Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2722-1

Опубликовано: 01 июл. 2026
Источник: suse-cvrf

Описание

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP7 kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290).
  • CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668).
  • CVE-2026-23392: netfilter: nf_tables: release flowtable after rcu grace period on error (bsc#1260531).
  • CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085).
  • CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392).
  • CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620).
  • CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false
  • CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748).
  • CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798).
  • CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674).
  • CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993).
  • CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178).
  • CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057).
  • CVE-2026-31592: KVM: SEV: Protect all of sev_mem_enc_register_region() with kvm->lock (bsc#1263123).
  • CVE-2026-31593: KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU (bsc#1263124).
  • CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578).
  • CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137).
  • CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568).
  • CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563).
  • CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744).
  • CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045).
  • CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076).
  • CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137).
  • CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930).
  • CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934).
  • CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996).
  • CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993).
  • CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080).
  • CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470).
  • CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266).
  • CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239).
  • CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437).
  • CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561).
  • CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595).
  • CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549).
  • CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603).
  • CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610).
  • CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444).
  • CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763).
  • CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103).
  • CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741).
  • CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143).
  • CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628).
  • CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397).
  • CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390).
  • CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705).
  • CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704).
  • CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895).
  • CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916).
  • CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933).
  • CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698).
  • CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208).
  • CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922).
  • CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431).
  • CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361).
  • CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878).
  • CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628).
  • CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621).
  • CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387).
  • CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624).
  • CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840).
  • CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903).
  • CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654).
  • CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685).
  • CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651).

The following non-security bugs were fixed:

  • ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes).
  • ACPI: IPMI: Fix message kref handling on dead device (git-fixes).
  • ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes).
  • ALSA: aloop: Drop superfluous break (git-fixes).
  • ALSA: cmipci: check snd_ctl_new1() return value (git-fixes).
  • ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git-fixes).
  • ALSA: es1938: check snd_ctl_new1() return value (git-fixes).
  • ALSA: gus: check snd_ctl_new1() return value (git-fixes).
  • ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes).
  • ALSA: ice1712: check snd_ctl_new1() return value (git-fixes).
  • ALSA: seq: Clear variable event pointer on read (git-fixes).
  • ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes).
  • ALSA: seq: Fix partial userptr event expansion (git-fixes).
  • ALSA: seq: midi: Serialize output teardown with event_input (git-fixes).
  • ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes).
  • ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes).
  • ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes).
  • ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes).
  • ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes).
  • ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes).
  • ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes).
  • ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes).
  • ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes).
  • ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes).
  • ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git-fixes).
  • ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes).
  • ASoC: SOF: topology: validate vendor array size before parsing (git-fixes).
  • ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git-fixes).
  • ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes).
  • ASoC: cs35l56: Cleanup if component_probe fails (git-fixes).
  • ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes).
  • ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes).
  • ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes).
  • ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes).
  • ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes).
  • ASoC: meson: aiu: Validate written enum values (git-fixes).
  • ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes).
  • ASoC: topology: Check PCM and DAI name strings before use (git-fixes).
  • ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git-fixes).
  • Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes).
  • Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git-fixes).
  • Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes).
  • Bluetooth: btusb: fix use-after-free on registration failure (git-fixes).
  • Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes).
  • Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes).
  • Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git-fixes).
  • Bluetooth: hci: validate codec capability element length (git-fixes).
  • Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device (git-fixes).
  • Bluetooth: vhci: validate devcoredump state before side effects (git-fixes).
  • KVM: SEV: Ignore MMIO requests of length '0' (git-fixes).
  • KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes).
  • KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes).
  • KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes).
  • KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes).
  • KVM: SVM: check validity of VMCB controls when returning from SMM (git-fixes).
  • KVM: arm64: Discard PC update state on vcpu reset (git-fixes).
  • KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes).
  • KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes).
  • KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes).
  • KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes).
  • KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes).
  • KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes).
  • KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes).
  • KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes).
  • KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes).
  • KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git-fixes).
  • PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes).
  • USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes).
  • USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes).
  • USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes).
  • X.509: Fix validation of ASN.1 certificate header (git-fixes).
  • accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes).
  • agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes).
  • batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes).
  • batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes).
  • batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes).
  • batman-adv: tp_meter: avoid window underflow (git-fixes).
  • batman-adv: tp_meter: fix fast recovery precondition (git-fixes).
  • batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes).
  • batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes).
  • batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes).
  • batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes).
  • crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes).
  • crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes).
  • crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git-fixes).
  • crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes).
  • crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes).
  • crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes).
  • crypto: ccp - Treat zero-length cert chain as query for blob lengths (git-fixes).
  • crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes).
  • crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes).
  • crypto: drbg - Fix the fips_enabled priority boost (git-fixes).
  • crypto: ecc - Fix carry overflow in vli multiplication (git-fixes).
  • crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes).
  • crypto: hisilicon/qm - disable error report before flr (git-fixes).
  • crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git-fixes).
  • crypto: pcrypt - restore callback for non-parallel fallback (git-fixes).
  • crypto: qat - protect service table iterations with service_lock (git-fixes).
  • crypto: qat - validate RSA CRT component lengths (git-fixes).
  • crypto: rng - Free default RNG on module exit (git-fixes).
  • driver core: reject devices with unregistered buses (git-fixes).
  • driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git-fixes).
  • drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes).
  • drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git-fixes).
  • drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes).
  • drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes).
  • drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes).
  • drm/amdkfd: always resume_all after suspend_all (git-fixes).
  • drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes).
  • drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git-fixes).
  • drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git-fixes).
  • drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes).
  • drm/gpuvm: Do not prepare NULL objects (git-fixes).
  • drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git-fixes).
  • drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes).
  • drm/hyperv: use VMBUS_RING_SIZE() (git-fixes).
  • drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes).
  • drm/imagination: Count paired job fence as dependency in prepare_job() (git-fixes).
  • drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes).
  • drm/msm/dp: Fix the ISR_* enum values (git-fixes).
  • drm/msm/dp: fix HPD state status bit shift value (git-fixes).
  • drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes).
  • drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes).
  • drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes).
  • drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git-fixes).
  • drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git-fixes).
  • drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes).
  • drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes).
  • drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git-fixes).
  • drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes).
  • drm/tidss: Fix missing drm_bridge_add() call (git-fixes).
  • drm/vc4: fix krealloc() memory leak (git-fixes).
  • drm/virtio: Fix driver removal with disabled KMS (git-fixes).
  • drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes).
  • drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes).
  • drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes).
  • fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git-fixes).
  • fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes).
  • fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes).
  • fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git-fixes).
  • fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes).
  • fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes).
  • fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git-fixes).
  • fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes).
  • fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes).
  • fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes).
  • fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes).
  • fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git-fixes).
  • fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes).
  • fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes).
  • firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes).
  • firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes).
  • firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes).
  • firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes).
  • gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes).
  • gpu: host1x: Allow entries in BO caches to be freed (git-fixes).
  • gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes).
  • hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes).
  • hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes).
  • hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes).
  • i2c: core: fix irq domain leak on adapter registration failure (git-fixes).
  • i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes).
  • i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes).
  • i2c: tegra: Fix NOIRQ suspend/resume (git-fixes).
  • ice: ptp: do not WARN when controlling PF is unavailable (bsc#1267251).
  • misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes).
  • misc: fastrpc: fix DMA address corruption due to find_vma misuse (git-fixes).
  • misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git-fixes).
  • misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes).
  • of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes).
  • scripts/submit_branch: add SLE15-SP7 submission script
  • serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git-fixes).
  • serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git-fixes).
  • slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes).
  • soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes).
  • soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes).
  • spi: at91-usart: drop dead runtime pm support (git-fixes).
  • spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes).
  • spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes).
  • spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git-fixes).
  • spi: meson-spifc: fix runtime PM leak on remove (git-fixes).
  • spi: xilinx: use FIFO occupancy register to determine buffer size (git-fixes).
  • thermal: hwmon: Fix critical temperature attribute removal (git-fixes).
  • thunderbolt: Bound root directory content to block size (git-fixes).
  • thunderbolt: Clamp XDomain response data copy to allocation size (git-fixes).
  • thunderbolt: Limit XDomain response copy to actual frame size (git-fixes).
  • thunderbolt: Reject zero-length property entries in validator (git-fixes).
  • thunderbolt: Validate XDomain request packet size before type cast (git-fixes).
  • watchdog: apple: Add 'apple,t8103-wdt' compatible (git-fixes).
  • watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes).
  • watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes).
  • watchdog: unregister PM notifier on watchdog unregister (git-fixes).
  • wifi: ath11k: fix warning when unbinding (git-fixes).
  • wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes).
  • wifi: cfg80211: fix grammar in MLO group key error message (git-fixes).
  • wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes).
  • wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes).
  • wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes).
  • wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes).
  • wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes).
  • wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes).
  • wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes).
  • wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes).
  • wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes).
  • wifi: rtw88: increase TX report timeout to fix race condition (git-fixes).
  • wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes).
  • wifi: rtw89: Correct data type for scan index to avoid infinite loop (git-fixes).
  • wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes).
  • wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git-fixes).
  • wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git-fixes).

