Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
135 commits
Select commit Hold shift + click to select a range
f627035
gfs2: Don't get stuck writing page onto itself under direct I/O
PlaidCat Sep 15, 2026
0d5ca01
gfs2: fiemap page fault fix
PlaidCat Sep 15, 2026
37ffa55
gfs2: Remove redundant check for GLF_INSTANTIATE_NEEDED
PlaidCat Sep 15, 2026
1726a7b
gfs2: Don't remember delete unless it's successful
PlaidCat Sep 15, 2026
5c03599
gfs2: Call unlock_new_inode before d_instantiate
PlaidCat Sep 15, 2026
be64176
gfs2: Remove unnecessary check in gfs2_evict_inode
PlaidCat Sep 15, 2026
5a3e960
gfs2: Avoid unnecessary transactions in evict_linked_inode
PlaidCat Sep 15, 2026
6b90ebe
gfs2: minor evict_[un]linked_inode cleanup
PlaidCat Sep 15, 2026
5eac771
gfs2: Fix data loss during inode evict
PlaidCat Sep 15, 2026
8ea3d35
rtnetlink: Add peer_type in struct rtnl_link_ops.
PlaidCat Sep 15, 2026
82e70bd
veth: Set VETH_INFO_PEER to veth_link_ops.peer_type.
PlaidCat Sep 15, 2026
b269a49
vxcan: Set VXCAN_INFO_PEER to vxcan_link_ops.peer_type.
PlaidCat Sep 15, 2026
cbfa7c1
rtnetlink: fix double call of rtnl_link_get_net_ifla()
PlaidCat Sep 15, 2026
0f67763
rtnetlink: Try the outer netns attribute in rtnl_get_peer_net().
PlaidCat Sep 15, 2026
3da6a01
rtnetlink: add missing netlink_ns_capable() check for peer netns
PlaidCat Sep 15, 2026
fc3ec22
rtla/timerlat: Exit top main loop on any non-zero wait_retval
PlaidCat Sep 15, 2026
6a94dd8
net: account for encap headers in qdisc pkt len
PlaidCat Sep 15, 2026
5003c66
net_sched: make room for (struct qdisc_skb_cb)->pkt_segs
PlaidCat Sep 15, 2026
c447e09
net: init shinfo->gso_segs from qdisc_pkt_len_init()
PlaidCat Sep 15, 2026
0cb929f
net_sched: initialize qdisc_skb_cb(skb)->pkt_segs in qdisc_pkt_len_in…
PlaidCat Sep 15, 2026
70d2fc3
net: qdisc_pkt_len_segs_init() cleanup
PlaidCat Sep 15, 2026
ac04701
net: pull headers in qdisc_pkt_len_segs_init()
PlaidCat Sep 15, 2026
f3061d5
xfrm: Don't clobber inner headers when already set
PlaidCat Sep 15, 2026
52fc70a
Bluetooth: serialize accept_q access
PlaidCat Sep 15, 2026
474fb71
Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
PlaidCat Sep 15, 2026
4ccdb5a
Bluetooth: RFCOMM: validate skb length in MCC handlers
PlaidCat Sep 15, 2026
0ff6d36
Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock
PlaidCat Sep 15, 2026
3f89a5b
iommu/amd: Fix clone_alias() to use the original device's devid
PlaidCat Sep 15, 2026
191116e
Bluetooth: SMP: force responder MITM requirements before building the…
PlaidCat Sep 15, 2026
89c7936
ixgbevf: fix use-after-free in VEPA multicast source pruning
PlaidCat Sep 15, 2026
0f3b302
Bluetooth: ISO: fix UAF in iso_recv_frame
PlaidCat Sep 15, 2026
02fe09f
scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32
PlaidCat Sep 15, 2026
2f7a132
Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
PlaidCat Sep 15, 2026
ead6960
Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync
PlaidCat Sep 15, 2026
f4b2d76
Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
PlaidCat Sep 15, 2026
4e1bdd6
Bluetooth: HIDP: fix missing length checks in hidp_input_report()
PlaidCat Sep 15, 2026
83a08a6
Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
PlaidCat Sep 15, 2026
78dd34b
wifi: mac80211: fix MLE defragmentation
PlaidCat Sep 15, 2026
4232a66
wifi: mac80211: fix multi-link element inheritance
PlaidCat Sep 15, 2026
671a24e
net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
PlaidCat Sep 15, 2026
9b15119
wifi: nl80211: reject oversized EMA RNR lists
PlaidCat Sep 15, 2026
71bb034
wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disa…
PlaidCat Sep 15, 2026
4af8fe3
wifi: mac80211: fix missing RX bitrate update for mesh forwarding path
PlaidCat Sep 15, 2026
7f03c41
wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb
PlaidCat Sep 15, 2026
63a0e21
wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session hand…
PlaidCat Sep 15, 2026
e691cbe
sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
PlaidCat Sep 15, 2026
4cc8f21
sctp: validate embedded INIT chunk and address list lengths in cookie
PlaidCat Sep 15, 2026
7dbcf58
scsi: qla2xxx: Clear cmds after chip reset
PlaidCat Sep 15, 2026
b2078f7
netfilter: nfnetlink_queue: nfqnl_instance GFP_ATOMIC -> GFP_KERNEL_A…
PlaidCat Sep 15, 2026
e84e996
netfilter: nfnetlink_queue: optimize verdict lookup with hash table
PlaidCat Sep 15, 2026
e398055
netfilter: nfnetlink_queue: make hash table per queue
PlaidCat Sep 15, 2026
bf547a9
selftests: netfilter: nft_queue.sh: reduce test file size for debug b…
PlaidCat Sep 15, 2026
3e987c2
selftests: netfilter: nft_queue.sh: fix spurious timeout on debug kernel
PlaidCat Sep 15, 2026
c43a4e3
selftests: netfilter: nft_queue.sh: avoid flakes on debug kernels
PlaidCat Sep 15, 2026
7361071
kselftest: add test for nfqueue induced conntrack race
PlaidCat Sep 15, 2026
14dd503
selftests: nft_queue.sh: add a parallel stress test
PlaidCat Sep 15, 2026
ab36fa7
sctp: diag: reject stale associations in dump_one path
PlaidCat Sep 15, 2026
4f6f621
sctp: fix race between sctp_wait_for_connect and peeloff
PlaidCat Sep 15, 2026
6a3e747
drm/xe: Open-code GGTT MMIO access protection
PlaidCat Sep 15, 2026
6c91be6
drm/xe: Issue GGTT invalidation under lock in ggtt_node_remove
PlaidCat Sep 15, 2026
eff36e6
drm/xe: always keep track of remap prev/next
PlaidCat Sep 15, 2026
6f12922
drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib
PlaidCat Sep 15, 2026
4e7f6dc
drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat
PlaidCat Sep 15, 2026
8c32679
drm/i915: Fix potential overflow of shmem scatterlist length
PlaidCat Sep 15, 2026
95540a9
drm/amdgpu: Fix use-after-free race in VM acquire
PlaidCat Sep 15, 2026
328c63b
Rebuild rocky9_8 with kernel-5.14.0-687.47.1.el9_8
PlaidCat Sep 15, 2026
20f31f5
vhost: move vdpa group bound check to vhost_vdpa
PlaidCat Sep 16, 2026
b1c4bf3
security/keys: fix missed RCU read section on lookup
PlaidCat Sep 16, 2026
ecf5d56
net/rds: Restrict use of RDS/IB to the initial network namespace
PlaidCat Sep 16, 2026
cc7bf7f
octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify
PlaidCat Sep 16, 2026
5ceba99
gfs2: Get rid of gfs2_log_[un]lock helpers
PlaidCat Sep 16, 2026
c022f03
gfs2: Move gfs2_remove_from_journal to log.c
PlaidCat Sep 16, 2026
d145702
gfs2: Remove trans_drain code duplication
PlaidCat Sep 16, 2026
9055e60
gfs2: bufdata allocation race
PlaidCat Sep 16, 2026
47b9a77
Rebuild rocky9_8 with kernel-5.14.0-687.48.1.el9_8
PlaidCat Sep 16, 2026
7ee96e5
USB: serial: io_ti: fix heap overflow in get_manuf_info()
PlaidCat Sep 18, 2026
1ee55a4
USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
PlaidCat Sep 18, 2026
c21f178
IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
PlaidCat Sep 18, 2026
63cd244
netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST with…
PlaidCat Sep 18, 2026
72b7132
ALSA: timer: Forcibly close timer instances at closing
PlaidCat Sep 18, 2026
ed74f7a
ALSA: seq: Serialize UMP output teardown with event_input
PlaidCat Sep 18, 2026
7e2390a
ALSA: timer: Fix UAF at snd_timer_user_params()
PlaidCat Sep 18, 2026
69c1e57
net: ena: PHC: Fix potential use-after-free in get_timestamp
PlaidCat Sep 18, 2026
70508ae
RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads
PlaidCat Sep 18, 2026
11f3bac
RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
PlaidCat Sep 18, 2026
cca6d67
RDMA/rxe: Fix race condition in QP timer handlers
PlaidCat Sep 18, 2026
0395198
RDMA/rxe: Reject unknown opcodes before ICRC processing
PlaidCat Sep 18, 2026
b4e96f4
RDMA/rxe: Fix a use-after-free problem in rxe_mmap
PlaidCat Sep 18, 2026
22ffaac
ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().
PlaidCat Sep 18, 2026
3574095
ip6: vti: Use ip6_tnl.net in vti6_changelink().
PlaidCat Sep 18, 2026
59ddaf6
xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_…
PlaidCat Sep 18, 2026
a157efd
