[ciqlts9_2] Multiple patches tested (5 commits) - #1628
Open
ciq-kernel-automation[bot] wants to merge 5 commits into
Open
ciq-kernel-automation[bot] wants to merge 5 commits into
ciq-kernel-automation[bot] wants to merge 5 commits into
Conversation
bmastbergen
requested changes
Sep 18, 2026
| u8 ip_version; | ||
|
|
||
| if (!pskb_may_pull(skb, 1)) { | ||
| err = -EINVAL; |
Collaborator
There was a problem hiding this comment.
I think we need to define a drop_reason before the goto drop;, otherwise drop_reason is passed undefined to kfree_skb_reason.
Collaborator
There was a problem hiding this comment.
Good catch the 8.6 had the same but doesn't have the drop_reason ..
I chose to backport the precondition commit as it cleans up this jumping around awkwardly
PlaidCat
force-pushed
the
{maple}_ciqlts9_2
branch
from
September 18, 2026 21:43
4628832 to
efaff75
Compare
jira VULN-211382 cve CVE-2026-80844 commit-author Asim Viladi Oglu Manizada <manizada@pm.me> commit 7bad4bd AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of addresses described by the routing header's hdrlen field. That assumption does not hold for raw IPv6 HDRINCL packets. A packet with hdrlen equal to 2 describes one address, but can carry an arbitrary segments_left value. With segments_left equal to 255, the function moves its address pointer 4,064 bytes backwards and passes a 4,064-byte length to memmove(), resulting in an out-of-bounds access. Validate the invariant locally before modifying the routing header or performing any address-pointer arithmetic, and propagate malformed-header errors to the existing AH6 input and output error paths. Fixes: 1da177e ("Linux-2.6.12-rc2") Cc: stable@vger.kernel.org Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me> Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com> (cherry picked from commit 7bad4bd) Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira VULN-209970 cve-pre CVE-2026-81000 commit-author Chuang Wang <nashuiliang@gmail.com> commit ab00af8 The error handling in tun_get_user is very scattered. This patch unifies error handling, reduces duplication of code, and makes the logic clearer. Signed-off-by: Chuang Wang <nashuiliang@gmail.com> Signed-off-by: David S. Miller <davem@davemloft.net> (cherry picked from commit ab00af8) Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira VULN-209970 cve CVE-2026-81000 commit-author Asim Viladi Oglu Manizada <manizada@pm.me> commit 447c930 tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the result becomes negative when stored in good_linear. That value later wraps when assigned to the size_t linear variable, and tun_alloc_skb() can place skb->data outside the allocated head. Bound the headroom stored by TUN to the one-page skb-head budget and the largest non-sentinel 16-bit skb header offset. Leave one linear byte for raw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN. Also pull the raw-TUN protocol byte and the TAP Ethernet header before accessing them, so these checks remain safe for nonlinear skbs supplied by other allocation paths. Fixes: eaea34b ("net/tun: implement ndo_set_rx_headroom") Cc: stable@vger.kernel.org Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me> Reviewed-by: Willem de Bruijn <willemb@google.com> Link: https://patch.msgid.link/20260812012139.2134643-1-manizada@pm.me Signed-off-by: Jakub Kicinski <kuba@kernel.org> (cherry picked from commit 447c930) Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira VULN-197182 cve CVE-2026-68121 commit-author Asim Viladi Oglu Manizada <manizada@pm.me> commit e9c238f pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is added to an empty team device. The team's delegated GRE header callback then expands the skb head. PPPoE subsequently writes six bytes through the stale pointer into the freed head. Reload the PPPoE header through the skb's network-header offset after device header creation. pskb_expand_head() updates that offset when it relocates the head. Fixes: 1da177e ("Linux-2.6.12-rc2") Cc: stable@vger.kernel.org Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me> Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev> Reviewed-by: Eric Dumazet <edumazet@google.com> Link: https://patch.msgid.link/20260722093814.3017176-1-manizada@pm.me Signed-off-by: Jakub Kicinski <kuba@kernel.org> (cherry picked from commit e9c238f) Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira VULN-207732 cve CVE-2026-74469 commit-author Asim Viladi Oglu Manizada <manizada@pm.me> commit bd0e928 sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload, then copies one sockaddr_storage for every entry in transport_addr_list. After the wrap, a diagnostic dump reserves an empty payload and writes 8 MiB of peer addresses past the skb tail. Reject a new unique peer when transport_count has reached U16_MAX. Perform the check after the existing-peer lookup so a duplicate address continues to return its existing transport at the limit. Fixes: 8f840e4 ("sctp: add the sctp_diag.c file") Cc: stable@vger.kernel.org Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me> Acked-by: Xin Long <lucien.xin@gmail.com> Link: https://patch.msgid.link/20260725032053.521705-1-manizada@pm.me Signed-off-by: Jakub Kicinski <kuba@kernel.org> (cherry picked from commit bd0e928) Signed-off-by: Jonathan Maple <jmaple@ciq.com>
PlaidCat
force-pushed
the
{maple}_ciqlts9_2
branch
from
September 18, 2026 21:46
efaff75 to
d6ac555
Compare
|
🤖 Validation Checks In Progress Workflow run: https://github.com/ctrliq/kernel-src-tree/actions/runs/35399092725 |
|
✅ Validation checks completed successfully View full results: https://github.com/ctrliq/kernel-src-tree/actions/runs/35399092725 |
kerneltoast
approved these changes
Sep 19, 2026
kerneltoast
left a comment
Collaborator
There was a problem hiding this comment.
@bmastbergen your block appears to be addressed
🚢
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR has been automatically created after successful completion of all CI stages.
Commit Message(s)
Test Results
✅ Build Stage
✅ Boot Verification
✅ Kernel Selftests
✅ LTP Results
aarch64 regressions:
🤖 This PR was automatically generated by GitHub Actions
Run ID: 35398563540