Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2799-1

Опубликовано: 08 июл. 2026
Источник: suse-cvrf

Описание

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP7 RT kernel was updated to fix various security issues

The following security issues were fixed:

  • CVE-2025-10263: arm64: cputype: Add C1-Ultra definitions (bsc#1266290).
  • CVE-2025-40216: io_uring/rsrc: don't rely on user vaddr alignment (bsc#1259764).
  • CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029).
  • CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668).
  • CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562).
  • CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604).
  • CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085).
  • CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392).
  • CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618).
  • CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620).
  • CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655).
  • CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825).
  • CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (bsc#1267816).
  • CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748).
  • CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798).
  • CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674).
  • CVE-2026-31500: Bluetooth: hci_sync: Remove remaining dependencies of hci_request (bsc#1262993).
  • CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072).
  • CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178).
  • CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057).
  • CVE-2026-31592: KVM: SEV: Protect all of sev_mem_enc_register_region() with kvm->lock (bsc#1263123).
  • CVE-2026-31593: KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU (bsc#1263124).
  • CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581).
  • CVE-2026-31664: xfrm: clear trailing padding in build_polexpire() (bsc#1263578).
  • CVE-2026-31665: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137).
  • CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573).
  • CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568).
  • CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560).
  • CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563).
  • CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744).
  • CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116).
  • CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880).
  • CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879).
  • CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045).
  • CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076).
  • CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145).
  • CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015).
  • CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001).
  • CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137).
  • CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930).
  • CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934).
  • CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998).
  • CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996).
  • CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993).
  • CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080).
  • CVE-2026-43053: xfs: factor out xfs_attr3_node_entry_remove (bsc#1264084).
  • CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263).
  • CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470).
  • CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228).
  • CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236).
  • CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241).
  • CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266).
  • CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230).
  • CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286).
  • CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261).
  • CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254).
  • CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231).
  • CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239).
  • CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258).
  • CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437).
  • CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561).
  • CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612).
  • CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294).
  • CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595).
  • CVE-2026-43171: EFI/CPER: don't dump the entire memory region (bsc#1264549).
  • CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603).
  • CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610).
  • CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337).
  • CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320).
  • CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444).
  • CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974).
  • CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113).
  • CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763).
  • CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103).
  • CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741).
  • CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814).
  • CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734).
  • CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143).
  • CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748).
  • CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628).
  • CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629).
  • CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008).
  • CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396).
  • CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397).
  • CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390).
  • CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734).
  • CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705).
  • CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704).
  • CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717).
  • CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895).
  • CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899).
  • CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916).
  • CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929).
  • CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933).
  • CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698).
  • CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208).
  • CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922).
  • CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700).
  • CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431).
  • CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430).
  • CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361).
  • CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427).
  • CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228).
  • CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458).
  • CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437).
  • CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591).
  • CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365).
  • CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878).
  • CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582).
  • CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369).
  • CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628).
  • CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640).
  • CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621).
  • CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847).
  • CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928).
  • CVE-2026-46150: fanotify: fix false positive on permission events.
  • CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624).
  • CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840).
  • CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903).
  • CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722).
  • CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830).
  • CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381).
  • CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717).
  • CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697).
  • CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567).
  • CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654).
  • CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635).
  • CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637).
  • CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685).
  • CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684).
  • CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1265211 bsc#1267651).
  • CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966).
  • CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937).
  • CVE-2026-46315: io_uring/waitid: clear waitid info before copying it to userspace (bsc#1267953).
  • CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022).
  • CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993).
  • CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037).
  • CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661).
  • CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660).
  • CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100).
  • CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033).
  • CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022).
  • CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137).
  • CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103).
  • CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135).
  • CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184).
  • CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195).
  • CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090).
  • CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397).
  • CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398).
  • CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314).
  • CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310).
  • CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678).
  • CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681).
  • CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418).
  • CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821).
  • CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281).
  • CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884).
  • CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574).
  • CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136).
  • CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519).
  • CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506).
  • CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059).
  • CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493).

The following non security issues were fixed:

  • accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes).
  • ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes).
  • ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes).
  • ACPI: IPMI: Fix message kref handling on dead device (git-fixes).
  • ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes).
  • ACPI: resource: Amend kernel-doc style (git-fixes).
  • agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes).
  • ALSA: aloop: Drop superfluous break (git-fixes).
  • ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes).
  • ALSA: cmipci: check snd_ctl_new1() return value (git-fixes).
  • ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git-fixes).
  • ALSA: es1938: check snd_ctl_new1() return value (git-fixes).
  • ALSA: firewire: isight: bound the sample count to the packet payload (git-fixes).
  • ALSA: gus: check snd_ctl_new1() return value (git-fixes).
  • ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes).
  • ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes).
  • ALSA: ice1712: check snd_ctl_new1() return value (git-fixes).
  • ALSA: seq: Clear variable event pointer on read (git-fixes).
  • ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes).
  • ALSA: seq: Fix partial userptr event expansion (git-fixes).
  • ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes).
  • ALSA: seq: midi: Serialize output teardown with event_input (git-fixes).
  • ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes).
  • ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes).
  • ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes).
  • ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes).
  • ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes).
  • ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes).
  • ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes).
  • ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes).
  • ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes).
  • ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes).
  • ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git-fixes).
  • ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes).
  • ASoC: cs35l56: Cleanup if component_probe fails (git-fixes).
  • ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (git-fixes).
  • ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes).
  • ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes).
  • ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git-fixes).
  • ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes).
  • ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes).
  • ASoC: meson: aiu: Validate written enum values (git-fixes).
  • ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git-fixes).
  • ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes).
  • ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes).
  • ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes).
  • ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git-fixes).
  • ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes).
  • ASoC: SOF: topology: validate vendor array size before parsing (git-fixes).
  • ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes).
  • ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git-fixes).
  • ASoC: topology: Check PCM and DAI name strings before use (git-fixes).
  • ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git-fixes).
  • batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes).
  • batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes).
  • batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes).
  • batman-adv: tp_meter: avoid window underflow (git-fixes).
  • batman-adv: tp_meter: fix fast recovery precondition (git-fixes).
  • batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes).
  • batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes).
  • batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes).
  • batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes).
  • Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes).
  • Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git-fixes).
  • Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes).
  • Bluetooth: btusb: fix use-after-free on registration failure (git-fixes).
  • Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes).
  • Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes).
  • Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git-fixes).
  • Bluetooth: hci: validate codec capability element length (git-fixes).
  • Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device (git-fixes).
  • Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable-fixes).
  • Bluetooth: vhci: validate devcoredump state before side effects (git-fixes).
  • bnxt_en: Fix NULL pointer dereference (bsc#1268307).
  • bus: mhi: ep: Add missing state_lock protection for mhi_state access (git-fixes).
  • bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes).
  • bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes).
  • char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes).
  • crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes).
  • crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes).
  • crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git-fixes).
  • crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes).
  • crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes).
  • crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes).
  • crypto: ccp - Treat zero-length cert chain as query for blob lengths (git-fixes).
  • crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes).
  • crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes).
  • crypto: drbg - Fix the fips_enabled priority boost (git-fixes).
  • crypto: ecc - Fix carry overflow in vli multiplication (git-fixes).
  • crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes).
  • crypto: hisilicon/qm - disable error report before flr (git-fixes).
  • crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git-fixes).
  • crypto: pcrypt - restore callback for non-parallel fallback (git-fixes).
  • crypto: qat - protect service table iterations with service_lock (git-fixes).
  • crypto: qat - validate RSA CRT component lengths (git-fixes).
  • crypto: rng - Free default RNG on module exit (git-fixes).
  • dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes).
  • dmaengine: Fix possible use after free (git-fixes).
  • dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes).
  • dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes).
  • dmaengine: tegra: Fix burst size calculation (git-fixes).
  • driver core: reject devices with unregistered buses (git-fixes).
  • driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git-fixes).
  • Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes).
  • drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable-fixes).
  • drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes).
  • drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes).
  • drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes).
  • drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes).
  • drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git-fixes).
  • drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes).
  • drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git-fixes).
  • drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes).
  • drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes).
  • drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes).
  • drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes).
  • drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git-fixes).
  • drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes).
  • drm/amdkfd: always resume_all after suspend_all (git-fixes).
  • drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes).
  • drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable-fixes).
  • drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes).
  • drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes).
  • drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes).
  • drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes).
  • drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes).
  • drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes).
  • drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git-fixes).
  • drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git-fixes).
  • drm/dp: Add eDP 1.5 bit definition (stable-fixes).
  • drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes).
  • drm/gpuvm: Do not prepare NULL objects (git-fixes).
  • drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git-fixes).
  • drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes).
  • drm/hyperv: use VMBUS_RING_SIZE() (git-fixes).
  • drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes).
  • drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes).
  • drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes).
  • drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes).
  • drm/imagination: Count paired job fence as dependency in prepare_job() (git-fixes).
  • drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes).
  • drm/msm/dp: fix HPD state status bit shift value (git-fixes).
  • drm/msm/dp: Fix the ISR_* enum values (git-fixes).
  • drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes).
  • drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes).
  • drm/nouveau: fix reversed error cleanup order in ucopy functions (git-fixes).
  • drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes).
  • drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes).
  • drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git-fixes).
  • drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git-fixes).
  • drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes).
  • drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git-fixes).
  • drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes).
  • drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes).
  • drm/tidss: Fix missing drm_bridge_add() call (git-fixes).
  • drm/vc4: fix krealloc() memory leak (git-fixes).
  • drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes).
  • drm/virtio: Fix driver removal with disabled KMS (git-fixes).
  • drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes).
  • drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes).
  • ethtool: provide customized dim profile management (bsc#1261256).
  • fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git-fixes).
  • fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes).
  • fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes).
  • fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git-fixes).
  • fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes).
  • fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes).
  • fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git-fixes).
  • fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes).
  • fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes).
  • fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes).
  • fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes).
  • fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git-fixes).
  • fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes).
  • fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes).
  • firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes).
  • firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes).
  • firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes).
  • firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes).
  • fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes).
  • fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes).
  • fpga: region: fix use-after-free in child_regions_with_firmware() (git-fixes).
  • gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes).
  • gpu: host1x: Allow entries in BO caches to be freed (git-fixes).
  • gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes).
  • HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes).
  • HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes).
  • HID: wacom: stop hardware after post-start probe failures (git-fixes).
  • HID: wiimote: Fix table layout and whitespace errors (git-fixes).
  • hv: utils: handle and propagate errors in kvp_register (git-fixes).
  • hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes).
  • hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes).
  • hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes).
  • hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes).
  • hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes).
  • i2c: core: fix irq domain leak on adapter registration failure (git-fixes).
  • i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes).
  • i2c: mpc: Fix timeout calculations (git-fixes).
  • i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes).
  • i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes).
  • i2c: stm32f7: truncate clock period instead of rounding it (git-fixes).
  • i2c: tegra: Fix NOIRQ suspend/resume (git-fixes).
  • i3c: master: Prevent reuse of dynamic address on device add failure (git-fixes).
  • ice: ptp: don't WARN when controlling PF is unavailable (bsc#1267251).
  • iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes).
  • iio: adc: npcm: Convert to platform remove callback returning void (stable-fixes).
  • iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes).
  • iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes).
  • iio: chemical: scd30: fix division by zero in write_raw (git-fixes).
  • iio: chemical: scd30: Use guard(mutex) to allow early returns (stable-fixes).
  • iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git-fixes).
  • iio: gyro: bmg160: wait full startup time after mode change at probe (git-fixes).
  • iio: light: opt3001: fix missing state reset on timeout (git-fixes).
  • iio: light: si1133: prevent race condition on timeout (git-fixes).
  • iio: light: si1133: reset counter to prevent race condition (git-fixes).