xfrm: input: hold netns during deferred transport reinjection
PlaidCat Sep 18, 2026
e162778
xfrm: hold device only for the asynchronous decryption
PlaidCat Sep 18, 2026
113bc43
xfrm: hold dev ref until after transport_finish NF_HOOK
PlaidCat Sep 18, 2026
a48d875
gfs2: Add clean argument to lm_unmount hook
PlaidCat Sep 18, 2026
54816ff
gfs2: Asynchronous withdraw
PlaidCat Sep 18, 2026
ff385f0
gfs2: Fix usage of bio->bi_status in gfs2_end_log_write
PlaidCat Sep 18, 2026
f4b200c
gfs2: Get rid of delayed withdraws
PlaidCat Sep 18, 2026
791ff1c
gfs2: Fix freeze consistency check in log_write_header
PlaidCat Sep 18, 2026
5127db1
gfs2: Rename gfs2_{withdrawing_or_ => }withdrawn
PlaidCat Sep 18, 2026
2a21ffc
gfs2: Withdraw immediately on log write errors
PlaidCat Sep 18, 2026
602c72f
gfs2: Kill gfs2_io_error_bh_wd
PlaidCat Sep 18, 2026
94d073e
gfs2: Rename LM_FLAG_{NOEXP -> RECOVER}
PlaidCat Sep 18, 2026
0476e87
Revert "gfs2: don't stop reads while withdraw in progress"
PlaidCat Sep 18, 2026
67f1da7
gfs2: Follow-up to flag rename in sysfs status file
PlaidCat Sep 18, 2026
b5d4275
Revert "gfs2: Force withdraw to replay journals and wait for it to fi…
PlaidCat Sep 18, 2026
eea4cc1
Revert "gfs2: Force withdraw to replay journals and wait for it to fi…
PlaidCat Sep 18, 2026
5b35dff
Revert "gfs2: Force withdraw to replay journals and wait for it to fi…
PlaidCat Sep 18, 2026
e880c36
Revert "gfs2: Force withdraw to replay journals and wait for it to fi…
PlaidCat Sep 18, 2026
11b4770
Revert "gfs2: Force withdraw to replay journals and wait for it to fi…
PlaidCat Sep 18, 2026
78dee07
Revert "gfs2: Force withdraw to replay journals and wait for it to fi…
PlaidCat Sep 18, 2026
a0ccdd5
Revert "gfs2: fix a deadlock on withdraw-during-mount"
PlaidCat Sep 18, 2026
9f23c58
Revert "gfs2: Check for log write errors before telling dlm to unlock"
PlaidCat Sep 18, 2026
079af15
Revert "gfs2: Allow some glocks to be used during withdraw"
PlaidCat Sep 18, 2026
74fd446
Revert "gfs2: fix infinite loop when checking ail item count before g…
PlaidCat Sep 18, 2026
2ca7450
gfs2: Rename gfs2_{gl_dq_holders => withdraw_glocks}
PlaidCat Sep 18, 2026
e895518
gfs2: Clean up properly during a withdraw
PlaidCat Sep 18, 2026
ecf35cd
gfs2: New gfs2_withdraw_helper
PlaidCat Sep 18, 2026
7046452
gfs2: Withdraw immediately in gfs2_trans_add_meta
PlaidCat Sep 18, 2026
c322b3b
gfs2: Minor gfs2_{freeze,thaw}_super cleanup
PlaidCat Sep 18, 2026
66b7fe4
gfs2: Refcounting fix in gfs2_thaw_super
PlaidCat Sep 18, 2026
322f3a9
gfs2: gfs2_freeze_unlock cleanup
PlaidCat Sep 18, 2026
16de5f0
gfs2: No longer thaw filesystems during a withdraw
PlaidCat Sep 18, 2026
bc9b316
gfs2: Clean up SDF_JOURNAL_LIVE flag handling
PlaidCat Sep 18, 2026
a3a1ddb
libceph: Amend checking to fix `make W=1` build breakage
PlaidCat Sep 18, 2026
4cd1c39
gfs2: Clean up glock demote logic
PlaidCat Sep 18, 2026
5b0421b
gfs2: Minor gfs2_glock_cb cleanup
PlaidCat Sep 18, 2026
1d8bcc0
gfs2: Introduce glock_{type,number,sbd} helpers
PlaidCat Sep 18, 2026
87105d5
net: wwan: t7xx: fix potential skb->frags overflow in RX path
PlaidCat Sep 18, 2026
96a95d0
wifi: iwlwifi: mvm: fix driver-set TX rates on old devices
PlaidCat Sep 18, 2026
1accfed
wifi: iwlwifi: mld: stop TX during firmware restart
PlaidCat Sep 18, 2026
f5bcb1a
net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
PlaidCat Sep 18, 2026
6947d59
wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
PlaidCat Sep 18, 2026
58bc745
wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_ra…
PlaidCat Sep 18, 2026
c7225e9
Rebuild rocky9_8 with kernel-5.14.0-687.49.1.el9_8
PlaidCat Sep 18, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
File renamed without changes.
2 changes: 1 addition & 1 deletion Makefile.rhelver
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ RHEL_MINOR = 8
#
# Use this spot to avoid future merge conflicts.
# Do not trim this comment.
RHEL_RELEASE = 687.46.1
RHEL_RELEASE = 687.49.1

