry Snitselaar) [RHEL-213791]
- iommufd: Fix a race with concurrent allocation and unmap (Jerry Snitselaar) [RHEL-213791]
- iommu/amd: Fix clone_alias() to use the original device's devid (Jerry Snitselaar) [RHEL-213791] {CVE-2026-53053}
- iommu/vt-d: Block PASID attachment to nested domain with dirty tracking (Jerry Snitselaar) [RHEL-213791] {CVE-2026-53372}
- iommufd: Fix return value of iommufd_fault_fops_write() (Jerry Snitselaar) [RHEL-213791]
- dma-mapping: add missing `inline` for `dma_free_attrs` (Jerry Snitselaar) [RHEL-213791]
- iommu/amd: Block identity domain when SNP enabled (Jerry Snitselaar) [RHEL-213791]
- iommu/vt-d: Only handle IOPF for SVA when PRI is supported (Jerry Snitselaar) [RHEL-213791]
- iommu/vt-d: Fix intel iommu iotlb sync hardlockup and retry (Jerry Snitselaar) [RHEL-213791]
- iommufd/selftest: Fix page leaks in mock_viommu_{init,destroy} (Jerry Snitselaar) [RHEL-213791]
- iommufd: vfio compatibility extension check for noiommu mode (Jerry Snitselaar) [RHEL-213791]
- dma-mapping: benchmark: Restore padding to ensure uABI remained consistent (Jerry Snitselaar) [RHEL-213791]
- x86/sev: Fix broken SNP support with KVM module built-in (Jerry Snitselaar) [RHEL-213791]
- lib: scatterlist: fix sg_split_phys to preserve original scatterlist offsets (Jerry Snitselaar) [RHEL-213791]
- scatterlist: fix incorrect func name in kernel-doc (Jerry Snitselaar) [RHEL-213791]
- powerpc/pseries/iommu: Fix kmemleak in TCE table userspace view (Jerry Snitselaar) [RHEL-213791]
- seccomp: passthrough uretprobe systemcall without filtering (Ricardo Robaina) [RHEL-210962] {CVE-2025-21834}
- perf/x86/intel: Enable auto counter reload for DMR (Michael Petlan) [RHEL-115120]
- perf/x86/intel: Disable PMI for self-reloaded ACR events (Michael Petlan) [RHEL-115120]
- perf/x86/intel: Always reprogram ACR events to prevent stale masks (Michael Petlan) [RHEL-115120]
- perf/x86/intel: Improve validation and configuration of ACR masks (Michael Petlan) [RHEL-115120]
- perf/x86/intel: Fix OMR snoop information parsing issues (Michael Petlan) [RHEL-117335]
- perf/x86/intel/uncore: Remove extra double quote mark (Michael Petlan) [RHEL-115124]
- perf/x86/intel/uncore: Fix die ID init and look up bugs (Michael Petlan) [RHEL-115124] {CVE-2026-43079}
- perf/x86/intel/uncore: Skip discovery table for offline dies (Michael Petlan) [RHEL-115124] {CVE-2026-43344}
- perf/x86/intel/uncore: Fix iounmap() leak on global_init failure (Michael Petlan) [RHEL-115124]
- perf/x86/intel: Add support for rdpmc user disable feature (Michael Petlan) [RHEL-117335]
- perf/x86: Use macros to replace magic numbers in attr_rdpmc (Michael Petlan) [RHEL-117335]
- perf/x86/intel: Add core PMU support for Novalake (Michael Petlan) [RHEL-117335]
- perf/x86/intel: Add support for PEBS memory auxiliary info field in NVL (Michael Petlan) [RHEL-117335]
- perf/x86/intel: Add core PMU support for DMR (Michael Petlan) [RHEL-115120]
- perf/x86/intel: Add support for PEBS memory auxiliary info field in DMR (Michael Petlan) [RHEL-115120]
- perf/x86/intel: Support the 4 new OMR MSRs introduced in DMR and NVL (Michael Petlan) [RHEL-115120 RHEL-117335]
- perf/x86/intel/uncore: Convert comma to semicolon (Michael Petlan) [RHEL-117337]
- perf/x86/intel/uncore: Add Nova Lake support (Michael Petlan) [RHEL-117337]
- perf/x86/intel/uncore: Add missing PMON units for Panther Lake (Michael Petlan) [RHEL-117337]
- perf pmu: Relax uncore wildcard matching to allow numeric suffix (Michael Petlan) [RHEL-115124]
- perf/x86/intel/uncore: Update DMR uncore constraints preliminarily (Michael Petlan) [RHEL-115124]
- perf/x86/intel/uncore: Support uncore constraint ranges (Michael Petlan) [RHEL-115124]
- perf/x86/intel/uncore: Support IIO free-running counters on DMR (Michael Petlan) [RHEL-115124]
- perf/x86/intel/uncore: Add freerunning event descriptor helper macro (Michael Petlan) [RHEL-115124]
- perf/x86/intel/uncore: Add domain global init callback (Michael Petlan) [RHEL-115124]
- perf/x86/intel/uncore: Add CBB PMON support for Diamond Rapids (Michael Petlan) [RHEL-115124]
- perf/x86/intel/uncore: Add IMH PMON support for Diamond Rapids (Michael Petlan) [RHEL-115124]
- perf/x86/intel/uncore: Remove has_generic_discovery_table() (Michael Petlan) [RHEL-115124]
- perf/x86/intel/uncore: Support per-platform discovery base devices (Michael Petlan) [RHEL-115124]
- perf/x86/intel/uncore: Move uncore discovery init struct to header (Michael Petlan) [RHEL-115124]
- perf/x86/intel/cstate: Add Diamond Rapids support (Michael Petlan) [RHEL-115122]