  • iio: light: veml6030: fix channel type when pushing events (git-fixes).
  • iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes).
  • iio: magnetometer: ak8975: fix potential kernel stack memory leak (git-fixes).
  • iio: tcs3472: power down chip on probe failure (git-fixes).
  • iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes).
  • Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes).
  • Input: elan_i2c - validate firmware size before use (stable-fixes).
  • Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable-fixes).
  • Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes).
  • Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git-fixes).
  • Input: xpad - add 'Nova 2 Lite' from GameSir (stable-fixes).
  • Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes).
  • iommu/s390: allow larger region tables (jsc#PED-15880).
  • iommu/s390: Fix memory corruption when using identity domain (jsc#PED-15880).
  • iommu/s390: handle IOAT registration based on domain (jsc#PED-15880).
  • iommu/s390: implement iommu passthrough via identity domain (jsc#PED-15880).
  • iommu/s390: set appropriate IOTA region type (jsc#PED-15880).
  • iommu/s390: support cleanup of additional table regions (jsc#PED-15880).
  • iommu/s390: support iova_to_phys for additional table regions (jsc#PED-15880).
  • iommu/s390: support map/unmap for additional table regions (jsc#PED-15880).
  • KVM: arm64: Discard PC update state on vcpu reset (git-fixes).
  • KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes).
  • KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes).
  • KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes).
  • KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes).
  • KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes).
  • KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes).
  • KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes).
  • KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes).
  • KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes).
  • KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes).
  • KVM: s390: Limit adapter indicator access to mapped page (bsc#1268159).
  • KVM: SEV: Ignore MMIO requests of length '0' (git-fixes).
  • KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes).
  • KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes).
  • KVM: SVM: check validity of VMCB controls when returning from SMM (git-fixes).
  • KVM: SVM: Don't set GIF when clearing EFER.SVME (git-fixes).
  • KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes).
  • KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes).
  • KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes).
  • KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes).
  • KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes).
  • KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes).
  • KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git-fixes).
  • KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes).
  • KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git-fixes).
  • KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes).
  • KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes).
  • KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes).
  • leds: uleds: Fix potential buffer overread (git-fixes).
  • linux/dim: move useful macros to .h file (bsc#1261256).
  • loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303).
  • loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303).
  • mailbox: mtk-adsp: fix UAF during device teardown (git-fixes).
  • media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes).
  • media: cec: seco: unregister adapter on IR probe failure (git-fixes).
  • media: cedrus: Fix failure to clean up hardware on probe failure (git-fixes).
  • media: cedrus: Fix missing cleanup in error path (git-fixes).
  • media: cedrus: skip invalid H.264 reference list entries (git-fixes).
  • media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes).
  • media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes).
  • media: pci: dm1105: Free allocated workqueue (git-fixes).
  • media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes).
  • media: v4l2-ctrls: validate HEVC active reference counts (git-fixes).
  • media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes).
  • media: vidtv: fix reference leak on failed device registration (git-fixes).
  • media: vimc: fix reference leak on failed device registration (git-fixes).
  • media: vpif_capture: fix OF node reference imbalance (git-fixes).
  • misc: fastrpc: fix DMA address corruption due to find_vma misuse (git-fixes).
  • misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes).
  • misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git-fixes).
  • misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes).
  • module: fix init_module_from_file() error handling (jsc#PED-16303).
  • module: make waiting for a concurrent module loader interruptible (jsc#PED-16303).
  • module: Split modules_install compression and in-kernel decompression (jsc#PED-16303).
  • module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303).
  • module: warn about excessively long module waits (jsc#PED-16303).
  • modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303).
  • mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git-fixes).
  • mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes).
  • mtd: rawnand: pl353: fix probe resource allocation (git-fixes).
  • mtd: slram: remove failed entries from the device list (git-fixes).
  • mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes).
  • mtd: spi-nor: swp: Improve locking user experience (git-fixes).
  • net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428).
  • net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256).
  • net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256).
  • net: mana: Add support for PF device 0x00C1 (bsc#1268237).
  • net: mana: Add support for RX CQE Coalescing (bsc#1261256).
  • net: mana: Allocate interrupt context for each EQ when creating vPort (git-fixes).
  • net: mana: Create separate EQs for each vPort (git-fixes).
  • net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes).
  • net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git-fixes).
  • net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes).
  • net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes).
  • net: mana: Optimize irq affinity for low vcpu configs (git-fixes).
  • net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes).
  • net: mana: Use GIC functions to allocate global EQs (git-fixes).
  • nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes).
  • nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes).
  • nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes).
  • of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes).
  • page_pool: Move pp_magic check into helper functions (bsc#1261562).
  • page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562).
  • platform/x86: intel-hid: Protect ACPI notify handler against recursion (git-fixes).
  • platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes).
  • PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes).
  • power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes).
  • power: supply: charger-manager: fix refcount leak in is_full_charged() (git-fixes).
  • power: supply: core: fix supplied_from allocations (git-fixes).
  • power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes).
  • powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes).
  • powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git-fixes).
  • RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes).
  • RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes).
  • rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes).
  • rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes).
  • rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes).
  • rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git-fixes).
  • rtc: mpfs: fix counter upload completion condition (git-fixes).
  • rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes).
  • s390/pci: check for relaxed translation capability (jsc#PED-15880).
  • s390/pci: Fix dev.dma_range_map missing sentinel element (jsc#PED-15880).
  • s390/pci: store DMA offset in bus_dma_region (jsc#PED-15880).
  • scripts/submit_branch: add SLE15-SP7 submission script.
  • scsi: storvsc: Replace symbolic permissions with octal (git-fixes).
  • scsi: target: Fix hexadecimal CHAP_I handling (git-fixes).
  • selftests/bpf: Add BPF_STRICT_BUILD toggle (bsc#1269617).
  • selftests/bpf: Allow test_progs to link with a partial object set (bsc#1269617).
  • selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (bsc#1269617).
  • selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (bsc#1269617).
  • selftests/bpf: Provide weak definitions for cross-test functions (bsc#1269617).
  • selftests/bpf: Skip tests whose objects were not built (bsc#1269617).
  • selftests/bpf: Tolerate benchmark build failures (bsc#1269617).
  • selftests/bpf: Tolerate BPF and skeleton generation failures (bsc#1269617).
  • selftests/bpf: Tolerate missing files during install (bsc#1269617).
  • selftests/bpf: Tolerate test file compilation failures (bsc#1269617).
  • serdev: make serdev_bus_type const (stable-fixes).
  • serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git-fixes).
  • serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git-fixes).
  • slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes).
  • soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes).
  • soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes).
  • spi: at91-usart: drop dead runtime pm support (git-fixes).
  • spi: dw: fix wrong BAUDR setting after resume (git-fixes).
  • spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes).
  • spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes).
  • spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git-fixes).
  • spi: meson-spifc: fix runtime PM leak on remove (git-fixes).
  • spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes).
  • spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes).
  • spi: xilinx: use FIFO occupancy register to determine buffer size (git-fixes).
  • Split off kABI workaround for bsc#1267458 (bsc#1267458).
  • staging: most: video: avoid double free on video register failure (git-fixes).
  • staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes).
  • thermal: hwmon: Fix critical temperature attribute removal (git-fixes).
  • thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes).
  • thunderbolt: Bound root directory content to block size (git-fixes).
  • thunderbolt: Clamp XDomain response data copy to allocation size (git-fixes).
  • thunderbolt: Limit XDomain response copy to actual frame size (git-fixes).
  • thunderbolt: Reject zero-length property entries in validator (git-fixes).
  • thunderbolt: Validate XDomain request packet size before type cast (git-fixes).
  • tpm: fix event_size output in tpm1_binary_bios_measurements_show (git-fixes).
  • tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes).
  • usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes).
  • usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes).
  • usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes).
  • usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git-fixes).
  • usb: host: max3421: Reject hub port requests for non-existent ports (git-fixes).
  • USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes).
  • USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes).
  • USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes).
  • USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes).
  • USB: serial: option: add MeiG SRM813Q (stable-fixes).
  • USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes).
  • usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes).
  • usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes).
  • usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes).
  • usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes).
  • usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes).
  • usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes).
  • usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes).
  • vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes).
  • watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199).
  • watchdog: apple: Add 'apple,t8103-wdt' compatible (git-fixes).
  • watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes).
  • watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes).
  • watchdog: unregister PM notifier on watchdog unregister (git-fixes).
  • wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes).
  • wifi: ath11k: fix warning when unbinding (git-fixes).
  • wifi: cfg80211: fix grammar in MLO group key error message (git-fixes).
  • wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes).
  • wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes).
  • wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes).
  • wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes).
  • wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes).
  • wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes).
  • wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes).
  • wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes).
  • wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes).
  • wifi: rtw88: increase TX report timeout to fix race condition (git-fixes).
  • wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes).
  • wifi: rtw89: Correct data type for scan index to avoid infinite loop (git-fixes).
  • wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git-fixes).
  • wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes).
  • wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git-fixes).
  • x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305).
  • x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305).
  • X.509: Fix validation of ASN.1 certificate header (git-fixes).