#
# ZSTREAM
Expand Down
90 changes: 90 additions & 0 deletions ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/0861615c.failed
Original file line number Diff line number Diff line change
@@ -0,0 +1,90 @@
sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing

jira KERNEL-1590
cve CVE-2026-53246
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Xin Long <lucien.xin@gmail.com>
commit 0861615c28de668669d748ef4eb913ea9262d13b
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/0861615c.failed

When a listening SCTP server processes a COOKIE_ECHO chunk, the cached
peer INIT chunk embedded after the cookie is parsed and its parameters
are later walked by sctp_process_init() using sctp_walk_params().

However, the chunk header length of this cached INIT chunk was not
validated against the remaining buffer in the COOKIE_ECHO payload. If
the length field is inflated, the parameter walk can run beyond the
actual received data, leading to out-of-bounds reads and potential
memory corruption during later parameter handling (e.g. STATE_COOKIE
processing and kmemdup() copies).

Add a bounds check in sctp_unpack_cookie() to ensure the cached INIT
chunk length does not exceed the available data in the COOKIE_ECHO
buffer before it is used.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Brian Geffon <bgeffon@google.com>
Signed-off-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/eb60825fa22d6f9e663c7d4dbb69f397b5d34d42.1780362366.git.lucien.xin@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 0861615c28de668669d748ef4eb913ea9262d13b)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
# net/sctp/sm_make_chunk.c
diff --cc net/sctp/sm_make_chunk.c
index c8f4ec5d5f98,85264862fb6b..000000000000
--- a/net/sctp/sm_make_chunk.c
+++ b/net/sctp/sm_make_chunk.c
@@@ -1748,7 -1730,7 +1748,11 @@@ struct sctp_association *sctp_unpack_co
struct sctp_signed_cookie *cookie;
struct sk_buff *skb = chunk->skb;
struct sctp_cookie *bear_cookie;
++<<<<<<< HEAD
+ __u8 *digest = ep->digest;
++=======
+ struct sctp_chunkhdr *ch;
++>>>>>>> 0861615c28de (sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing)
enum sctp_scope scope;
unsigned int len;
ktime_t kt;
@@@ -1778,20 -1760,19 +1782,30 @@@
cookie = chunk->subh.cookie_hdr;
bear_cookie = &cookie->c;