- perf/x86/intel/cstate: Add Nova Lake support (Michael Petlan) [RHEL-120357]
- perf/x86/intel/cstate: Add Wildcat Lake support (Michael Petlan) [RHEL-95668]
- ipc: limit next_id allocation to the valid ID range (Rafael Aquini) [RHEL-188220] {CVE-2026-52923}
- KVM: arm64: account pKVM reclaim against the VM mm (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Set IL in fake ESR for pKVM memory sharing exit (Sebastian Ott) [RHEL-180320]
- KVM: arm64: ptdump: Initialize parser_state before pgtable walk (Sebastian Ott) [RHEL-180320]
- KVM: arm64: nv: Expose shadow page tables in debugfs (Sebastian Ott) [RHEL-180320]
- KVM: arm64: ptdump: Make KVM ptdump code s2 mmu aware (Sebastian Ott) [RHEL-180320]
- Revert "KVM: arm64: Restore S1PIE register visibility to userspace" (Sebastian Ott) [RHEL-180320]
- Revert "KVM: arm64: Restore TCR2_EL1 register visibility to userspace" (Sebastian Ott) [RHEL-180320]
- KVM: selftests: Add test for KVM_REG_ARM_VENDOR_HYP_BMAP_2 (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Introduce KVM_REG_ARM_VENDOR_HYP_BMAP_2 (Sebastian Ott) [RHEL-180320]
- drivers/virt: pkvm: Add Kconfig dependency on DMA_RESTRICTED_POOL (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Rename PKVM_PAGE_STATE_MASK (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Extend pKVM page ownership selftests to cover guest hvcs (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Extend pKVM page ownership selftests to cover forced reclaim (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Register 'selftest_vm' in the VM table (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Extend pKVM page ownership selftests to cover guest donation (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Add some initial documentation for pKVM (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Allow userspace to create protected VMs when pKVM is enabled (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Implement the MEM_UNSHARE hypercall for protected VMs (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Implement the MEM_SHARE hypercall for protected VMs (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Add hvc handler at EL2 for hypercalls from protected VMs (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Return -EFAULT from VCPU_RUN on access to a poisoned pte (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Reclaim faulting page from pKVM in spurious fault handler (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Introduce hypercall to force reclaim of a protected page (Sebastian Ott) [RHEL-180320]
- KVM: arm64: nv: Fully update VNCR fixmap state in kvm_translate_vncr() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: nv: Inject SEA TTW when desc update can't write to GPA (Sebastian Ott) [RHEL-180320]
- KVM: arm64: nv: Restart stage-1 walk if stage-2 desc update fails (Sebastian Ott) [RHEL-180320]
- KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (Sebastian Ott) [RHEL-180320]
- KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Don't pass host_debug_state to BRBE world-switch routines (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Pre-check vcpu memcache for host->guest donate (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Pre-check vcpu memcache for host->guest share (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Make EL2 exception entry and exit context-synchronization events (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Annotate guest donations with handle and gfn in host stage-2 (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Change 'pkvm_handle_t' to u16 (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Introduce host_stage2_set_owner_metadata_locked() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Generalise kvm_pgtable_stage2_set_owner() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Avoid pointless annotation when mapping host-owned pages (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Inject SIGSEGV on illegal accesses (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Support translation faults in inject_host_exception() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Factor out pKVM host exception injection logic (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Hook up reclaim hypercall to pkvm_pgtable_stage2_destroy() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Introduce __pkvm_reclaim_dying_guest_page() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Don't advertise unsupported features for protected guests (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Fix block mapping