Список пакетов

SUSE Linux Enterprise Live Patching 15 SP7
kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7
cluster-md-kmp-rt-6.4.0-150700.7.62.1
dlm-kmp-rt-6.4.0-150700.7.62.1
gfs2-kmp-rt-6.4.0-150700.7.62.1
kernel-devel-rt-6.4.0-150700.7.62.1
kernel-rt-6.4.0-150700.7.62.1
kernel-rt-devel-6.4.0-150700.7.62.1
kernel-source-rt-6.4.0-150700.7.62.1
kernel-syms-rt-6.4.0-150700.7.62.1
ocfs2-kmp-rt-6.4.0-150700.7.62.1

Описание

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment There is no guaranteed alignment for user pointers, however the calculation of an offset of the first page into a folio after coalescing uses some weird bit mask logic, get rid of it.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: futex: Don't leak robust_list pointer on exec race sys_get_robust_list() and compat_get_robust_list() use ptrace_may_access() to check if the calling task is allowed to access another task's robust_list pointer. This check is racy against a concurrent exec() in the target process. During exec(), a task may transition from a non-privileged binary to a privileged one (e.g., setuid binary) and its credentials/memory mappings may change. If get_robust_list() performs ptrace_may_access() before this transition, it may erroneously allow access to sensitive information after the target becomes privileged. A racy access allows an attacker to exploit a window during which ptrace_may_access() passes before a target process transitions to a privileged state via exec(). For example, consider a non-privileged task T that is about to execute a setuid-root binary. An attacker task A calls get_robust_list(T) while T is still unprivileged. Since ptrace_may_access() checks permissions based on current credentials, it succeeds. However, if T begins exec immediately afterwards, it becomes privileged and may change its memory mappings. Because get_robust_list() proceeds to access T->robust_list without synchronizing with exec() it may read user-space pointers from a now-privileged process. This violates the intended post-exec access restrictions and could expose sensitive memory addresses or be used as a primitive in a larger exploit chain. Consequently, the race can lead to unauthorized disclosure of information across privilege boundaries and poses a potential security risk. Take a read lock on signal->exec_update_lock prior to invoking ptrace_may_access() and accessing the robust_list/compat_robust_list. This ensures that the target task's exec state remains stable during the check, allowing for consistent and synchronized validation of credentials.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Input: alps - fix use-after-free bugs caused by dev3_register_work The dev3_register_work delayed work item is initialized within alps_reconnect() and scheduled upon receipt of the first bare PS/2 packet from an external PS/2 device connected to the ALPS touchpad. During device detachment, the original implementation calls flush_workqueue() in psmouse_disconnect() to ensure completion of dev3_register_work. However, the flush_workqueue() in psmouse_disconnect() only blocks and waits for work items that were already queued to the workqueue prior to its invocation. Any work items submitted after flush_workqueue() is called are not included in the set of tasks that the flush operation awaits. This means that after flush_workqueue() has finished executing, the dev3_register_work could still be scheduled. Although the psmouse state is set to PSMOUSE_CMD_MODE in psmouse_disconnect(), the scheduling of dev3_register_work remains unaffected. The race condition can occur as follows: CPU 0 (cleanup path) | CPU 1 (delayed work) psmouse_disconnect() | psmouse_set_state() | flush_workqueue() | alps_report_bare_ps2_packet() alps_disconnect() | psmouse_queue_work() kfree(priv); // FREE | alps_register_bare_ps2_mouse() | priv = container_of(work...); // USE | priv->dev3 // USE Add disable_delayed_work_sync() in alps_disconnect() to ensure that dev3_register_work is properly canceled and prevented from executing after the alps_data structure has been deallocated. This bug is identified by static analysis.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix NULL pointer issue buffer funcs If SDMA block not enabled, buffer_funcs will not initialize, fix the null pointer issue if buffer_funcs not initialized.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_parse() can loop if a stack of two bonding devices is setup, because skb->dev always points to the hierarchy top. Add new "const struct net_device *dev" parameter to (struct header_ops)->parse() method to make sure the recursion is bounded, and that the final leaf parse method is called.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper Use expect->helper in ctnetlink and /proc to dump the helper name. Using nfct_help() without holding a reference to the master conntrack is unsafe. Use exp->master->helper in ctnetlink path if userspace does not provide an explicit helper when creating an expectation to retain the existing behaviour. The ctnetlink expectation path holds the reference on the master conntrack and nf_conntrack_expect lock and the nfnetlink glue path refers to the master ct that is attached to the skb.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: skb: fix cross-cache free of KFENCE-allocated skb head SKB_SMALL_HEAD_CACHE_SIZE is intentionally set to a non-power-of-2 value (e.g. 704 on x86_64) to avoid collisions with generic kmalloc bucket sizes. This ensures that skb_kfree_head() can reliably use skb_end_offset to distinguish skb heads allocated from skb_small_head_cache vs. generic kmalloc caches. However, when KFENCE is enabled, kfence_ksize() returns the exact requested allocation size instead of the slab bucket size. If a caller (e.g. bpf_test_init) allocates skb head data via kzalloc() and the requested size happens to equal SKB_SMALL_HEAD_CACHE_SIZE, then slab_build_skb() -> ksize() returns that exact value. After subtracting skb_shared_info overhead, skb_end_offset ends up matching SKB_SMALL_HEAD_HEADROOM, causing skb_kfree_head() to incorrectly free the object to skb_small_head_cache instead of back to the original kmalloc cache, resulting in a slab cross-cache free: kmem_cache_free(skbuff_small_head): Wrong slab cache. Expected skbuff_small_head but got kmalloc-1k Fix this by always calling kfree(head) in skb_kfree_head(). This keeps the free path generic and avoids allocator-specific misclassification for KFENCE objects.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ext4: publish jinode after initialization ext4_inode_attach_jinode() publishes ei->jinode to concurrent users. It used to set ei->jinode before jbd2_journal_init_jbd_inode(), allowing a reader to observe a non-NULL jinode with i_vfs_inode still unset. The fast commit flush path can then pass this jinode to jbd2_wait_inode_data(), which dereferences i_vfs_inode->i_mapping and may crash. Below is the crash I observe: ``` BUG: unable to handle page fault for address: 000000010beb47f4 PGD 110e51067 P4D 110e51067 PUD 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 1 UID: 0 PID: 4850 Comm: fc_fsync_bench_ Not tainted 6.18.0-00764-g795a690c06a5 #1 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.17.0-2-2 04/01/2014 RIP: 0010:xas_find_marked+0x3d/0x2e0 Code: e0 03 48 83 f8 02 0f 84 f0 01 00 00 48 8b 47 08 48 89 c3 48 39 c6 0f 82 fd 01 00 00 48 85 c9 74 3d 48 83 f9 03 77 63 4c 8b 0f <49> 8b 71 08 48 c7 47 18 00 00 00 00 48 89 f1 83 e1 03 48 83 f9 02 RSP: 0018:ffffbbee806e7bf0 EFLAGS: 00010246 RAX: 000000000010beb4 RBX: 000000000010beb4 RCX: 0000000000000003 RDX: 0000000000000001 RSI: 0000002000300000 RDI: ffffbbee806e7c10 RBP: 0000000000000001 R08: 0000002000300000 R09: 000000010beb47ec R10: ffff9ea494590090 R11: 0000000000000000 R12: 0000002000300000 R13: ffffbbee806e7c90 R14: ffff9ea494513788 R15: ffffbbee806e7c88 FS: 00007fc2f9e3e6c0(0000) GS:ffff9ea6b1444000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000000010beb47f4 CR3: 0000000119ac5000 CR4: 0000000000750ef0 PKRU: 55555554 Call Trace: <TASK> filemap_get_folios_tag+0x87/0x2a0 __filemap_fdatawait_range+0x5f/0xd0 ? srso_alias_return_thunk+0x5/0xfbef5 ? __schedule+0x3e7/0x10c0 ? srso_alias_return_thunk+0x5/0xfbef5 ? srso_alias_return_thunk+0x5/0xfbef5 ? srso_alias_return_thunk+0x5/0xfbef5 ? preempt_count_sub+0x5f/0x80 ? srso_alias_return_thunk+0x5/0xfbef5 ? cap_safe_nice+0x37/0x70 ? srso_alias_return_thunk+0x5/0xfbef5 ? preempt_count_sub+0x5f/0x80 ? srso_alias_return_thunk+0x5/0xfbef5 filemap_fdatawait_range_keep_errors+0x12/0x40 ext4_fc_commit+0x697/0x8b0 ? ext4_file_write_iter+0x64b/0x950 ? srso_alias_return_thunk+0x5/0xfbef5 ? preempt_count_sub+0x5f/0x80 ? srso_alias_return_thunk+0x5/0xfbef5 ? vfs_write+0x356/0x480 ? srso_alias_return_thunk+0x5/0xfbef5 ? preempt_count_sub+0x5f/0x80 ext4_sync_file+0xf7/0x370 do_fsync+0x3b/0x80 ? syscall_trace_enter+0x108/0x1d0 __x64_sys_fdatasync+0x16/0x20 do_syscall_64+0x62/0x2c0 entry_SYSCALL_64_after_hwframe+0x76/0x7e ... ``` Fix this by initializing the jbd2_inode first. Use smp_wmb() and WRITE_ONCE() to publish ei->jinode after initialization. Readers use READ_ONCE() to fetch the pointer.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ext4: convert inline data to extents when truncate exceeds inline size Add a check in ext4_setattr() to convert files from inline data storage to extent-based storage when truncate() grows the file size beyond the inline capacity. This prevents the filesystem from entering an inconsistent state where the inline data flag is set but the file size exceeds what can be stored inline. Without this fix, the following sequence causes a kernel BUG_ON(): 1. Mount filesystem with inode that has inline flag set and small size 2. truncate(file, 50MB) - grows size but inline flag remains set 3. sendfile() attempts to write data 4. ext4_write_inline_data() hits BUG_ON(write_size > inline_capacity) The crash occurs because ext4_write_inline_data() expects inline storage to accommodate the write, but the actual inline capacity (~60 bytes for i_block + ~96 bytes for xattrs) is far smaller than the file size and write request. The fix checks if the new size from setattr exceeds the inode's actual inline capacity (EXT4_I(inode)->i_inline_size) and converts the file to extent-based storage before proceeding with the size change. This addresses the root cause by ensuring the inline data flag and file size remain consistent during truncate operations.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfs: avoid dereferencing log items after push callbacks After xfsaild_push_item() calls iop_push(), the log item may have been freed if the AIL lock was dropped during the push. Background inode reclaim or the dquot shrinker can free the log item while the AIL lock is not held, and the tracepoints in the switch statement dereference the log item after iop_push() returns. Fix this by capturing the log item type, flags, and LSN before calling xfsaild_push_item(), and introducing a new xfs_ail_push_class trace event class that takes these pre-captured values and the ailp pointer instead of the log item pointer.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: prevent immediate PASID reuse case PASID resue could cause interrupt issue when process immediately runs into hw state left by previous process exited with the same PASID, it's possible that page faults are still pending in the IH ring buffer when the process exits and frees up its PASID. To prevent the case, it uses idr cyclic allocator same as kernel pid's. (cherry picked from commit 8f1de51f49be692de137c8525106e0fce2d1912d)


