Skip to content

[ciqlts8_6] Multiple patches tested (4 commits) - #1629

Open
ciq-kernel-automation[bot] wants to merge 4 commits into
ciqlts8_6from
{maple}_ciqlts8_6
Open

ciq-kernel-automation[bot] wants to merge 4 commits into
ciqlts8_6from
{maple}_ciqlts8_6

Conversation

@ciq-kernel-automation

@ciq-kernel-automation ciq-kernel-automation Bot commented Sep 18, 2026

Copy link
Copy Markdown

Summary

This PR has been automatically created after successful completion of all CI stages.

Commit Message(s)

xfrm: ah6: validate routing header segments_left

jira VULN-211383
cve CVE-2026-80844
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit 7bad4bda74dc4713f398d3b7624ff05478e3a568
net: tun: bound receive headroom

jira VULN-209966
cve CVE-2026-81000
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit 447c9303942c439a117d9b76ce6d6e2116b38ee7
pppoe: reload header pointer after dev_hard_header()

jira VULN-197178
cve CVE-2026-68121
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit e9c238f6fe42fb1b4dba3a578277de32cb487937
sctp: prevent peer transport count overflow

jira VULN-207728
cve CVE-2026-74469
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit bd0e9289e2642f6a5c54faad304ce0f41e926d22
upstream-diff |
	context diff due to missing:
	4e7696d90b51a1a73ce0e8174f3aff58b914619c
	[sctp: get netns from asoc and ep base]

Test Results

✅ Build Stage

Architecture Build Time Total Time
x86_64 23m 6s 24m 1s
aarch64 9m 22s 9m 58s

✅ Boot Verification

✅ Kernel Selftests

Architecture Passed Failed Compared Against Status
x86_64 108 31 ciqlts8_6 ✅ No regressions
aarch64 67 20 ciqlts8_6 ✅ No regressions

✅ LTP Results

Architecture Passed Failed Compared Against Status
x86_64 1443 13 ciqlts8_6 ✅ No regressions
aarch64 1425 14 ciqlts8_6 ✅ No regressions

🤖 This PR was automatically generated by GitHub Actions
Run ID: 35391607379

@ciq-kernel-automation ciq-kernel-automation Bot added the created-by-kernelci Tag PRs that were automatically created when a user branch was pushed to the repo (kernelCI) label Sep 18, 2026
@PlaidCat PlaidCat self-assigned this Sep 18, 2026
@PlaidCat
PlaidCat requested a review from a team September 18, 2026 19:53
jira VULN-211383
cve CVE-2026-80844
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit 7bad4bd

AH6 rearranges routing-header addresses before computing or verifying the
ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than
the number of addresses described by the routing header's hdrlen field.

That assumption does not hold for raw IPv6 HDRINCL packets. A packet with
hdrlen equal to 2 describes one address, but can carry an arbitrary
segments_left value. With segments_left equal to 255, the function moves
its address pointer 4,064 bytes backwards and passes a 4,064-byte length to
memmove(), resulting in an out-of-bounds access.

Validate the invariant locally before modifying the routing header or
performing any address-pointer arithmetic, and propagate malformed-header
errors to the existing AH6 input and output error paths.

Fixes: 1da177e ("Linux-2.6.12-rc2")
	Cc: stable@vger.kernel.org
Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
	Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
	Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
(cherry picked from commit 7bad4bd)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira VULN-209966
cve CVE-2026-81000
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit 447c930

tun_get_user() uses tun->align both as skb headroom and when choosing how
much packet data to keep linear. OVS can propagate an oversized headroom
request from another port to TUN or TAP.

When align is larger than the usable space in a one-page skb head,
SKB_MAX_HEAD(align) underflows and the result becomes negative when stored
in good_linear. That value later wraps when assigned to the size_t linear
variable, and tun_alloc_skb() can place skb->data outside the allocated
head.

Bound the headroom stored by TUN to the one-page skb-head budget and the
largest non-sentinel 16-bit skb header offset. Leave one linear byte for
raw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN.

Also pull the raw-TUN protocol byte and the TAP Ethernet header before
accessing them, so these checks remain safe for nonlinear skbs supplied by
other allocation paths.

Fixes: eaea34b ("net/tun: implement ndo_set_rx_headroom")
	Cc: stable@vger.kernel.org
	Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
	Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260812012139.2134643-1-manizada@pm.me
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 447c930)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira VULN-197178
cve CVE-2026-68121
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit e9c238f

pppoe_sendmsg() saves a pointer to the PPPoE header before calling
dev_hard_header(). Device header callbacks are allowed to reallocate the
skb head, invalidating pointers into it.