validity check in stage-1 walker (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Roll back partial shares on kvm_share_hyp() failure (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Avoid host/hyp share desync on unshare hypercall failure (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Free hyp-share tracking node when share hypercall fails (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Flush HCR_EL2.VSE to deliver SErrors to pKVM guests (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Correctly identify executable PTEs at stage-2 (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Reassign nested_mmus array behind mmu_lock (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Restore POR_EL0 access to host EL0 (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Restart instruction upon race in __kvm_at_s12() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Wire AT S1E1A in the system instruction handling table (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Key CPTR_EL2.E0POE propagation on FEAT_S1POE (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor (Sebastian Ott) [RHEL-180320]
- KVM: arm64: PMU: Preserve AArch32 counter low bits (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Fix __pkvm_init_vm error path (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Reset page order in pKVM hyp_pool (Sebastian Ott) [RHEL-180320]
- KVM: arm64: vgic: Free private_irqs when init fails after allocation (Sebastian Ott) [RHEL-180320]
- KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Fix __deactivate_fgt macro parameter typo (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Handle permission faults with guest_memfd (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Handle aborts from protected VMs (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Introduce __pkvm_host_donate_guest() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Remove unused PKVM_ID_FFA definition (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Remove is_protected_kvm_enabled() checks from hypercalls (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Expose self-hosted debug regs as RAZ/WI for protected guests (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Hook up donation hypercall to pkvm_pgtable_stage2_map() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Split teardown hypercall into two phases (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Rename __pkvm_pgtable_stage2_unmap() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Move handle check into pkvm_pgtable_stage2_destroy_range() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Ignore -EAGAIN when mapping in pages for the pKVM host (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Prevent unsupported memslot operations on protected VMs (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Ignore MMU notifier callbacks for protected VMs (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Convert gmem_abort() to struct kvm_s2_fault_desc (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Simplify integration of adjust_nested_*_perms() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Directly expose mapping prot and kill kvm_s2_fault (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Move device mapping management into kvm_s2_fault_pin_pfn() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Replace force_pte with a max_map_size attribute (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Move kvm_s2_fault.{pfn,page} to kvm_s2_vma_info (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Restrict the scope of the 'writable' attribute (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Kill logging_active from kvm_s2_fault (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Move VMA-related information to kvm_s2_fault_vma_info (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Kill topup_memcache from kvm_s2_fault (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Kill exec_fault from kvm_s2_fault (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Kill write_fault from kvm_s2_fault (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Constrain fault_granule to kvm_s2_fault_map() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Replace fault_is_perm with a helper (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Move fault context to const structure (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Make fault_ipa immutable (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Kill fault->ipa (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Clean