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() On arm64 server, we found folio that get from migration entry isn't locked in softleaf_to_folio(). This issue triggers when mTHP splitting and zap_nonpresent_ptes() races, and the root cause is lack of memory barrier in softleaf_to_folio(). The race is as follows: CPU0 CPU1 deferred_split_scan() zap_nonpresent_ptes() lock folio split_folio() unmap_folio() change ptes to migration entries __split_folio_to_order() softleaf_to_folio() set flags(including PG_locked) for tail pages folio = pfn_folio(softleaf_to_pfn(entry)) smp_wmb() VM_WARN_ON_ONCE(!folio_test_locked(folio)) prep_compound_page() for tail pages In __split_folio_to_order(), smp_wmb() guarantees page flags of tail pages are visible before the tail page becomes non-compound. smp_wmb() should be paired with smp_rmb() in softleaf_to_folio(), which is missed. As a result, if zap_nonpresent_ptes() accesses migration entry that stores tail pfn, softleaf_to_folio() may see the updated compound_head of tail page before page->flags. This issue will trigger VM_WARN_ON_ONCE() in pfn_swap_entry_folio() because of the race between folio split and zap_nonpresent_ptes() leading to a folio incorrectly undergoing modification without a folio lock being held. This is a BUG_ON() before commit 93976a20345b ("mm: eliminate further swapops predicates"), which in merged in v6.19-rc1. To fix it, add missing smp_rmb() if the softleaf entry is migration entry in softleaf_to_folio() and softleaf_to_page(). [tujinjiang@huawei.com: update function name and comments]


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false A UAF issue occurs when the virtio_net driver is configured with napi_tx=N and the device's IFF_XMIT_DST_RELEASE flag is cleared (e.g., during the configuration of tc route filter rules). When IFF_XMIT_DST_RELEASE is removed from the net_device, the network stack expects the driver to hold the reference to skb->dst until the packet is fully transmitted and freed. In virtio_net with napi_tx=N, skbs may remain in the virtio transmit ring for an extended period. If the network namespace is destroyed while these skbs are still pending, the corresponding dst_ops structure has freed. When a subsequent packet is transmitted, free_old_xmit() is triggered to clean up old skbs. It then calls dst_release() on the skb associated with the stale dst_entry. Since the dst_ops (referenced by the dst_entry) has already been freed, a UAF kernel paging request occurs. fix it by adds skb_dst_drop(skb) in start_xmit to explicitly release the dst reference before the skb is queued in virtio_net. Call Trace: Unable to handle kernel paging request at virtual address ffff80007e150000 CPU: 2 UID: 0 PID: 6236 Comm: ping Kdump: loaded Not tainted 7.0.0-rc1+ #6 PREEMPT ... percpu_counter_add_batch+0x3c/0x158 lib/percpu_counter.c:98 (P) dst_release+0xe0/0x110 net/core/dst.c:177 skb_release_head_state+0xe8/0x108 net/core/skbuff.c:1177 sk_skb_reason_drop+0x54/0x2d8 net/core/skbuff.c:1255 dev_kfree_skb_any_reason+0x64/0x78 net/core/dev.c:3469 napi_consume_skb+0x1c4/0x3a0 net/core/skbuff.c:1527 __free_old_xmit+0x164/0x230 drivers/net/virtio_net.c:611 [virtio_net] free_old_xmit drivers/net/virtio_net.c:1081 [virtio_net] start_xmit+0x7c/0x530 drivers/net/virtio_net.c:3329 [virtio_net] ... Reproduction Steps: NETDEV="enp3s0" config_qdisc_route_filter() { tc qdisc del dev $NETDEV root tc qdisc add dev $NETDEV root handle 1: prio tc filter add dev $NETDEV parent 1:0 \ protocol ip prio 100 route to 100 flowid 1:1 ip route add 192.168.1.100/32 dev $NETDEV realm 100 } test_ns() { ip netns add testns ip link set $NETDEV netns testns ip netns exec testns ifconfig $NETDEV 10.0.32.46/24 ip netns exec testns ping -c 1 10.0.32.1 ip netns del testns } config_qdisc_route_filter test_ns sleep 2 test_ns