Список пакетов

Container bci/bci-sle15-kernel-module-devel:latest
kernel-default-devel-6.4.0-150700.53.63.1
kernel-devel-6.4.0-150700.53.63.1
kernel-macros-6.4.0-150700.53.63.1
kernel-syms-6.4.0-150700.53.63.1
Image SLES15-SP7-CHOST-BYOS-Aliyun
kernel-default-6.4.0-150700.53.63.1
Image SLES15-SP7-CHOST-BYOS-Azure
kernel-default-6.4.0-150700.53.63.1
Image SLES15-SP7-CHOST-BYOS-EC2
kernel-default-6.4.0-150700.53.63.1
Image SLES15-SP7-CHOST-BYOS-GCE
kernel-default-6.4.0-150700.53.63.1
Image SLES15-SP7-CHOST-BYOS-GDC
kernel-default-6.4.0-150700.53.63.1
Image SLES15-SP7-CHOST-BYOS-SAP-CCloud
kernel-default-6.4.0-150700.53.63.1
Image SLES15-SP7-HPC-Azure
kernel-azure-6.4.0-150700.53.63.1
Image SLES15-SP7-HPC-BYOS-Azure
kernel-default-6.4.0-150700.53.63.1
Image SLES15-SP7-HPC-BYOS-EC2
kernel-default-6.4.0-150700.53.63.1
Image SLES15-SP7-HPC-BYOS-GCE
kernel-default-6.4.0-150700.53.63.1
SUSE Linux Enterprise High Availability Extension 15 SP7
cluster-md-kmp-default-6.4.0-150700.53.63.1
dlm-kmp-default-6.4.0-150700.53.63.1
gfs2-kmp-default-6.4.0-150700.53.63.1
ocfs2-kmp-default-6.4.0-150700.53.63.1
SUSE Linux Enterprise Live Patching 15 SP7
kernel-default-livepatch-6.4.0-150700.53.63.1
kernel-default-livepatch-devel-6.4.0-150700.53.63.1
kernel-livepatch-6_4_0-150700_53_63-default-1-150700.15.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
kernel-64kb-6.4.0-150700.53.63.1
kernel-64kb-devel-6.4.0-150700.53.63.1
kernel-default-6.4.0-150700.53.63.1
kernel-default-base-6.4.0-150700.53.63.1.150700.17.37.1
kernel-default-devel-6.4.0-150700.53.63.1
kernel-devel-6.4.0-150700.53.63.1
kernel-macros-6.4.0-150700.53.63.1
kernel-zfcpdump-6.4.0-150700.53.63.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
kernel-docs-6.4.0-150700.53.63.1
kernel-obs-build-6.4.0-150700.53.63.1
kernel-source-6.4.0-150700.53.63.1
kernel-syms-6.4.0-150700.53.63.1
SUSE Linux Enterprise Module for Legacy 15 SP7
reiserfs-kmp-default-6.4.0-150700.53.63.1
SUSE Linux Enterprise Module for Public Cloud 15 SP7
kernel-azure-6.4.0-150700.53.63.1
kernel-azure-devel-6.4.0-150700.53.63.1
SUSE Linux Enterprise Workstation Extension 15 SP7
kernel-default-extra-6.4.0-150700.53.63.1

Описание

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Input: alps - fix use-after-free bugs caused by dev3_register_work The dev3_register_work delayed work item is initialized within alps_reconnect() and scheduled upon receipt of the first bare PS/2 packet from an external PS/2 device connected to the ALPS touchpad. During device detachment, the original implementation calls flush_workqueue() in psmouse_disconnect() to ensure completion of dev3_register_work. However, the flush_workqueue() in psmouse_disconnect() only blocks and waits for work items that were already queued to the workqueue prior to its invocation. Any work items submitted after flush_workqueue() is called are not included in the set of tasks that the flush operation awaits. This means that after flush_workqueue() has finished executing, the dev3_register_work could still be scheduled. Although the psmouse state is set to PSMOUSE_CMD_MODE in psmouse_disconnect(), the scheduling of dev3_register_work remains unaffected. The race condition can occur as follows: CPU 0 (cleanup path) | CPU 1 (delayed work) psmouse_disconnect() | psmouse_set_state() | flush_workqueue() | alps_report_bare_ps2_packet() alps_disconnect() | psmouse_queue_work() kfree(priv); // FREE | alps_register_bare_ps2_mouse() | priv = container_of(work...); // USE | priv->dev3 // USE Add disable_delayed_work_sync() in alps_disconnect() to ensure that dev3_register_work is properly canceled and prevented from executing after the alps_data structure has been deallocated. This bug is identified by static analysis.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flowtable after rcu grace period on error Call synchronize_rcu() after unregistering the hooks from error path, since a hook that already refers to this flowtable can be already registered, exposing this flowtable to packet path and nfnetlink_hook control plane. This error path is rare, it should only happen by reaching the maximum number hooks or by failing to set up to hardware offload, just call synchronize_rcu(). There is a check for already used device hooks by different flowtable that could result in EEXIST at this late stage. The hook parser can be updated to perform this check earlier to this error path really becomes rarely exercised. Uncovered by KASAN reported as use-after-free from nfnetlink_hook path when dumping hooks.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper Use expect->helper in ctnetlink and /proc to dump the helper name. Using nfct_help() without holding a reference to the master conntrack is unsafe. Use exp->master->helper in ctnetlink path if userspace does not provide an explicit helper when creating an expectation to retain the existing behaviour. The ctnetlink expectation path holds the reference on the master conntrack and nf_conntrack_expect lock and the nfnetlink glue path refers to the master ct that is attached to the skb.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: skb: fix cross-cache free of KFENCE-allocated skb head SKB_SMALL_HEAD_CACHE_SIZE is intentionally set to a non-power-of-2 value (e.g. 704 on x86_64) to avoid collisions with generic kmalloc bucket sizes. This ensures that skb_kfree_head() can reliably use skb_end_offset to distinguish skb heads allocated from skb_small_head_cache vs. generic kmalloc caches. However, when KFENCE is enabled, kfence_ksize() returns the exact requested allocation size instead of the slab bucket size. If a caller (e.g. bpf_test_init) allocates skb head data via kzalloc() and the requested size happens to equal SKB_SMALL_HEAD_CACHE_SIZE, then slab_build_skb() -> ksize() returns that exact value. After subtracting skb_shared_info overhead, skb_end_offset ends up matching SKB_SMALL_HEAD_HEADROOM, causing skb_kfree_head() to incorrectly free the object to skb_small_head_cache instead of back to the original kmalloc cache, resulting in a slab cross-cache free: kmem_cache_free(skbuff_small_head): Wrong slab cache. Expected skbuff_small_head but got kmalloc-1k Fix this by always calling kfree(head) in skb_kfree_head(). This keeps the free path generic and avoids allocator-specific misclassification for KFENCE objects.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ext4: convert inline data to extents when truncate exceeds inline size Add a check in ext4_setattr() to convert files from inline data storage to extent-based storage when truncate() grows the file size beyond the inline capacity. This prevents the filesystem from entering an inconsistent state where the inline data flag is set but the file size exceeds what can be stored inline. Without this fix, the following sequence causes a kernel BUG_ON(): 1. Mount filesystem with inode that has inline flag set and small size 2. truncate(file, 50MB) - grows size but inline flag remains set 3. sendfile() attempts to write data 4. ext4_write_inline_data() hits BUG_ON(write_size > inline_capacity) The crash occurs because ext4_write_inline_data() expects inline storage to accommodate the write, but the actual inline capacity (~60 bytes for i_block + ~96 bytes for xattrs) is far smaller than the file size and write request. The fix checks if the new size from setattr exceeds the inode's actual inline capacity (EXT4_I(inode)->i_inline_size) and converts the file to extent-based storage before proceeding with the size change. This addresses the root cause by ensuring the inline data flag and file size remain consistent during truncate operations.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfs: avoid dereferencing log items after push callbacks After xfsaild_push_item() calls iop_push(), the log item may have been freed if the AIL lock was dropped during the push. Background inode reclaim or the dquot shrinker can free the log item while the AIL lock is not held, and the tracepoints in the switch statement dereference the log item after iop_push() returns. Fix this by capturing the log item type, flags, and LSN before calling xfsaild_push_item(), and introducing a new xfs_ail_push_class trace event class that takes these pre-captured values and the ailp pointer instead of the log item pointer.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false A UAF issue occurs when the virtio_net driver is configured with napi_tx=N and the device's IFF_XMIT_DST_RELEASE flag is cleared (e.g., during the configuration of tc route filter rules). When IFF_XMIT_DST_RELEASE is removed from the net_device, the network stack expects the driver to hold the reference to skb->dst until the packet is fully transmitted and freed. In virtio_net with napi_tx=N, skbs may remain in the virtio transmit ring for an extended period. If the network namespace is destroyed while these skbs are still pending, the corresponding dst_ops structure has freed. When a subsequent packet is transmitted, free_old_xmit() is triggered to clean up old skbs. It then calls dst_release() on the skb associated with the stale dst_entry. Since the dst_ops (referenced by the dst_entry) has already been freed, a UAF kernel paging request occurs. fix it by adds skb_dst_drop(skb) in start_xmit to explicitly release the dst reference before the skb is queued in virtio_net. Call Trace: Unable to handle kernel paging request at virtual address ffff80007e150000 CPU: 2 UID: 0 PID: 6236 Comm: ping Kdump: loaded Not tainted 7.0.0-rc1+ #6 PREEMPT ... percpu_counter_add_batch+0x3c/0x158 lib/percpu_counter.c:98 (P) dst_release+0xe0/0x110 net/core/dst.c:177 skb_release_head_state+0xe8/0x108 net/core/skbuff.c:1177 sk_skb_reason_drop+0x54/0x2d8 net/core/skbuff.c:1255 dev_kfree_skb_any_reason+0x64/0x78 net/core/dev.c:3469 napi_consume_skb+0x1c4/0x3a0 net/core/skbuff.c:1527 __free_old_xmit+0x164/0x230 drivers/net/virtio_net.c:611 [virtio_net] free_old_xmit drivers/net/virtio_net.c:1081 [virtio_net] start_xmit+0x7c/0x530 drivers/net/virtio_net.c:3329 [virtio_net] ... Reproduction Steps: NETDEV="enp3s0" config_qdisc_route_filter() { tc qdisc del dev $NETDEV root tc qdisc add dev $NETDEV root handle 1: prio tc filter add dev $NETDEV parent 1:0 \ protocol ip prio 100 route to 100 flowid 1:1 ip route add 192.168.1.100/32 dev $NETDEV realm 100 } test_ns() { ip netns add testns ip link set $NETDEV netns testns ip netns exec testns ifconfig $NETDEV 10.0.32.46/24 ip netns exec testns ping -c 1 10.0.32.1 ip netns del testns } config_qdisc_route_filter test_ns sleep 2 test_ns