up control flow in kvm_s2_fault_map() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Hoist MTE validation check out of MMU lock path (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Optimize early exit checks in kvm_s2_fault_pin_pfn() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Initialize struct kvm_s2_fault completely at declaration (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Simplify return logic in user_mem_abort() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Remove redundant state variables from struct kvm_s2_fault (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Simplify nested VMA shift calculation (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Extract page table mapping in user_mem_abort() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Extract stage-2 permission logic in user_mem_abort() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Isolate mmap_read_lock inside new kvm_s2_fault_get_vma_info() helper (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Extract PFN resolution in user_mem_abort() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Introduce struct kvm_s2_fault to user_mem_abort() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Extract VMA size resolution in user_mem_abort() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Wake-up from WFI when iqrchip is in userspace (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Fix initialisation order in __pkvm_init_finalise() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu() (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Fix kvm_vcpu_initialized() macro parameter (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Fix FEAT_SPE_FnE to use PMSIDR_EL1.FnE, not PMSVer (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Fix typo in feature check comments (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Fix FEAT_Debugv8p9 to check DebugVer, not PMUVer (Sebastian Ott) [RHEL-180320]
- KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Don't leak stage-2 page-table if VM fails to init under pKVM (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Disable SPE Profiling Buffer when running in guest context (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Disable TRBE Trace Buffer Unit when running in guest context (Sebastian Ott) [RHEL-180320]
- KVM: arm64: Read PMUVer as unsigned (Sebastian Ott) [RHEL-180320]
- arm64: cpufeature: Use pmuv3_implemented() function (Sebastian Ott) [RHEL-180320]
- arm64: cpufeature: Make PMUVer and PerfMon unsigned (Sebastian Ott) [RHEL-180320]
- selftests/cgroup: include slab in test_percpu_basic memory check (Waiman Long) [RHEL-154159]
- selftests/cgroup: fix hardcoded page size in test_percpu_basic (Waiman Long) [RHEL-154159]
- selftests/cgroup: test_zswap: wait for asynchronous writeback (Waiman Long) [RHEL-154157]
- selftest/cgroup: fix zswap attempt_writeback() on 64K pagesize system (Waiman Long) [RHEL-154157]
- selftest/cgroup: fix zswap test_no_invasive_cgroup_shrink on large pagesize system (Waiman Long) [RHEL-154157]
- selftests/cgroup: replace hardcoded page size values in test_zswap (Waiman Long) [RHEL-154157]
- selftests/cgroup: rename PAGE_SIZE to BUF_SIZE in cgroup_util (Waiman Long) [RHEL-154157]
- selftests/cgroup: use runtime page size for zswpin check (Waiman Long) [RHEL-154157]
- selftests/cgroup: avoid OOM in test_swapin_nozswap (Waiman Long) [RHEL-154157]
- selftests/cgroup: skip test_zswap if zswap is globally disabled (Waiman Long) [RHEL-154157]
- selftests/cgroup: Fix error path leaks in test_percpu_basic (Waiman Long) [RHEL-184801]
- selftests/cgroup: Fix string comparison in write_test (Waiman Long) [RHEL-184801]
- selftests/cgroup: Fix cg_read_strcmp() empty string comparison (Waiman Long) [RHEL-184801]
- selftest: memcg: skip memcg_sock test if address family not supported (Waiman Long) [RHEL-184801]
- selftests: cgroup: make test_memcg_sock robust against delayed sock stats (Waiman Long) [RHEL-184801]
- selftests: cgroup: Add cg_read_key_long_poll() to poll a cgroup key with retries (Waiman Long) [RHEL-184801]
- selftests: complete kselftest include centralization (Waiman Long) [RHEL-184801]
- selftests/cgroup: conform test to KTAP format output (Waiman Long) [RHEL-184801]
- selftests: memcg: increase error tolerance of child memory.current check in test_memcg_protection() (Waiman Long) [RHEL-184801]
- selftests: memcg: allow low event with no memory.low and memory_recursiveprot on (Waiman Long) [RHEL-184801]
- selftests/cgroup: use bash in test_cpuset_v1_hp.sh (Waiman Long) [RHEL-184801]