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Initialize free_qp completion before using it In irdma_create_qp, if ib_copy_to_udata fails, it will call irdma_destroy_qp to clean up which will attempt to wait on the free_qp completion, which is not initialized yet. Fix this by initializing the completion before the ib_copy_to_udata call.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: use netlink policy range checks Replace manual range and mask validations with netlink policy annotations in ctnetlink code paths, so that the netlink core rejects invalid values early and can generate extack errors. - CTA_PROTOINFO_TCP_STATE: reject values > TCP_CONNTRACK_SYN_SENT2 at policy level, removing the manual >= TCP_CONNTRACK_MAX check. - CTA_PROTOINFO_TCP_WSCALE_ORIGINAL/REPLY: reject values > TCP_MAX_WSCALE (14). The normal TCP option parsing path already clamps to this value, but the ctnetlink path accepted 0-255, causing undefined behavior when used as a u32 shift count. - CTA_FILTER_ORIG_FLAGS/REPLY_FLAGS: use NLA_POLICY_MASK with CTA_FILTER_F_ALL, removing the manual mask checks. - CTA_EXPECT_FLAGS: use NLA_POLICY_MASK with NF_CT_EXPECT_MASK, adding a new mask define grouping all valid expect flags. Extracted from a broader nf-next patch by Florian Westphal, scoped to ctnetlink for the fixes tree.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() l2cap_conn_del() calls cancel_delayed_work_sync() for both info_timer and id_addr_timer while holding conn->lock. However, the work functions l2cap_info_timeout() and l2cap_conn_update_id_addr() both acquire conn->lock, creating a potential AB-BA deadlock if the work is already executing when l2cap_conn_del() takes the lock. Move the work cancellations before acquiring conn->lock and use disable_delayed_work_sync() to additionally prevent the works from being rearmed after cancellation, consistent with the pattern used in hci_conn_del().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock btintel_hw_error() issues two __hci_cmd_sync() calls (HCI_OP_RESET and Intel exception-info retrieval) without holding hci_req_sync_lock(). This lets it race against hci_dev_do_close() -> btintel_shutdown_combined(), which also runs __hci_cmd_sync() under the same lock. When both paths manipulate hdev->req_status/req_rsp concurrently, the close path may free the response skb first, and the still-running hw_error path hits a slab-use-after-free in kfree_skb(). Wrap the whole recovery sequence in hci_req_sync_lock/unlock so it is serialized with every other synchronous HCI command issuer. Below is the data race report and the kasan report: BUG: data-race in __hci_cmd_sync_sk / btintel_shutdown_combined read of hdev->req_rsp at net/bluetooth/hci_sync.c:199 by task kworker/u17:1/83: __hci_cmd_sync_sk+0x12f2/0x1c30 net/bluetooth/hci_sync.c:200 __hci_cmd_sync+0x55/0x80 net/bluetooth/hci_sync.c:223 btintel_hw_error+0x114/0x670 drivers/bluetooth/btintel.c:254 hci_error_reset+0x348/0xa30 net/bluetooth/hci_core.c:1030 write/free by task ioctl/22580: btintel_shutdown_combined+0xd0/0x360 drivers/bluetooth/btintel.c:3648 hci_dev_close_sync+0x9ae/0x2c10 net/bluetooth/hci_sync.c:5246 hci_dev_do_close+0x232/0x460 net/bluetooth/hci_core.c:526 BUG: KASAN: slab-use-after-free in sk_skb_reason_drop+0x43/0x380 net/core/skbuff.c:1202 Read of size 4 at addr ffff888144a738dc by task kworker/u17:1/83: __hci_cmd_sync_sk+0x12f2/0x1c30 net/bluetooth/hci_sync.c:200 __hci_cmd_sync+0x55/0x80 net/bluetooth/hci_sync.c:223 btintel_hw_error+0x186/0x670 drivers/bluetooth/btintel.c:260


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: team: fix header_ops type confusion with non-Ethernet ports Similar to commit 950803f72547 ("bonding: fix type confusion in bond_setup_by_slave()") team has the same class of header_ops type confusion. For non-Ethernet ports, team_setup_by_port() copies port_dev->header_ops directly. When the team device later calls dev_hard_header() or dev_parse_header(), these callbacks can run with the team net_device instead of the real lower device, so netdev_priv(dev) is interpreted as the wrong private type and can crash. The syzbot report shows a crash in bond_header_create(), but the root cause is in team: the topology is gre -> bond -> team, and team calls the inherited header_ops with its own net_device instead of the lower device, so bond_header_create() receives a team device and interprets netdev_priv() as bonding private data, causing a type confusion crash. Fix this by introducing team header_ops wrappers for create/parse, selecting a team port under RCU, and calling the lower device callbacks with port->dev, so each callback always sees the correct net_device context. Also pass the selected lower device to the lower parse callback, so recursion is bounded in stacked non-Ethernet topologies and parse callbacks always run with the correct device context.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: futex: Clear stale exiting pointer in futex_lock_pi() retry path Fuzzying/stressing futexes triggered: WARNING: kernel/futex/core.c:825 at wait_for_owner_exiting+0x7a/0x80, CPU#11: futex_lock_pi_s/524 When futex_lock_pi_atomic() sees the owner is exiting, it returns -EBUSY and stores a refcounted task pointer in 'exiting'. After wait_for_owner_exiting() consumes that reference, the local pointer is never reset to nil. Upon a retry, if futex_lock_pi_atomic() returns a different error, the bogus pointer is passed to wait_for_owner_exiting(). CPU0 CPU1 CPU2 futex_lock_pi(uaddr) // acquires the PI futex exit() futex_cleanup_begin() futex_state = EXITING; futex_lock_pi(uaddr) futex_lock_pi_atomic() attach_to_pi_owner() // observes EXITING *exiting = owner; // takes ref return -EBUSY wait_for_owner_exiting(-EBUSY, owner) put_task_struct(); // drops ref // exiting still points to owner goto retry; futex_lock_pi_atomic() lock_pi_update_atomic() cmpxchg(uaddr) *uaddr ^= WAITERS // whatever // value changed return -EAGAIN; wait_for_owner_exiting(-EAGAIN, exiting) // stale WARN_ON_ONCE(exiting) Fix this by resetting upon retry, essentially aligning it with requeue_pi.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: spi: spi-dw-dma: fix print error log when wait finish transaction If an error occurs, the device may not have a current message. In this case, the system will crash. In this case, it's better to use dev from the struct ctlr (struct spi_controller*).