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Initialize free_qp completion before using it In irdma_create_qp, if ib_copy_to_udata fails, it will call irdma_destroy_qp to clean up which will attempt to wait on the free_qp completion, which is not initialized yet. Fix this by initializing the completion before the ib_copy_to_udata call.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: use netlink policy range checks Replace manual range and mask validations with netlink policy annotations in ctnetlink code paths, so that the netlink core rejects invalid values early and can generate extack errors. - CTA_PROTOINFO_TCP_STATE: reject values > TCP_CONNTRACK_SYN_SENT2 at policy level, removing the manual >= TCP_CONNTRACK_MAX check. - CTA_PROTOINFO_TCP_WSCALE_ORIGINAL/REPLY: reject values > TCP_MAX_WSCALE (14). The normal TCP option parsing path already clamps to this value, but the ctnetlink path accepted 0-255, causing undefined behavior when used as a u32 shift count. - CTA_FILTER_ORIG_FLAGS/REPLY_FLAGS: use NLA_POLICY_MASK with CTA_FILTER_F_ALL, removing the manual mask checks. - CTA_EXPECT_FLAGS: use NLA_POLICY_MASK with NF_CT_EXPECT_MASK, adding a new mask define grouping all valid expect flags. Extracted from a broader nf-next patch by Florian Westphal, scoped to ctnetlink for the fixes tree.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() l2cap_conn_del() calls cancel_delayed_work_sync() for both info_timer and id_addr_timer while holding conn->lock. However, the work functions l2cap_info_timeout() and l2cap_conn_update_id_addr() both acquire conn->lock, creating a potential AB-BA deadlock if the work is already executing when l2cap_conn_del() takes the lock. Move the work cancellations before acquiring conn->lock and use disable_delayed_work_sync() to additionally prevent the works from being rearmed after cancellation, consistent with the pattern used in hci_conn_del().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock btintel_hw_error() issues two __hci_cmd_sync() calls (HCI_OP_RESET and Intel exception-info retrieval) without holding hci_req_sync_lock(). This lets it race against hci_dev_do_close() -> btintel_shutdown_combined(), which also runs __hci_cmd_sync() under the same lock. When both paths manipulate hdev->req_status/req_rsp concurrently, the close path may free the response skb first, and the still-running hw_error path hits a slab-use-after-free in kfree_skb(). Wrap the whole recovery sequence in hci_req_sync_lock/unlock so it is serialized with every other synchronous HCI command issuer. Below is the data race report and the kasan report: BUG: data-race in __hci_cmd_sync_sk / btintel_shutdown_combined read of hdev->req_rsp at net/bluetooth/hci_sync.c:199 by task kworker/u17:1/83: __hci_cmd_sync_sk+0x12f2/0x1c30 net/bluetooth/hci_sync.c:200 __hci_cmd_sync+0x55/0x80 net/bluetooth/hci_sync.c:223 btintel_hw_error+0x114/0x670 drivers/bluetooth/btintel.c:254 hci_error_reset+0x348/0xa30 net/bluetooth/hci_core.c:1030 write/free by task ioctl/22580: btintel_shutdown_combined+0xd0/0x360 drivers/bluetooth/btintel.c:3648 hci_dev_close_sync+0x9ae/0x2c10 net/bluetooth/hci_sync.c:5246 hci_dev_do_close+0x232/0x460 net/bluetooth/hci_core.c:526 BUG: KASAN: slab-use-after-free in sk_skb_reason_drop+0x43/0x380 net/core/skbuff.c:1202 Read of size 4 at addr ffff888144a738dc by task kworker/u17:1/83: __hci_cmd_sync_sk+0x12f2/0x1c30 net/bluetooth/hci_sync.c:200 __hci_cmd_sync+0x55/0x80 net/bluetooth/hci_sync.c:223 btintel_hw_error+0x186/0x670 drivers/bluetooth/btintel.c:260


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: futex: Clear stale exiting pointer in futex_lock_pi() retry path Fuzzying/stressing futexes triggered: WARNING: kernel/futex/core.c:825 at wait_for_owner_exiting+0x7a/0x80, CPU#11: futex_lock_pi_s/524 When futex_lock_pi_atomic() sees the owner is exiting, it returns -EBUSY and stores a refcounted task pointer in 'exiting'. After wait_for_owner_exiting() consumes that reference, the local pointer is never reset to nil. Upon a retry, if futex_lock_pi_atomic() returns a different error, the bogus pointer is passed to wait_for_owner_exiting(). CPU0 CPU1 CPU2 futex_lock_pi(uaddr) // acquires the PI futex exit() futex_cleanup_begin() futex_state = EXITING; futex_lock_pi(uaddr) futex_lock_pi_atomic() attach_to_pi_owner() // observes EXITING *exiting = owner; // takes ref return -EBUSY wait_for_owner_exiting(-EBUSY, owner) put_task_struct(); // drops ref // exiting still points to owner goto retry; futex_lock_pi_atomic() lock_pi_update_atomic() cmpxchg(uaddr) *uaddr ^= WAITERS // whatever // value changed return -EAGAIN; wait_for_owner_exiting(-EAGAIN, exiting) // stale WARN_ON_ONCE(exiting) Fix this by resetting upon retry, essentially aligning it with requeue_pi.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: spi: spi-dw-dma: fix print error log when wait finish transaction If an error occurs, the device may not have a current message. In this case, the system will crash. In this case, it's better to use dev from the struct ctlr (struct spi_controller*).