++<<<<<<< HEAD
+ if (!sctp_sk(ep->base.sk)->hmac)
+ goto no_hmac;
++=======
+ ch = (struct sctp_chunkhdr *)(bear_cookie + 1);
+ if (ntohs(ch->length) > len - fixed_size)
+ goto malformed;
+
+ /* Verify the cookie's MAC, if cookie authentication is enabled. */
+ if (sctp_sk(ep->base.sk)->cookie_auth_enable) {
+ u8 mac[SHA256_DIGEST_SIZE];
-
- hmac_sha256(&ep->cookie_auth_key, (const u8 *)bear_cookie,
- bodysize, mac);
- static_assert(sizeof(cookie->mac) == sizeof(mac));
- if (crypto_memneq(mac, cookie->mac, sizeof(mac))) {
- *error = -SCTP_IERROR_BAD_SIG;
++>>>>>>> 0861615c28de (sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing)
+
+ /* Check the signature. */
+ {
+ struct crypto_shash *tfm = sctp_sk(ep->base.sk)->hmac;
+ int err;
+
+ err = crypto_shash_setkey(tfm, ep->secret_key,
+ sizeof(ep->secret_key)) ?:
+ crypto_shash_tfm_digest(tfm, (u8 *)bear_cookie, bodysize,
+ digest);
+ if (err) {
+ *error = -SCTP_IERROR_NOMEM;
goto fail;
}
}
* Unmerged path net/sctp/sm_make_chunk.c
68 changes: 68 additions & 0 deletions ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/225d02cb.failed
Original file line number Diff line number Diff line change
@@ -0,0 +1,68 @@
drm/xe: Issue GGTT invalidation under lock in ggtt_node_remove

jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Matthew Brost <matthew.brost@intel.com>
commit 225d02cb46d0e567eb788308168159f61735c8fe
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/225d02cb.failed

Async work (e.g., GuC queue teardowns) can call ggtt_node_remove, so the
operation must be performed under the GGTT lock to ensure the GGTT
online check remains stable. GGTT insertion and removal are heavyweight
operations (e.g., queue create/destroy), so the additional serialization
cost is negligible compared to ensuring correctness.

Fixes: 4f3a998a173b ("drm/xe: Open-code GGTT MMIO access protection")
Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Reviewed-by: Dnyaneshwar Bhadane <dnyaneshwar.bhadane@intel.com>
Link: https://patch.msgid.link/20260326011207.62373-1-matthew.brost@intel.com
(cherry picked from commit 225d02cb46d0e567eb788308168159f61735c8fe)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
# drivers/gpu/drm/xe/xe_ggtt.c
diff --cc drivers/gpu/drm/xe/xe_ggtt.c
index 5edc0cad47e2,a848d1a41b9b..000000000000
--- a/drivers/gpu/drm/xe/xe_ggtt.c
+++ b/drivers/gpu/drm/xe/xe_ggtt.c
@@@ -334,29 -468,24 +334,35 @@@ static void xe_ggtt_initial_clear(struc
static void ggtt_node_remove(struct xe_ggtt_node *node)
{
struct xe_ggtt *ggtt = node->ggtt;
+ struct xe_device *xe = tile_to_xe(ggtt->tile);
bool bound;
+ int idx;
+
+ bound = drm_dev_enter(&xe->drm, &idx);

mutex_lock(&ggtt->lock);
- bound = ggtt->flags & XE_GGTT_FLAGS_ONLINE;
if (bound)
- xe_ggtt_clear(ggtt, xe_ggtt_node_addr(node), xe_ggtt_node_size(node));
+ xe_ggtt_clear(ggtt, node->base.start, node->base.size);
drm_mm_remove_node(&node->base);
node->base.size = 0;
+ if (bound && node->invalidate_on_remove)
+ xe_ggtt_invalidate(ggtt);
mutex_unlock(&ggtt->lock);

++<<<<<<< HEAD
+ if (!bound)
+ goto free_node;
+
+ if (node->invalidate_on_remove)
+ xe_ggtt_invalidate(ggtt);
+
+ drm_dev_exit(idx);
+
+free_node:
+ xe_ggtt_node_fini(node);
++=======
+ ggtt_node_fini(node);
++>>>>>>> 225d02cb46d0 (drm/xe: Issue GGTT invalidation under lock in ggtt_node_remove)
}

static void ggtt_node_remove_work_func(struct work_struct *work)
* Unmerged path drivers/gpu/drm/xe/xe_ggtt.c
Loading
Loading