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock Take and hold kvm->lock for before checking sev_guest() in sev_mem_enc_register_region(), as sev_guest() isn't stable unless kvm->lock is held (or KVM can guarantee KVM_SEV_INIT{2} has completed and can't rollack state). If KVM_SEV_INIT{2} fails, KVM can end up trying to add to a not-yet-initialized sev->regions_list, e.g. triggering a #GP Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 110 UID: 0 PID: 72717 Comm: syz.15.11462 Tainted: G U W O 6.16.0-smp-DEV #1 NONE Tainted: [U]=USER, [W]=WARN, [O]=OOT_MODULE Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.52.0-0 10/28/2024 RIP: 0010:sev_mem_enc_register_region+0x3f0/0x4f0 ../include/linux/list.h:83 Code: <41> 80 3c 04 00 74 08 4c 89 ff e8 f1 c7 a2 00 49 39 ed 0f 84 c6 00 RSP: 0018:ffff88838647fbb8 EFLAGS: 00010256 RAX: dffffc0000000000 RBX: 1ffff92015cf1e0b RCX: dffffc0000000000 RDX: 0000000000000000 RSI: 0000000000001000 RDI: ffff888367870000 RBP: ffffc900ae78f050 R08: ffffea000d9e0007 R09: 1ffffd4001b3c000 R10: dffffc0000000000 R11: fffff94001b3c001 R12: 0000000000000000 R13: ffff8982ab0bde00 R14: ffffc900ae78f058 R15: 0000000000000000 FS: 00007f34e9dc66c0(0000) GS:ffff89ee64d33000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fe180adef98 CR3: 000000047210e000 CR4: 0000000000350ef0 Call Trace: <TASK> kvm_arch_vm_ioctl+0xa72/0x1240 ../arch/x86/kvm/x86.c:7371 kvm_vm_ioctl+0x649/0x990 ../virt/kvm/kvm_main.c:5363 __se_sys_ioctl+0x101/0x170 ../fs/ioctl.c:51 do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x6f/0x1f0 ../arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7f34e9f7e9a9 Code: <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f34e9dc6038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007f34ea1a6080 RCX: 00007f34e9f7e9a9 RDX: 0000200000000280 RSI: 000000008010aebb RDI: 0000000000000007 RBP: 00007f34ea000d69 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 0000000000000000 R14: 00007f34ea1a6080 R15: 00007ffce77197a8 </TASK> with a syzlang reproducer that looks like: syz_kvm_add_vcpu$x86(0x0, &(0x7f0000000040)={0x0, &(0x7f0000000180)=ANY=[], 0x70}) (async) syz_kvm_add_vcpu$x86(0x0, &(0x7f0000000080)={0x0, &(0x7f0000000180)=ANY=[@ANYBLOB="..."], 0x4f}) (async) r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000200), 0x0, 0x0) r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0) r2 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000240), 0x0, 0x0) r3 = ioctl$KVM_CREATE_VM(r2, 0xae01, 0x0) ioctl$KVM_SET_CLOCK(r3, 0xc008aeba, &(0x7f0000000040)={0x1, 0x8, 0x0, 0x5625e9b0}) (async) ioctl$KVM_SET_PIT2(r3, 0x8010aebb, &(0x7f0000000280)={[...], 0x5}) (async) ioctl$KVM_SET_PIT2(r1, 0x4070aea0, 0x0) (async) r4 = ioctl$KVM_CREATE_VM(0xffffffffffffffff, 0xae01, 0x0) openat$kvm(0xffffffffffffff9c, 0x0, 0x0, 0x0) (async) ioctl$KVM_SET_USER_MEMORY_REGION(r4, 0x4020ae46, &(0x7f0000000400)={0x0, 0x0, 0x0, 0x2000, &(0x7f0000001000/0x2000)=nil}) (async) r5 = ioctl$KVM_CREATE_VCPU(r4, 0xae41, 0x2) close(r0) (async) openat$kvm(0xffffffffffffff9c, &(0x7f0000000000), 0x8000, 0x0) (async) ioctl$KVM_SET_GUEST_DEBUG(r5, 0x4048ae9b, &(0x7f0000000300)={0x4376ea830d46549b, 0x0, [0x46, 0x0, 0x0, 0x0, 0x0, 0x1000]}) (async) ioctl$KVM_RUN(r5, 0xae80, 0x0) Opportunistically use guard() to avoid having to define a new error label and goto usage.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU Reject synchronizing vCPU state to its associated VMSA if the vCPU has already been launched, i.e. if the VMSA has already been encrypted. On a host with SNP enabled, accessing guest-private memory generates an RMP #PF and panics the host. BUG: unable to handle page fault for address: ff1276cbfdf36000 #PF: supervisor write access in kernel mode #PF: error_code(0x80000003) - RMP violation PGD 5a31801067 P4D 5a31802067 PUD 40ccfb5063 PMD 40e5954063 PTE 80000040fdf36163 SEV-SNP: PFN 0x40fdf36, RMP entry: [0x6010fffffffff001 - 0x000000000000001f] Oops: Oops: 0003 [#1] SMP NOPTI CPU: 33 UID: 0 PID: 996180 Comm: qemu-system-x86 Tainted: G OE Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE Hardware name: Dell Inc. PowerEdge R7625/0H1TJT, BIOS 1.5.8 07/21/2023 RIP: 0010:sev_es_sync_vmsa+0x54/0x4c0 [kvm_amd] Call Trace: <TASK> snp_launch_update_vmsa+0x19d/0x290 [kvm_amd] snp_launch_finish+0xb6/0x380 [kvm_amd] sev_mem_enc_ioctl+0x14e/0x720 [kvm_amd] kvm_arch_vm_ioctl+0x837/0xcf0 [kvm] kvm_vm_ioctl+0x3fd/0xcc0 [kvm] __x64_sys_ioctl+0xa3/0x100 x64_sys_call+0xfe0/0x2350 do_syscall_64+0x81/0x10f0 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7ffff673287d </TASK> Note, the KVM flaw has been present since commit ad73109ae7ec ("KVM: SVM: Provide support to launch and run an SEV-ES guest"), but has only been actively dangerous for the host since SNP support was added. With SEV-ES, KVM would "just" clobber guest state, which is totally fine from a host kernel perspective since userspace can clobber guest state any time before sev_launch_update_vmsa().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling Switch from using the completion's raw spinlock to a local lock in the idpf_vc_xn struct. The conversion is safe because complete/_all() are called outside the lock and there is no reason to share the completion lock in the current logic. This avoids invalid wait context reported by the kernel due to the async handler taking BH spinlock: [ 805.726977] ============================= [ 805.726991] [ BUG: Invalid wait context ] [ 805.727006] 7.0.0-rc2-net-devq-031026+ #28 Tainted: G S OE [ 805.727026] ----------------------------- [ 805.727038] kworker/u261:0/572 is trying to lock: [ 805.727051] ff190da6a8dbb6a0 (&vport_config->mac_filter_list_lock){+...}-{3:3}, at: idpf_mac_filter_async_handler+0xe9/0x260 [idpf] [ 805.727099] other info that might help us debug this: [ 805.727111] context-{5:5} [ 805.727119] 3 locks held by kworker/u261:0/572: [ 805.727132] #0: ff190da6db3e6148 ((wq_completion)idpf-0000:83:00.0-mbx){+.+.}-{0:0}, at: process_one_work+0x4b5/0x730 [ 805.727163] #1: ff3c6f0a6131fe50 ((work_completion)(&(&adapter->mbx_task)->work)){+.+.}-{0:0}, at: process_one_work+0x1e5/0x730 [ 805.727191] #2: ff190da765190020 (&x->wait#34){+.+.}-{2:2}, at: idpf_recv_mb_msg+0xc8/0x710 [idpf] [ 805.727218] stack backtrace: ... [ 805.727238] Workqueue: idpf-0000:83:00.0-mbx idpf_mbx_task [idpf] [ 805.727247] Call Trace: [ 805.727249] <TASK> [ 805.727251] dump_stack_lvl+0x77/0xb0 [ 805.727259] __lock_acquire+0xb3b/0x2290 [ 805.727268] ? __irq_work_queue_local+0x59/0x130 [ 805.727275] lock_acquire+0xc6/0x2f0 [ 805.727277] ? idpf_mac_filter_async_handler+0xe9/0x260 [idpf] [ 805.727284] ? _printk+0x5b/0x80 [ 805.727290] _raw_spin_lock_bh+0x38/0x50 [ 805.727298] ? idpf_mac_filter_async_handler+0xe9/0x260 [idpf] [ 805.727303] idpf_mac_filter_async_handler+0xe9/0x260 [idpf] [ 805.727310] idpf_recv_mb_msg+0x1c8/0x710 [idpf] [ 805.727317] process_one_work+0x226/0x730 [ 805.727322] worker_thread+0x19e/0x340 [ 805.727325] ? __pfx_worker_thread+0x10/0x10 [ 805.727328] kthread+0xf4/0x130 [ 805.727333] ? __pfx_kthread+0x10/0x10 [ 805.727336] ret_from_fork+0x32c/0x410 [ 805.727345] ? __pfx_kthread+0x10/0x10 [ 805.727347] ret_from_fork_asm+0x1a/0x30 [ 805.727354] </TASK>