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock Take and hold kvm->lock for before checking sev_guest() in sev_mem_enc_register_region(), as sev_guest() isn't stable unless kvm->lock is held (or KVM can guarantee KVM_SEV_INIT{2} has completed and can't rollack state). If KVM_SEV_INIT{2} fails, KVM can end up trying to add to a not-yet-initialized sev->regions_list, e.g. triggering a #GP Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 110 UID: 0 PID: 72717 Comm: syz.15.11462 Tainted: G U W O 6.16.0-smp-DEV #1 NONE Tainted: [U]=USER, [W]=WARN, [O]=OOT_MODULE Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.52.0-0 10/28/2024 RIP: 0010:sev_mem_enc_register_region+0x3f0/0x4f0 ../include/linux/list.h:83 Code: <41> 80 3c 04 00 74 08 4c 89 ff e8 f1 c7 a2 00 49 39 ed 0f 84 c6 00 RSP: 0018:ffff88838647fbb8 EFLAGS: 00010256 RAX: dffffc0000000000 RBX: 1ffff92015cf1e0b RCX: dffffc0000000000 RDX: 0000000000000000 RSI: 0000000000001000 RDI: ffff888367870000 RBP: ffffc900ae78f050 R08: ffffea000d9e0007 R09: 1ffffd4001b3c000 R10: dffffc0000000000 R11: fffff94001b3c001 R12: 0000000000000000 R13: ffff8982ab0bde00 R14: ffffc900ae78f058 R15: 0000000000000000 FS: 00007f34e9dc66c0(0000) GS:ffff89ee64d33000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fe180adef98 CR3: 000000047210e000 CR4: 0000000000350ef0 Call Trace: <TASK> kvm_arch_vm_ioctl+0xa72/0x1240 ../arch/x86/kvm/x86.c:7371 kvm_vm_ioctl+0x649/0x990 ../virt/kvm/kvm_main.c:5363 __se_sys_ioctl+0x101/0x170 ../fs/ioctl.c:51 do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x6f/0x1f0 ../arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7f34e9f7e9a9 Code: <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f34e9dc6038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007f34ea1a6080 RCX: 00007f34e9f7e9a9 RDX: 0000200000000280 RSI: 000000008010aebb RDI: 0000000000000007 RBP: 00007f34ea000d69 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 0000000000000000 R14: 00007f34ea1a6080 R15: 00007ffce77197a8 </TASK> with a syzlang reproducer that looks like: syz_kvm_add_vcpu$x86(0x0, &(0x7f0000000040)={0x0, &(0x7f0000000180)=ANY=[], 0x70}) (async) syz_kvm_add_vcpu$x86(0x0, &(0x7f0000000080)={0x0, &(0x7f0000000180)=ANY=[@ANYBLOB="..."], 0x4f}) (async) r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000200), 0x0, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r2 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000240), 0x0, 0x0) r3 = ioctl$KVM_CREATE_VM(r2, 0xae01, 0x0) ioctl$KVM_SET_CLOCK(r3, 0xc008aeba, &(0x7f0000000040)={0x1, 0x8, 0x0, 0x5625e9b0}) (async) ioctl$KVM_SET_PIT2(r3, 0x8010aebb, &(0x7f0000000280)={[...], 0x5}) (async) ioctl$KVM_SET_PIT2(r1, 0x4070aea0, 0x0) (async) r4 = ioctl$KVM_CREATE_VM(0xffffffffffffffff, 0xae01, 0x0) openat$kvm(0xffffffffffffff9c, 0x0, 0x0, 0x0) (async) ioctl$KVM_SET_USER_MEMORY_REGION(r4, 0x4020ae46, &(0x7f0000000400)={0x0, 0x0, 0x0, 0x2000, &(0x7f0000001000/0x2000)=nil}) (async) r5 = ioctl$KVM_CREATE_VCPU(r4, 0xae41, 0x2) close(r0) (async) openat$kvm(0xffffffffffffff9c, &(0x7f0000000000), 0x8000, 0x0) (async) ioctl$KVM_SET_GUEST_DEBUG(r5, 0x4048ae9b, &(0x7f0000000300)={0x4376ea830d46549b, 0x0, [0x46, 0x0, 0x0, 0x0, 0x0, 0x1000]}) (async) ioctl$KVM_RUN(r5, 0xae80, 0x0) Opportunistically use guard() to avoid having to define a new error label and goto usage.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU Reject synchronizing vCPU state to its associated VMSA if the vCPU has already been launched, i.e. if the VMSA has already been encrypted. On a host with SNP enabled, accessing guest-private memory generates an RMP #PF and panics the host. BUG: unable to handle page fault for address: ff1276cbfdf36000 #PF: supervisor write access in kernel mode #PF: error_code(0x80000003) - RMP violation PGD 5a31801067 P4D 5a31802067 PUD 40ccfb5063 PMD 40e5954063 PTE 80000040fdf36163 SEV-SNP: PFN 0x40fdf36, RMP entry: [0x6010fffffffff001 - 0x000000000000001f] Oops: Oops: 0003 [#1] SMP NOPTI CPU: 33 UID: 0 PID: 996180 Comm: qemu-system-x86 Tainted: G OE Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE Hardware name: Dell Inc. PowerEdge R7625/0H1TJT, BIOS 1.5.8 07/21/2023 RIP: 0010:sev_es_sync_vmsa+0x54/0x4c0 [kvm_amd] Call Trace: <TASK> snp_launch_update_vmsa+0x19d/0x290 [kvm_amd] snp_launch_finish+0xb6/0x380 [kvm_amd] sev_mem_enc_ioctl+0x14e/0x720 [kvm_amd] kvm_arch_vm_ioctl+0x837/0xcf0 [kvm] kvm_vm_ioctl+0x3fd/0xcc0 [kvm] __x64_sys_ioctl+0xa3/0x100 x64_sys_call+0xfe0/0x2350 do_syscall_64+0x81/0x10f0 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7ffff673287d </TASK> Note, the KVM flaw has been present since commit ad73109ae7ec ("KVM: SVM: Provide support to launch and run an SEV-ES guest"), but has only been actively dangerous for the host since SNP support was added. With SEV-ES, KVM would "just" clobber guest state, which is totally fine from a host kernel perspective since userspace can clobber guest state any time before sev_launch_update_vmsa().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfrm: clear trailing padding in build_polexpire() build_expire() clears the trailing padding bytes of struct xfrm_user_expire after setting the hard field via memset_after(), but the analogous function build_polexpire() does not do this for struct xfrm_user_polexpire. The padding bytes after the __u8 hard field are left uninitialized from the heap allocation, and are then sent to userspace via netlink multicast to XFRMNLGRP_EXPIRE listeners, leaking kernel heap memory contents. Add the missing memset_after() call, matching build_expire().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: fix use-after-free in timeout object destroy nft_ct_timeout_obj_destroy() frees the timeout object with kfree() immediately after nf_ct_untimeout(), without waiting for an RCU grace period. Concurrent packet processing on other CPUs may still hold RCU-protected references to the timeout object obtained via rcu_dereference() in nf_ct_timeout_data(). Add an rcu_head to struct nf_ct_timeout and use kfree_rcu() to defer freeing until after an RCU grace period, matching the approach already used in nfnetlink_cttimeout.c. KASAN report: BUG: KASAN: slab-use-after-free in nf_conntrack_tcp_packet+0x1381/0x29d0 Read of size 4 at addr ffff8881035fe19c by task exploit/80 Call Trace: nf_conntrack_tcp_packet+0x1381/0x29d0 nf_conntrack_in+0x612/0x8b0 nf_hook_slow+0x70/0x100 __ip_local_out+0x1b2/0x210 tcp_sendmsg_locked+0x722/0x1580 __sys_sendto+0x2d8/0x320 Allocated by task 75: nft_ct_timeout_obj_init+0xf6/0x290 nft_obj_init+0x107/0x1b0 nf_tables_newobj+0x680/0x9c0 nfnetlink_rcv_batch+0xc29/0xe00 Freed by task 26: nft_obj_destroy+0x3f/0xa0 nf_tables_trans_destroy_work+0x51c/0x5c0 process_one_work+0x2c4/0x5a0


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() Reject rt match rules whose addrnr exceeds IP6T_RT_HOPS. rt_mt6() expects addrnr to stay within the bounds of rtinfo->addrs[]. Validate addrnr during rule installation so malformed rules are rejected before the match logic can use an out-of-range value.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: flowlabel: defer exclusive option free until RCU teardown `ip6fl_seq_show()` walks the global flowlabel hash under the seq-file RCU read-side lock and prints `fl->opt->opt_nflen` when an option block is present. Exclusive flowlabels currently free `fl->opt` as soon as `fl->users` drops to zero in `fl_release()`. However, the surrounding `struct ip6_flowlabel` remains visible in the global hash table until later garbage collection removes it and `fl_free_rcu()` finally tears it down. A concurrent `/proc/net/ip6_flowlabel` reader can therefore race that early `kfree()` and dereference freed option state, triggering a crash in `ip6fl_seq_show()`. Fix this by keeping `fl->opt` alive until `fl_free_rcu()`. That matches the lifetime already required for the enclosing flowlabel while readers can still reach it under RCU.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a label to signify the start of the code where a request can be replayed if necessary. However, some of these places were missing the necessary reinitializations of certain local variables before replay. This change makes sure that these variables get initialized after the label.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: validate ND option lengths br_nd_send() walks ND options according to option-provided lengths. A malformed option can make the parser advance beyond the computed option span or use a too-short source LLADDR option payload. Validate option lengths against the remaining NS option area before advancing, and only read source LLADDR when the option is large enough for an Ethernet address.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: ulpi: fix double free in ulpi_register_interface() error path When device_register() fails, ulpi_register() calls put_device() on ulpi->dev. The device release callback ulpi_dev_release() drops the OF node reference and frees ulpi, but the current error path in ulpi_register_interface() then calls kfree(ulpi) again, causing a double free. Let put_device() handle the cleanup through ulpi_dev_release() and avoid freeing ulpi again in ulpi_register_interface().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: fix race conditions in sco_sock_connect() sco_sock_connect() checks sk_state and sk_type without holding the socket lock. Two concurrent connect() syscalls on the same socket can both pass the check and enter sco_connect(), leading to use-after-free. The buggy scenario involves three participants and was confirmed with additional logging instrumentation: Thread A (connect): HCI disconnect: Thread B (connect): sco_sock_connect(sk) sco_sock_connect(sk) sk_state==BT_OPEN sk_state==BT_OPEN (pass, no lock) (pass, no lock) sco_connect(sk): sco_connect(sk): hci_dev_lock hci_dev_lock hci_connect_sco <- blocked -> hcon1 sco_conn_add->conn1 lock_sock(sk) sco_chan_add: conn1->sk = sk sk->conn = conn1 sk_state=BT_CONNECT release_sock hci_dev_unlock hci_dev_lock sco_conn_del: lock_sock(sk) sco_chan_del: sk->conn=NULL conn1->sk=NULL sk_state= BT_CLOSED SOCK_ZAPPED release_sock hci_dev_unlock (unblocked) hci_connect_sco -> hcon2 sco_conn_add -> conn2 lock_sock(sk) sco_chan_add: sk->conn=conn2 sk_state= BT_CONNECT // zombie sk! release_sock hci_dev_unlock Thread B revives a BT_CLOSED + SOCK_ZAPPED socket back to BT_CONNECT. Subsequent cleanup triggers double sock_put() and use-after-free. Meanwhile conn1 is leaked as it was orphaned when sco_conn_del() cleared the association. Fix this by: - Moving lock_sock() before the sk_state/sk_type checks in sco_sock_connect() to serialize concurrent connect attempts - Fixing the sk_type != SOCK_SEQPACKET check to actually return the error instead of just assigning it - Adding a state re-check in sco_connect() after lock_sock() to catch state changes during the window between the locks - Adding sco_pi(sk)->conn check in sco_chan_add() to prevent double-attach of a socket to multiple connections - Adding hci_conn_drop() on sco_chan_add failure to prevent HCI connection leaks