This can happen when a send is blocked in copy_from_user() while the first
non-Ethernet port is added to an empty team device. The team's delegated
GRE header callback then expands the skb head. PPPoE subsequently writes
six bytes through the stale pointer into the freed head.

Reload the PPPoE header through the skb's network-header offset after
device header creation. pskb_expand_head() updates that offset when it
relocates the head.

Fixes: 1da177e ("Linux-2.6.12-rc2")
	Cc: stable@vger.kernel.org
	Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
	Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
	Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260722093814.3017176-1-manizada@pm.me
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit e9c238f)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira VULN-207728
cve CVE-2026-74469
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit bd0e928
upstream-diff |
	context diff due to missing:
	4e7696d
	[sctp: get netns from asoc and ep base]

sctp_assoc_add_peer() increments the association's 16-bit transport_count
for every new unique peer. Adding the 65,536th transport wraps the count to
zero.

SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
then copies one sockaddr_storage for every entry in transport_addr_list.
After the wrap, a diagnostic dump reserves an empty payload and writes
8 MiB of peer addresses past the skb tail.

Reject a new unique peer when transport_count has reached U16_MAX. Perform
the check after the existing-peer lookup so a duplicate address continues
to return its existing transport at the limit.

Fixes: 8f840e4 ("sctp: add the sctp_diag.c file")
	Cc: stable@vger.kernel.org
	Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
	Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260725032053.521705-1-manizada@pm.me
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit bd0e928)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>
@github-actions

Copy link
Copy Markdown

🤖 Validation Checks In Progress Workflow run: https://github.com/ctrliq/kernel-src-tree/actions/runs/35392390218

@github-actions

Copy link
Copy Markdown

🔍 Interdiff Analysis

  • ⚠️ PR commit 4c4601df5414 (net: tun: bound receive headroom) → upstream 447c9303942c
    Differences found:
================================================================================
*    CONTEXT DIFFERENCES - surrounding code differences between the patches    *
================================================================================

--- b/drivers/net/tun.c
+++ b/drivers/net/tun.c
@@ -1981,2 +1843,3 @@
 			err = -ENOMEM;
+			drop_reason = SKB_DROP_REASON_HDR_TRUNC;
 			goto drop;
  • ⚠️ PR commit 50cde0c52b50 (sctp: prevent peer transport count overflow) → upstream bd0e9289e264
    Differences found:
################################################################################
!    REJECTED PATCH2 HUNKS - could not be compared; manual review needed       !
################################################################################

--- b/net/sctp/associola.c
+++ b/net/sctp/associola.c
@@ -614,6 +614,9 @@
 		return peer;
 	}
 
+	if (asoc->peer.transport_count == U16_MAX)
+		return NULL;
+
 	peer = sctp_transport_new(asoc->base.net, addr, gfp);
 	if (!peer)
 		return NULL;

================================================================================
*    CONTEXT DIFFERENCES - surrounding code differences between the patches    *
================================================================================

--- b/net/sctp/associola.c
+++ b/net/sctp/associola.c
@@ -612,5 +612,5 @@
 	}
 
-	peer = sctp_transport_new(net, addr, gfp);
+	peer = sctp_transport_new(asoc->base.net, addr, gfp);
 	if (!peer)
 		return NULL;

This is an automated interdiff check for backported commits.

@github-actions

Copy link
Copy Markdown

JIRA PR Check Results

1 commit(s) with issues found:

Commit 50cde0c52b50

Summary: sctp: prevent peer transport count overflow

❌ Errors:

  • VULN-207728: Status is 'To Do', expected 'In Progress'

⚠️ Warnings:

  • VULN-207728: No time logged - please log time manually

Summary: Checked 4 commit(s) total.

@github-actions

Copy link
Copy Markdown

Validation checks completed with issues View full results: https://github.com/ctrliq/kernel-src-tree/actions/runs/35392390218

@bmastbergen bmastbergen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🥌

@bmastbergen
bmastbergen requested a review from a team September 18, 2026 20:46

@kerneltoast kerneltoast left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚢

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

created-by-kernelci Tag PRs that were automatically created when a user branch was pushed to the repo (kernelCI)

Development

Successfully merging this pull request may close these issues.

4 participants