- ipv6: Fix out-of-bound access in fib6_add_rt2node(). (Antoine Tenart) [RHEL-152712]
- ipv6: mcast: Fix use-after-free when processing MLD queries (Antoine Tenart) [RHEL-152712]
- ipv6: anycast: insert aca into global hash under idev->lock (Antoine Tenart) [RHEL-152712]
- ipv6: fix possible infinite loop in fib6_select_path() (Antoine Tenart) [RHEL-152712]
- ipv6: fix possible infinite loop in rt6_fill_node() (Antoine Tenart) [RHEL-152712]
- ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (Antoine Tenart) [RHEL-152712]
- ipv6: validate extension header length before copying to cmsg (Antoine Tenart) [RHEL-152712]
- ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() (Antoine Tenart) [RHEL-152712]
- ipv6: exthdrs: refresh nh after handling HAO option (Antoine Tenart) [RHEL-152712]
- ipv6: ioam: refresh hdr pointer before ioam6_event() (Antoine Tenart) [RHEL-152712]
- ipv6: route: Unregister netdevice notifier on BPF init failure (Antoine Tenart) [RHEL-152712]
- ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() (Antoine Tenart) [RHEL-152712]
- ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD (Antoine Tenart) [RHEL-152712]
- ipv6: fix potential UAF caused by ip6_forward_proxy_check() (Antoine Tenart) [RHEL-152712]
- ipv6: Fix null-ptr-deref in fib6_mtu(). (Antoine Tenart) [RHEL-152712]
- ipv6: update route serial number on NETDEV_CHANGE (Antoine Tenart) [RHEL-152712]
- ipv6: Implement limits on extension header parsing (Antoine Tenart) [RHEL-152712]
- ipv6: fix possible UAF in icmpv6_rcv() (Antoine Tenart) [RHEL-152712]
- net: ioam6: fix OOB and missing lock (Antoine Tenart) [RHEL-152712]
- ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (Antoine Tenart) [RHEL-152712]
- ipv6: avoid overflows in ip6_datagram_send_ctl() (Antoine Tenart) [RHEL-152712]
- ipv6: fix data race in fib6_metric_set() using cmpxchg (Antoine Tenart) [RHEL-152712]
- net: ipv6: flowlabel: defer exclusive option free until RCU teardown (Antoine Tenart) [RHEL-152712]
- ipv6: prevent possible UaF in addrconf_permanent_addr() (Antoine Tenart) [RHEL-152712]
- net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (Antoine Tenart) [RHEL-152712]
- net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop (Antoine Tenart) [RHEL-152712]
- ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu() (Antoine Tenart) [RHEL-152712]
- ipv6: fix a race in ip6_sock_set_v6only() (Antoine Tenart) [RHEL-152712]
- ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() (Antoine Tenart) [RHEL-152712] {CVE-2026-43186}
- ipv6: Fix ECMP sibling count mismatch when clearing RTF_ADDRCONF (Antoine Tenart) [RHEL-152712]
- ipv6: use the right ifindex when replying to icmpv6 from localhost (Antoine Tenart) [RHEL-152712]
- ipv6: annotate data-race in ndisc_router_discovery() (Antoine Tenart) [RHEL-152712]
- net: ipv6: ip6mr: Fix in/out netdev to pass to the FORWARD chain (Antoine Tenart) [RHEL-152712]
Resolves: RHEL-115120, RHEL-115122, RHEL-115124, RHEL-117335, RHEL-117337, RHEL-120357, RHEL-152712, RHEL-154157, RHEL-154159, RHEL-180320, RHEL-184801, RHEL-188220, RHEL-210962, RHEL-213791, RHEL-224504, RHEL-226716, RHEL-231458, RHEL-231823, RHEL-95668
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
45 lines
1.1 KiB
Makefile
45 lines
1.1 KiB
Makefile
RHEL_MAJOR = 10
|
|
RHEL_MINOR = 3
|
|
|
|
#
|
|
# RHEL_RELEASE
|
|
# -------------
|
|
#
|
|
# Represents build number in 'release' part of RPM's name-version-release.
|
|
# name is <package_name>, e.g. kernel
|
|
# version is upstream kernel version this kernel is based on, e.g. 4.18.0
|
|
# release is <RHEL_RELEASE>.<dist_tag>[<buildid>], e.g. 100.el8
|
|
#
|
|
# Use this spot to avoid future merge conflicts.
|
|
# Do not trim this comment.
|
|
RHEL_RELEASE = 263
|
|
|
|
#
|
|
# RHEL_REBASE_NUM
|
|
# ----------------
|
|
#
|
|
# Used in RPM version string for Gemini kernels, which dont use upstream
|
|
# VERSION/PATCHLEVEL/SUBLEVEL. The number represents rebase number for
|
|
# current MAJOR release.
|
|
#
|
|
# Use this spot to avoid future merge conflicts.
|
|
# Do not trim this comment.
|
|
RHEL_REBASE_NUM = 1
|
|
|
|
#
|
|
# Automotive
|
|
# ----------
|
|
#
|
|
# Represents the major and minor release used by automotive.
|
|
# Primarily this is used to to identify the build target when
|
|
# building the automotive kernel package.
|
|
AUTOMOTIVE_MAJOR = 2
|
|
AUTOMOTIVE_MINOR = 1
|
|
|
|
#
|
|
# DERIVATIVE_BUILD
|
|
# ---------------------------
|
|
#
|
|
# Set DERIVATIVE_STREAM to "yes" to enable derivative kernel versioning.
|
|
DERIVATIVE_BUILD = 0
|