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject immediate NF_QUEUE verdict nft_queue is always used from userspace nftables to deliver the NF_QUEUE verdict. Immediately emitting an NF_QUEUE verdict is never used by the userspace nft tools, so reject immediate NF_QUEUE verdicts. The arp family does not provide queue support, but such an immediate verdict is still reachable. Globally reject NF_QUEUE immediate verdicts to address this issue.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: ensure names are nul-terminated Reject names that lack a \0 character before feeding them to functions that expect c-strings. Fixes tag is the most recent commit that needs this change.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak When building netlink messages, tc_chain_fill_node() never initializes the tcm_info field of struct tcmsg. Since the allocation is not zeroed, kernel heap memory is leaked to userspace through this 4-byte field. The fix simply zeroes tcm_info alongside the other fields that are already initialized.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: use skb_header_pointer() for TCPv4 GSO frag_off check Syzbot reported a KMSAN uninit-value warning in gso_features_check() called from netif_skb_features() [1]. gso_features_check() reads iph->frag_off to decide whether to clear mangleid_features. Accessing the IPv4 header via ip_hdr()/inner_ip_hdr() can rely on skb header offsets that are not always safe for direct dereference on packets injected from PF_PACKET paths. Use skb_header_pointer() for the TCPv4 frag_off check so the header read is robust whether data is already linear or needs copying. [1] https://syzkaller.appspot.com/bug?extid=1543a7d954d9c6d00407


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure Presently, if the force feedback initialisation fails when probing the Logitech G920 Driving Force Racing Wheel for Xbox One, an error number will be returned and propagated before the userspace infrastructure (sysfs and /dev/input) has been torn down. If userspace ignores the errors and continues to use its references to these dangling entities, a UAF will promptly follow. We have 2 options; continue to return the error, but ensure that all of the infrastructure is torn down accordingly or continue to treat this condition as a warning by emitting the message but returning success. It is thought that the original author's intention was to emit the warning but keep the device functional, less the force feedback feature, so let's go with that.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Fix minimum RX size check for decryption The check for the minimum receive buffer size did not take the tag size into account during decryption. Fix this by adding the required extra length.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue->qdisc); This code can lead to an out-of-bounds access of the dev->_tx[] array when is_input is true. In such a case, the packet is on the RX path and skb->queue_mapping contains the RX queue index of the ingress device. If the ingress device has more RX queues than the egress device (dev) has TX queues, skb_get_queue_mapping(skb) will exceed dev->num_tx_queues. Add a check to avoid this situation since skb_get_tx_queue() does not clamp the index. This issue has also revealed that per queue visibility cannot be accurate and will be replaced later as a new feature. While at it, add missing lock around qdisc_qstats_qlen_backlog(). The function __ioam6_fill_trace_data() is called from both softirq and process contexts, hence the use of spin_lock_bh() here.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() We need to check __in6_dev_get() for possible NULL value, as suggested by Yiming Qian. Also add skb_dst_dev_rcu() instead of skb_dst_dev(), and two missing READ_ONCE(). Note that @dev can't be NULL.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., "/"), the current logic attempts to check *(cursor2 - 1) before cursor2 has advanced. This results in an out-of-bounds read. This patch adds an early exit check after stripping prepended delimiters. If no path content remains, the function returns NULL. The bug was identified via manual audit and verified using a standalone test case compiled with AddressSanitizer, which triggered a SEGV on affected inputs.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: annotate data-races around hdev->req_status __hci_cmd_sync_sk() sets hdev->req_status under hdev->req_lock: hdev->req_status = HCI_REQ_PEND; However, several other functions read or write hdev->req_status without holding any lock: - hci_send_cmd_sync() reads req_status in hci_cmd_work (workqueue) - hci_cmd_sync_complete() reads/writes from HCI event completion - hci_cmd_sync_cancel() / hci_cmd_sync_cancel_sync() read/write - hci_abort_conn() reads in connection abort path Since __hci_cmd_sync_sk() runs on hdev->req_workqueue while hci_send_cmd_sync() runs on hdev->workqueue, these are different workqueues that can execute concurrently on different CPUs. The plain C accesses constitute a data race. Add READ_ONCE()/WRITE_ONCE() annotations on all concurrent accesses to hdev->req_status to prevent potential compiler optimizations that could affect correctness (e.g., load fusing in the wait_event condition or store reordering).


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfs: fix freemap adjustments when adding xattrs to leaf blocks xfs/592 and xfs/794 both trip this assertion in the leaf block freemap adjustment code after ~20 minutes of running on my test VMs: ASSERT(ichdr->firstused >= ichdr->count * sizeof(xfs_attr_leaf_entry_t) + xfs_attr3_leaf_hdr_size(leaf)); Upon enabling quite a lot more debugging code, I narrowed this down to fsstress trying to set a local extended attribute with namelen=3 and valuelen=71. This results in an entry size of 80 bytes. At the start of xfs_attr3_leaf_add_work, the freemap looks like this: i 0 base 448 size 0 rhs 448 count 46 i 1 base 388 size 132 rhs 448 count 46 i 2 base 2120 size 4 rhs 448 count 46 firstused = 520 where "rhs" is the first byte past the end of the leaf entry array. This is inconsistent -- the entries array ends at byte 448, but freemap[1] says there's free space starting at byte 388! By the end of the function, the freemap is in worse shape: i 0 base 456 size 0 rhs 456 count 47 i 1 base 388 size 52 rhs 456 count 47 i 2 base 2120 size 4 rhs 456 count 47 firstused = 440 Important note: 388 is not aligned with the entries array element size of 8 bytes. Based on the incorrect freemap, the name area starts at byte 440, which is below the end of the entries array! That's why the assertion triggers and the filesystem shuts down. How did we end up here? First, recall from the previous patch that the freemap array in an xattr leaf block is not intended to be a comprehensive map of all free space in the leaf block. In other words, it's perfectly legal to have a leaf block with: * 376 bytes in use by the entries array * freemap[0] has [base = 376, size = 8] * freemap[1] has [base = 388, size = 1500] * the space between 376 and 388 is free, but the freemap stopped tracking that some time ago If we add one xattr, the entries array grows to 384 bytes, and freemap[0] becomes [base = 384, size = 0]. So far, so good. But if we add a second xattr, the entries array grows to 392 bytes, and freemap[0] gets pushed up to [base = 392, size = 0]. This is bad, because freemap[1] hasn't been updated, and now the entries array and the free space claim the same space. The fix here is to adjust all freemap entries so that none of them collide with the entries array. Note that this fix relies on commit 2a2b5932db6758 ("xfs: fix attr leaf header freemap.size underflow") and the previous patch that resets zero length freemap entries to have base = 0.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: EFI/CPER: don't dump the entire memory region The current logic at cper_print_fw_err() doesn't check if the error record length is big enough to handle offset. On a bad firmware, if the ofset is above the actual record, length -= offset will underflow, making it dump the entire memory. The end result can be: - the logic taking a lot of time dumping large regions of memory; - data disclosure due to the memory dumps; - an OOPS, if it tries to dump an unmapped memory region. Fix it by checking if the section length is too small before doing a hex dump. [ rjw: Subject tweaks ]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfs: delete attr leaf freemap entries when empty Back in commit 2a2b5932db6758 ("xfs: fix attr leaf header freemap.size underflow"), Brian Foster observed that it's possible for a small freemap at the end of the end of the xattr entries array to experience a size underflow when subtracting the space consumed by an expansion of the entries array. There are only three freemap entries, which means that it is not a complete index of all free space in the leaf block. This code can leave behind a zero-length freemap entry with a nonzero base. Subsequent setxattr operations can increase the base up to the point that it overlaps with another freemap entry. This isn't in and of itself a problem because the code in _leaf_add that finds free space ignores any freemap entry with zero size. However, there's another bug in the freemap update code in _leaf_add, which is that it fails to update a freemap entry that begins midway through the xattr entry that was just appended to the array. That can result in the freemap containing two entries with the same base but different sizes (0 for the "pushed-up" entry, nonzero for the entry that's actually tracking free space). A subsequent _leaf_add can then allocate xattr namevalue entries on top of the entries array, leading to data loss. But fixing that is for later. For now, eliminate the possibility of confusion by zeroing out the base of any freemap entry that has zero size. Because the freemap is not intended to be a complete index of free space, a subsequent failure to find any free space for a new xattr will trigger block compaction, which regenerates the freemap. It looks like this bug has been in the codebase for quite a long time.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is already visible from TCP ehash table and other cpus might use it. Since newinet->pinet6 is still pointing to the listener ipv6_pinfo bad things can happen as syzbot found. Move the problematic code in tcp_v6_mapped_child_init() and call this new helper from tcp_v4_syn_recv_sock() before the ehash insertion. This allows the removal of one tcp_sync_mss(), since tcp_v4_syn_recv_sock() will call it with the correct context.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: smb: client: prevent races in ->query_interfaces() It was possible for two query interface works to be concurrently trying to update the interfaces. Prevent this by checking and updating iface_last_update under iface_lock.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent possible UaF in addrconf_permanent_addr() The mentioned helper try to warn the user about an exceptional condition, but the message is delivered too late, accessing the ipv6 after its possible deletion. Reorder the statement to avoid the possible UaF; while at it, place the warning outside the idev->lock as it needs no protection.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix event ring index not programmed for IPA v5.0+ For IPA v5.0+, the event ring index field moved from CH_C_CNTXT_0 to CH_C_CNTXT_1. The v5.0 register definition intended to define this field in the CH_C_CNTXT_1 fmask array but used the old identifier of ERINDEX instead of CH_ERINDEX. Without a valid event ring, GSI channels could never signal transfer completions. This caused gsi_channel_trans_quiesce() to block forever in wait_for_completion(). At least for IPA v5.2 this resolves an issue seen where runtime suspend, system suspend, and remoteproc stop all hanged forever. It also meant the IPA data path was completely non functional.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_monmap_decode() This patch fixes unnecessary implicit conversions that change signedness of blob_len and num_mon in ceph_monmap_decode(). Currently blob_len and num_mon are (signed) int variables. They are used to hold values that are always non-negative and get assigned in ceph_decode_32_safe(), which is meant to assign u32 values. Both variables are subsequently used as unsigned values, and the value of num_mon is further assigned to monmap->num_mon, which is of type u32. Therefore, both variables should be of type u32. This is especially relevant for num_mon. If the value read from the incoming message is very large, it is interpreted as a negative value, and the check for num_mon > CEPH_MAX_MON does not catch it. This leads to the attempt to allocate a very large chunk of memory for monmap, which will most likely fail. In this case, an unnecessary attempt to allocate memory is performed, and -ENOMEM is returned instead of -EINVAL.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Decrement re_receiving on the early exit paths In the event that rpcrdma_post_recvs() fails to create a work request (due to memory allocation failure, say) or otherwise exits early, we should decrement ep->re_receiving before returning. Otherwise we will hang in rpcrdma_xprt_drain() as re_receiving will never reach zero and the completion will never be triggered. On a system with high memory pressure, this can appear as the following hung task: INFO: task kworker/u385:17:8393 blocked for more than 122 seconds. Tainted: G S E 6.19.0 #3 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kworker/u385:17 state:D stack:0 pid:8393 tgid:8393 ppid:2 task_flags:0x4248060 flags:0x00080000 Workqueue: xprtiod xprt_autoclose [sunrpc] Call Trace: <TASK> __schedule+0x48b/0x18b0 ? ib_post_send_mad+0x247/0xae0 [ib_core] schedule+0x27/0xf0 schedule_timeout+0x104/0x110 __wait_for_common+0x98/0x180 ? __pfx_schedule_timeout+0x10/0x10 wait_for_completion+0x24/0x40 rpcrdma_xprt_disconnect+0x444/0x460 [rpcrdma] xprt_rdma_close+0x12/0x40 [rpcrdma] xprt_autoclose+0x5f/0x120 [sunrpc] process_one_work+0x191/0x3e0 worker_thread+0x2e3/0x420 ? __pfx_worker_thread+0x10/0x10 kthread+0x10d/0x230 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x273/0x2b0 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registration per node Current code does no bound checking on the number of servers added per node. A malicious client can flood NEW_SERVER messages and exhaust memory. Fix this issue by limiting the maximum number of server registrations to 256 per node. If the NEW_SERVER message is received for an old port, then don't restrict it as it will get replaced. While at it, also rate limit the error messages in the failure path of qrtr_ns_worker(). Note that the limit of 256 is chosen based on the current platform requirements. If requirement changes in the future, this limit can be increased.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: openvswitch: cap upcall PID array size and pre-size vport replies The vport netlink reply helpers allocate a fixed-size skb with nlmsg_new(NLMSG_DEFAULT_SIZE, ...) but serialize the full upcall PID array via ovs_vport_get_upcall_portids(). Since ovs_vport_set_upcall_portids() accepts any non-zero multiple of sizeof(u32) with no upper bound, a CAP_NET_ADMIN user can install a PID array large enough to overflow the reply buffer, causing nla_put() to fail with -EMSGSIZE and hitting BUG_ON(err < 0). On systems with unprivileged user namespaces enabled (e.g., Ubuntu default), this is reachable via unshare -Urn since OVS vport mutation operations use GENL_UNS_ADMIN_PERM. kernel BUG at net/openvswitch/datapath.c:2414! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 1 UID: 0 PID: 65 Comm: poc Not tainted 7.0.0-rc7-00195-geb216e422044 #1 RIP: 0010:ovs_vport_cmd_set+0x34c/0x400 Call Trace: <TASK> genl_family_rcv_msg_doit (net/netlink/genetlink.c:1116) genl_rcv_msg (net/netlink/genetlink.c:1194) netlink_rcv_skb (net/netlink/af_netlink.c:2550) genl_rcv (net/netlink/genetlink.c:1219) netlink_unicast (net/netlink/af_netlink.c:1344) netlink_sendmsg (net/netlink/af_netlink.c:1894) __sys_sendto (net/socket.c:2206) __x64_sys_sendto (net/socket.c:2209) do_syscall_64 (arch/x86/entry/syscall_64.c:63) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) </TASK> Kernel panic - not syncing: Fatal exception Reject attempts to set more PIDs than nr_cpu_ids in ovs_vport_set_upcall_portids(), and pre-compute the worst-case reply size in ovs_vport_cmd_msg_size() based on that bound, similar to the existing ovs_dp_cmd_msg_size(). nr_cpu_ids matches the cap already used by the per-CPU dispatch configuration on the datapath side (ovs_dp_cmd_fill_info() serialises at most nr_cpu_ids PIDs), so the two sides stay consistent.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO nf_osf_match_one() computes ctx->window % f->wss.val in the OSF_WSS_MODULO branch with no guard for f->wss.val == 0. A CAP_NET_ADMIN user can add such a fingerprint via nfnetlink; a subsequent matching TCP SYN divides by zero and panics the kernel. Reject the bogus fingerprint in nfnl_osf_add_callback() above the per-option for-loop. f->wss is per-fingerprint, not per-option, so the check must run regardless of f->opt_num (including 0). Also reject wss.wc >= OSF_WSS_MAX; nf_osf_match_one() already treats that as "should not happen". Crash: Oops: divide error: 0000 [#1] SMP KASAN NOPTI RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98) Call Trace: <IRQ> nf_osf_match (net/netfilter/nfnetlink_osf.c:220) xt_osf_match_packet (net/netfilter/xt_osf.c:32) ipt_do_table (net/ipv4/netfilter/ip_tables.c:348) nf_hook_slow (net/netfilter/core.c:622) ip_local_deliver (net/ipv4/ip_input.c:265) ip_rcv (include/linux/skbuff.h:1162) __netif_receive_skb_one_core (net/core/dev.c:6181) process_backlog (net/core/dev.c:6642) __napi_poll (net/core/dev.c:7710) net_rx_action (net/core/dev.c:7945) handle_softirqs (kernel/softirq.c:622)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Flush cache for PASID table before using it When writing the address of a freshly allocated zero-initialized PASID table to a PASID directory entry, do that after the CPU cache flush for this PASID table, not before it, to avoid the time window when this PASID table may be already used by non-coherent IOMMU hardware while its contents in RAM is still some random old data, not zero-initialized.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths The gssx_dec_ctx(), gssx_dec_status(), and gssx_dec_name() functions allocate memory via gssx_dec_buffer(), which calls kmemdup(). When a subsequent decode operation fails, these functions return immediately without freeing previously allocated buffers, causing memory leaks. The leak in gssx_dec_ctx() is particularly relevant because the caller (gssp_accept_sec_context_upcall) initializes several buffer length fields to non-zero values, resulting in memory allocation: struct gssx_ctx rctxh = { .exported_context_token.len = GSSX_max_output_handle_sz, .mech.len = GSS_OID_MAX_LEN, .src_name.display_name.len = GSSX_max_princ_sz, .targ_name.display_name.len = GSSX_max_princ_sz }; If, for example, gssx_dec_name() succeeds for src_name but fails for targ_name, the memory allocated for exported_context_token, mech, and src_name.display_name remains unreferenced and cannot be reclaimed. Add error handling with goto-based cleanup to free any previously allocated buffers before returning an error.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down PASID entry The Intel VT-d Scalable Mode PASID table entry consists of 512 bits (64 bytes). When tearing down an entry, the current implementation zeros the entire 64-byte structure immediately using multiple 64-bit writes. Since the IOMMU hardware may fetch these 64 bytes using multiple internal transactions (e.g., four 128-bit bursts), updating or zeroing the entire entry while it is active (P=1) risks a "torn" read. If a hardware fetch occurs simultaneously with the CPU zeroing the entry, the hardware could observe an inconsistent state, leading to unpredictable behavior or spurious faults. Follow the "Guidance to Software for Invalidations" in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake: 1. Clear only the 'Present' (P) bit of the PASID entry. 2. Use a dma_wmb() to ensure the cleared bit is visible to hardware before proceeding. 3. Execute the required invalidation sequence (PASID cache, IOTLB, and Device-TLB flush) to ensure the hardware has released all cached references. 4. Only after the flushes are complete, zero out the remaining fields of the PASID entry. Also, add a dma_wmb() in pasid_set_present() to ensure that all other fields of the PASID entry are visible to the hardware before the Present bit is set.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix oops when split header is enabled For GMAC4, when split header is enabled, in some rare cases, the hardware does not fill buf2 of the first descriptor with payload. Thus we cannot assume buf2 is always fully filled if it is not the last descriptor. Otherwise, the length of buf2 of the second descriptor will be calculated wrong and cause an oops: Unable to handle kernel paging request at virtual address ffff00019246bfc0 ... x2 : 0000000000000040 x1 : ffff00019246bfc0 x0 : ffff00009246c000 Call trace: dcache_inval_poc+0x28/0x58 (P) dma_direct_sync_single_for_cpu+0x38/0x6c __dma_sync_single_for_cpu+0x34/0x6c stmmac_napi_poll_rx+0x8f0/0xb60 __napi_poll.constprop.0+0x30/0x144 net_rx_action+0x160/0x274 handle_softirqs+0x1b8/0x1fc ... To fix this, the PL bit-field in RDES3 register is used for all descriptors, whether it is the last descriptor or not.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: gfs2: fix memory leaks in gfs2_fill_super error path Fix two memory leaks in the gfs2_fill_super() error handling path when transitioning a filesystem to read-write mode fails. First leak: kthread objects (thread_struct, task_struct, etc.) When gfs2_freeze_lock_shared() fails after init_threads() succeeds, the created kernel threads (logd and quotad) are never destroyed. This occurs because the fail_per_node label doesn't call gfs2_destroy_threads(). Second leak: quota bitmap buffer (8192 bytes) When gfs2_make_fs_rw() fails after gfs2_quota_init() succeeds but before other operations complete, the allocated quota bitmap is never freed. The fix moves thread cleanup to the fail_per_node label to handle all error paths uniformly. gfs2_destroy_threads() is safe to call unconditionally as it checks for NULL pointers. Quota cleanup is added in gfs2_make_fs_rw() to properly handle the withdrawal case where quota initialization succeeds but the filesystem is then withdrawn. Thread leak backtrace (gfs2_freeze_lock_shared failure): unreferenced object 0xffff88801d7bca80 (size 4480): copy_process+0x3a1/0x4670 kernel/fork.c:2422 kernel_clone+0xf3/0x6e0 kernel/fork.c:2779 kthread_create_on_node+0x100/0x150 kernel/kthread.c:478 init_threads+0xab/0x350 fs/gfs2/ops_fstype.c:611 gfs2_fill_super+0xe5c/0x1240 fs/gfs2/ops_fstype.c:1265 Quota leak backtrace (gfs2_make_fs_rw failure): unreferenced object 0xffff88812de7c000 (size 8192): gfs2_quota_init+0xe5/0x820 fs/gfs2/quota.c:1409 gfs2_make_fs_rw+0x7a/0xe0 fs/gfs2/super.c:149 gfs2_fill_super+0xfbb/0x1240 fs/gfs2/ops_fstype.c:1275


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path Commit 5940d1cf9f42 ("SUNRPC: Rebalance a kref in auth_gss.c") added a kref_get(&gss_auth->kref) call to balance the gss_put_auth() done in gss_release_msg(), but forgot to add a corresponding kref_put() on the error path when kstrdup_const() fails. If service_name is non-NULL and kstrdup_const() fails, the function jumps to err_put_pipe_version which calls put_pipe_version() and kfree(gss_msg), but never releases the gss_auth reference. This leads to a kref leak where the gss_auth structure is never freed. Add a forward declaration for gss_free_callback() and call kref_put() in the err_put_pipe_version error path to properly release the reference taken earlier.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix invalid deref of rawdata when export_binary is unset If the export_binary parameter is disabled on runtime, profiles that were loaded before that will still have their rawdata stored in apparmorfs, with a symbolic link to the rawdata on the policy directory. When one of those profiles are replaced, the rawdata is set to NULL, but when trying to resolve the symbolic links to rawdata for that profile, it will try to dereference profile->rawdata->name when profile->rawdata is now NULL causing an oops. Fix it by checking if rawdata is set. [ 168.653080] BUG: kernel NULL pointer dereference, address: 0000000000000088 [ 168.657420] #PF: supervisor read access in kernel mode [ 168.660619] #PF: error_code(0x0000) - not-present page [ 168.663613] PGD 0 P4D 0 [ 168.665450] Oops: Oops: 0000 [#1] SMP NOPTI [ 168.667836] CPU: 1 UID: 0 PID: 1729 Comm: ls Not tainted 6.19.0-rc7+ #3 PREEMPT(voluntary) [ 168.672308] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 168.679327] RIP: 0010:rawdata_get_link_base.isra.0+0x23/0x330 [ 168.682768] Code: 90 90 90 90 90 90 90 0f 1f 44 00 00 55 48 89 e5 41 57 41 56 41 55 41 54 53 48 83 ec 18 48 89 55 d0 48 85 ff 0f 84 e3 01 00 00 <48> 83 3c 25 88 00 00 00 00 0f 84 d4 01 00 00 49 89 f6 49 89 cc e8 [ 168.689818] RSP: 0018:ffffcdcb8200fb80 EFLAGS: 00010282 [ 168.690871] RAX: ffffffffaee74ec0 RBX: 0000000000000000 RCX: ffffffffb0120158 [ 168.692251] RDX: ffffcdcb8200fbe0 RSI: ffff88c187c9fa80 RDI: ffff88c186c98a80 [ 168.693593] RBP: ffffcdcb8200fbc0 R08: 0000000000000000 R09: 0000000000000000 [ 168.694941] R10: 0000000000000000 R11: 0000000000000000 R12: ffff88c186c98a80 [ 168.696289] R13: 00007fff005aaa20 R14: 0000000000000080 R15: ffff88c188f4fce0 [ 168.697637] FS: 0000790e81c58280(0000) GS:ffff88c20a957000(0000) knlGS:0000000000000000 [ 168.699227] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 168.700349] CR2: 0000000000000088 CR3: 000000012fd3e000 CR4: 0000000000350ef0 [ 168.701696] Call Trace: [ 168.702325] <TASK> [ 168.702995] rawdata_get_link_data+0x1c/0x30 [ 168.704145] vfs_readlink+0xd4/0x160 [ 168.705152] do_readlinkat+0x114/0x180 [ 168.706214] __x64_sys_readlink+0x1e/0x30 [ 168.708653] x64_sys_call+0x1d77/0x26b0 [ 168.709525] do_syscall_64+0x81/0x500 [ 168.710348] ? do_statx+0x72/0xb0 [ 168.711109] ? putname+0x3e/0x80 [ 168.711845] ? __x64_sys_statx+0xb7/0x100 [ 168.712711] ? x64_sys_call+0x10fc/0x26b0 [ 168.713577] ? do_syscall_64+0xbf/0x500 [ 168.714412] ? do_user_addr_fault+0x1d2/0x8d0 [ 168.715404] ? irqentry_exit+0xb2/0x740 [ 168.716359] ? exc_page_fault+0x90/0x1b0 [ 168.717307] entry_SYSCALL_64_after_hwframe+0x76/0x7e


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found If btrfs_search_slot_for_read() returns 1, it means we did not find any key greater than or equals to the key we asked for, meaning we have reached the end of the tree and therefore the path is not valid. If this happens we need to break out of the loop and stop, instead of continuing and accessing an invalid path.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfs: fix a resource leak in xfs_alloc_buftarg() In the error path, call fs_put_dax() to drop the DAX device reference.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: validate reply type before using icmp_pointers Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type. That value is outside the range covered by icmp_pointers[], which only describes the traditional ICMP types up to NR_ICMP_TYPES. Avoid consulting icmp_pointers[] for reply types outside that range, and use array_index_nospec() for the remaining in-range lookup. Normal ICMP replies keep their existing behavior unchanged.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: reject zero shift in nft_bitwise Reject zero shift operands for nft_bitwise left and right shift expressions during initialization. The carry propagation logic computes the carry from the adjacent 32-bit word using BITS_PER_TYPE(u32) - shift. A zero shift operand turns this into a 32-bit shift, which is undefined behaviour. Reject zero shift operands in the control plane, alongside the existing check for values greater than or equal to 32, so malformed rules never reach the packet path.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth message processing If a (potentially corrupted) message of type CEPH_MSG_AUTH_REPLY contains a positive value in its result field, it is treated as an error code by ceph_handle_auth_reply() and returned to handle_auth_reply(). Thereafter, an attempt is made to send the preallocated message of type CEPH_MSG_AUTH, where the returned value is interpreted as the size of the front segment to send. If the result value in the message is greater than the size of the memory buffer allocated for the front segment, an out-of-bounds access occurs, and the content of the memory region beyond this buffer is sent out. This patch fixes the issue by treating only negative values in the result field as errors. Positive values are therefore treated as success in the same way as a zero value. Additionally, a BUG_ON is added to __send_prepared_auth_request() comparing the len parameter to front_alloc_len to prevent sending the message if it exceeds the bounds of the allocation and to make it easier to catch any logic flaws leading to this.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: clamp rx length before skb_put virtbt_rx_work() calls skb_put(skb, len) where len comes directly from virtqueue_get_buf() with no validation against the buffer we posted to the device. The RX skb is allocated in virtbt_add_inbuf() and exposed to virtio as exactly 1000 bytes via sg_init_one(). Checking len against skb_tailroom(skb) is not sufficient because alloc_skb() can leave more tailroom than the 1000 bytes actually handed to the device. A malicious or buggy backend can therefore report used.len between 1001 and skb_tailroom(skb), causing skb_put() to include uninitialized kernel heap bytes that were never written by the device. The same path also accepts len == 0, in which case skb_put(skb, 0) leaves the skb empty but virtbt_rx_handle() still reads the pkt_type byte from skb->data, consuming uninitialized memory. Define VIRTBT_RX_BUF_SIZE once and reuse it in alloc_skb() and sg_init_one(), and gate virtbt_rx_work() on that same constant so the bound checked matches the buffer actually exposed to the device. Reject used.len == 0 in the same gate so an empty completion can no longer reach virtbt_rx_handle(). Use bt_dev_err_ratelimited() because the length value comes from an untrusted backend that can otherwise flood the kernel log. Same class of bug as commit c04db81cd028 ("net/9p: Fix buffer overflow in USB transport layer"), which hardened the USB 9p transport against unchecked device-reported length.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check. Fix by skipping over detached marks that are not in the current group.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix missing last_unlink_trans update when removing a directory When removing a directory we are not updating its last_unlink_trans field, which can result in incorrect fsync behaviour in case some one fsyncs the directory after it was removed because it's holding a file descriptor on it. Example scenario: mkdir /mnt/dir1 mkdir /mnt/dir1/dir2 mkdir /mnt/dir3 sync -f /mnt # Do some change to the directory and fsync it. chmod 700 /mnt/dir1 xfs_io -c fsync /mnt/dir1 # Move dir2 out of dir1 so that dir1 becomes empty. mv /mnt/dir1/dir2 /mnt/dir3/ open fd on /mnt/dir1 call rmdir(2) on path "/mnt/dir1" fsync fd <trigger power failure> When attempting to mount the filesystem, the log replay will fail with an -EIO error and dmesg/syslog has the following: [445771.626482] BTRFS info (device dm-0): first mount of filesystem 0368bbea-6c5e-44b5-b409-09abe496e650 [445771.626486] BTRFS info (device dm-0): using crc32c checksum algorithm [445771.627912] BTRFS info (device dm-0): start tree-log replay [445771.628335] page: refcount:2 mapcount:0 mapping:0000000061443ddc index:0x1d00 pfn:0x7072a5 [445771.629453] memcg:ffff89f400351b00 [445771.629892] aops:btree_aops [btrfs] ino:1 [445771.630737] flags: 0x17fffc00000402a(uptodate|lru|private|writeback|node=0|zone=2|lastcpupid=0x1ffff) [445771.632359] raw: 017fffc00000402a fffff47284d950c8 fffff472907b7c08 ffff89f458e412b8 [445771.633713] raw: 0000000000001d00 ffff89f6c51d1a90 00000002ffffffff ffff89f400351b00 [445771.635029] page dumped because: eb page dump [445771.635825] BTRFS critical (device dm-0): corrupt leaf: root=5 block=30408704 slot=10 ino=258, invalid nlink: has 2 expect no more than 1 for dir [445771.638088] BTRFS info (device dm-0): leaf 30408704 gen 10 total ptrs 17 free space 14878 owner 5 [445771.638091] BTRFS info (device dm-0): refs 4 lock_owner 0 current 3581087 [445771.638094] item 0 key (256 INODE_ITEM 0) itemoff 16123 itemsize 160 [445771.638097] inode generation 3 transid 9 size 16 nbytes 16384 [445771.638098] block group 0 mode 40755 links 1 uid 0 gid 0 [445771.638100] rdev 0 sequence 2 flags 0x0 [445771.638102] atime 1775744884.0 [445771.660056] ctime 1775744885.645502983 [445771.660058] mtime 1775744885.645502983 [445771.660060] otime 1775744884.0 [445771.660062] item 1 key (256 INODE_REF 256) itemoff 16111 itemsize 12 [445771.660064] index 0 name_len 2 [445771.660066] item 2 key (256 DIR_ITEM 1843588421) itemoff 16077 itemsize 34 [445771.660068] location key (259 1 0) type 2 [445771.660070] transid 9 data_len 0 name_len 4 [445771.660075] item 3 key (256 DIR_ITEM 2363071922) itemoff 16043 itemsize 34 [445771.660076] location key (257 1 0) type 2 [445771.660077] transid 9 data_len 0 name_len 4 [445771.660078] item 4 key (256 DIR_INDEX 2) itemoff 16009 itemsize 34 [445771.660079] location key (257 1 0) type 2 [445771.660080] transid 9 data_len 0 name_len 4 [445771.660081] item 5 key (256 DIR_INDEX 3) itemoff 15975 itemsize 34 [445771.660082] location key (259 1 0) type 2 [445771.660083] transid 9 data_len 0 name_len 4 [445771.660084] item 6 key (257 INODE_ITEM 0) itemoff 15815 itemsize 160 [445771.660086] inode generation 9 transid 9 size 8 nbytes 0 [445771.660087] block group 0 mode 40777 links 1 uid 0 gid 0 [445771.660088] rdev 0 sequence 2 flags 0x0 [445771.660089] atime 1775744885.641174097 [445771.660090] ctime 1775744885.645502983 [445771.660091] mtime 1775744885.645502983 [445771.660105] otime 1775744885.641174097 [445771.660106] item 7 key (257 INODE_REF 256) itemoff 15801 itemsize 14 [445771.660107] index 2 name_len 4 [445771.660108] item 8 key (257 DIR_ITEM 2676584006) itemoff 15767 itemsize 34 [445771.660109] location key (2 ---truncated---


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ice: fix double free in ice_sf_eth_activate() error path When auxiliary_device_add() fails, ice_sf_eth_activate() jumps to aux_dev_uninit and calls auxiliary_device_uninit(&sf_dev->adev). The device release callback ice_sf_dev_release() frees sf_dev, but the current error path falls through to sf_dev_free and calls kfree(sf_dev) again, causing a double free. Keep kfree(sf_dev) for the auxiliary_device_init() failure path, but avoid falling through to sf_dev_free after auxiliary_device_uninit().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() xfrm6_rcv_encap() performs an IPv6 route lookup when the skb does not already have a dst attached. ip6_route_input_lookup() returns a referenced dst entry even when the lookup resolves to an error route. If dst->error is set, xfrm6_rcv_encap() drops the skb without attaching the dst to the skb and without releasing the reference returned by the lookup. Repeated packets hitting this path therefore leak dst entries. Release the dst before jumping to the drop path.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset traversing all extension headers, but the result is immediately overwritten with nhoff + sizeof(_ip6h) (40 bytes), which only accounts for the IPv6 base header. This creates a desync between inner_thoff (wrong - points to extension header start) and l4proto (correct - e.g., IPPROTO_TCP), enabling transport header forgery and potential firewall bypass. This issue affects stable versions from Linux 6.2. For comparison, the normal (non-inner) IPv6 path correctly preserves ipv6_find_hdr()'s result. Removing the incorrect overwrite ensures that ipv6_find_hdr()'s calculated transport header offset is preserved, thereby fixing the desynchronization.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: procfs: fix missing RCU protection when reading real_parent in do_task_stat() When reading /proc/[pid]/stat, do_task_stat() accesses task->real_parent without proper RCU protection, which leads to: cpu 0 cpu 1 ----- ----- do_task_stat var = task->real_parent release_task call_rcu(delayed_put_task_struct) task_tgid_nr_ns(var) rcu_read_lock <--- Too late to protect task->real_parent! task_pid_ptr <--- UAF! rcu_read_unlock This patch uses task_ppid_nr_ns() instead of task_tgid_nr_ns() to add proper RCU protection for accessing task->real_parent.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power systems do not support segmentation offload when the MSS is less than 224 bytes. Attempting to send such packets causes the adapter to freeze, stopping all traffic until manually reset. Implement ndo_features_check to disable GSO for packets with small MSS values. The network stack will perform software segmentation instead. The 224-byte minimum matches ibmvnic commit <f10b09ef687f> ("ibmvnic: Enforce stronger sanity checks on GSO packets") which uses the same physical adapters in SEA configurations. The issue occurs specifically when the hardware attempts to perform segmentation (gso_segs > 1) with a small MSS. Single-segment GSO packets (gso_segs == 1) do not trigger the problematic LSO code path and are transmitted normally without segmentation. Add an ndo_features_check callback to disable GSO when MSS < 224 bytes. Also call vlan_features_check() to ensure proper handling of VLAN packets, particularly QinQ (802.1ad) configurations where the hardware parser may not support certain offload features. Validated using iptables to force small MSS values. Without the fix, the adapter freezes. With the fix, packets are segmented in software and transmission succeeds. Comprehensive regression testing completedd (MSS tests, performance, stability).


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.63.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.63.1

Ссылки
Уязвимость SUSE-SU-2026:2722-1