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfrm: clear trailing padding in build_polexpire() build_expire() clears the trailing padding bytes of struct xfrm_user_expire after setting the hard field via memset_after(), but the analogous function build_polexpire() does not do this for struct xfrm_user_polexpire. The padding bytes after the __u8 hard field are left uninitialized from the heap allocation, and are then sent to userspace via netlink multicast to XFRMNLGRP_EXPIRE listeners, leaking kernel heap memory contents. Add the missing memset_after() call, matching build_expire().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: fix use-after-free in timeout object destroy nft_ct_timeout_obj_destroy() frees the timeout object with kfree() immediately after nf_ct_untimeout(), without waiting for an RCU grace period. Concurrent packet processing on other CPUs may still hold RCU-protected references to the timeout object obtained via rcu_dereference() in nf_ct_timeout_data(). Add an rcu_head to struct nf_ct_timeout and use kfree_rcu() to defer freeing until after an RCU grace period, matching the approach already used in nfnetlink_cttimeout.c. KASAN report: BUG: KASAN: slab-use-after-free in nf_conntrack_tcp_packet+0x1381/0x29d0 Read of size 4 at addr ffff8881035fe19c by task exploit/80 Call Trace: nf_conntrack_tcp_packet+0x1381/0x29d0 nf_conntrack_in+0x612/0x8b0 nf_hook_slow+0x70/0x100 __ip_local_out+0x1b2/0x210 tcp_sendmsg_locked+0x722/0x1580 __sys_sendto+0x2d8/0x320 Allocated by task 75: nft_ct_timeout_obj_init+0xf6/0x290 nft_obj_init+0x107/0x1b0 nf_tables_newobj+0x680/0x9c0 nfnetlink_rcv_batch+0xc29/0xe00 Freed by task 26: nft_obj_destroy+0x3f/0xa0 nf_tables_trans_destroy_work+0x51c/0x5c0 process_one_work+0x2c4/0x5a0


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: rfkill: prevent unlimited numbers of rfkill events from being created Userspace can create an unlimited number of rfkill events if the system is so configured, while not consuming them from the rfkill file descriptor, causing a potential out of memory situation. Prevent this from bounding the number of pending rfkill events at a "large" number (i.e. 1000) to prevent abuses like this.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() Reject rt match rules whose addrnr exceeds IP6T_RT_HOPS. rt_mt6() expects addrnr to stay within the bounds of rtinfo->addrs[]. Validate addrnr during rule installation so malformed rules are rejected before the match logic can use an out-of-range value.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - limit RX SG extraction by receive buffer budget Make af_alg_get_rsgl() limit each RX scatterlist extraction to the remaining receive buffer budget. af_alg_get_rsgl() currently uses af_alg_readable() only as a gate before extracting data into the RX scatterlist. Limit each extraction to the remaining af_alg_rcvbuf(sk) budget so that receive-side accounting matches the amount of data attached to the request. If skcipher cannot obtain enough RX space for at least one chunk while more data remains to be processed, reject the recvmsg call instead of rounding the request length down to zero.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: flowlabel: defer exclusive option free until RCU teardown `ip6fl_seq_show()` walks the global flowlabel hash under the seq-file RCU read-side lock and prints `fl->opt->opt_nflen` when an option block is present. Exclusive flowlabels currently free `fl->opt` as soon as `fl->users` drops to zero in `fl_release()`. However, the surrounding `struct ip6_flowlabel` remains visible in the global hash table until later garbage collection removes it and `fl_free_rcu()` finally tears it down. A concurrent `/proc/net/ip6_flowlabel` reader can therefore race that early `kfree()` and dereference freed option state, triggering a crash in `ip6fl_seq_show()`. Fix this by keeping `fl->opt` alive until `fl_free_rcu()`. That matches the lifetime already required for the enclosing flowlabel while readers can still reach it under RCU.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a label to signify the start of the code where a request can be replayed if necessary. However, some of these places were missing the necessary reinitializations of certain local variables before replay. This change makes sure that these variables get initialized after the label.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed When retrieving the ID for the CPU, don't attempt to copy the ID blob to userspace if the firmware command failed. If the failure was due to an invalid length, i.e. the userspace buffer+length was too small, copying the number of bytes _firmware_ requires will overflow the kernel-allocated buffer and leak data to userspace. BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline] BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline] BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26 Read of size 64 at addr ffff8881867f5960 by task syz.0.906/24388 CPU: 130 UID: 0 PID: 24388 Comm: syz.0.906 Tainted: G U O 7.0.0-smp-DEV #28 PREEMPTLAZY Tainted: [U]=USER, [O]=OOT_MODULE Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.62.0-0 11/19/2025 Call Trace: <TASK> dump_stack_lvl+0xc5/0x110 ../lib/dump_stack.c:120 print_address_description ../mm/kasan/report.c:378 [inline] print_report+0xbc/0x260 ../mm/kasan/report.c:482 kasan_report+0xa2/0xe0 ../mm/kasan/report.c:595 check_region_inline ../mm/kasan/generic.c:-1 [inline] kasan_check_range+0x264/0x2c0 ../mm/kasan/generic.c:200 instrument_copy_to_user ../include/linux/instrumented.h:129 [inline] _inline_copy_to_user ../include/linux/uaccess.h:205 [inline] _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26 copy_to_user ../include/linux/uaccess.h:236 [inline] sev_ioctl_do_get_id2+0x361/0x490 ../drivers/crypto/ccp/sev-dev.c:2222 sev_ioctl+0x25f/0x490 ../drivers/crypto/ccp/sev-dev.c:2575 vfs_ioctl ../fs/ioctl.c:51 [inline] __do_sys_ioctl ../fs/ioctl.c:597 [inline] __se_sys_ioctl+0x11d/0x1b0 ../fs/ioctl.c:583 do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xe0/0x800 ../arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e </TASK> WARN if the driver says the command succeeded, but the firmware error code says otherwise, as __sev_do_cmd_locked() is expected to return -EIO on any firwmware error.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed When retrieving the PDH cert, don't attempt to copy the blobs to userspace if the firmware command failed. If the failure was due to an invalid length, i.e. the userspace buffer+length was too small, copying the number of bytes _firmware_ requires will overflow the kernel-allocated buffer and leak data to userspace. BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline] BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline] BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26 Read of size 2084 at addr ffff8885c4ab8aa0 by task syz.0.186/21033 CPU: 51 UID: 0 PID: 21033 Comm: syz.0.186 Tainted: G U O 7.0.0-smp-DEV #28 PREEMPTLAZY Tainted: [U]=USER, [O]=OOT_MODULE Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 34.84.12-0 11/17/2025 Call Trace: <TASK> dump_stack_lvl+0xc5/0x110 ../lib/dump_stack.c:120 print_address_description ../mm/kasan/report.c:378 [inline] print_report+0xbc/0x260 ../mm/kasan/report.c:482 kasan_report+0xa2/0xe0 ../mm/kasan/report.c:595 check_region_inline ../mm/kasan/generic.c:-1 [inline] kasan_check_range+0x264/0x2c0 ../mm/kasan/generic.c:200 instrument_copy_to_user ../include/linux/instrumented.h:129 [inline] _inline_copy_to_user ../include/linux/uaccess.h:205 [inline] _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26 copy_to_user ../include/linux/uaccess.h:236 [inline] sev_ioctl_do_pdh_export+0x3d3/0x7c0 ../drivers/crypto/ccp/sev-dev.c:2347 sev_ioctl+0x2a2/0x490 ../drivers/crypto/ccp/sev-dev.c:2568 vfs_ioctl ../fs/ioctl.c:51 [inline] __do_sys_ioctl ../fs/ioctl.c:597 [inline] __se_sys_ioctl+0x11d/0x1b0 ../fs/ioctl.c:583 do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xe0/0x800 ../arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e </TASK> WARN if the driver says the command succeeded, but the firmware error code says otherwise, as __sev_do_cmd_locked() is expected to return -EIO on any firwmware error.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed When retrieving the PEK CSR, don't attempt to copy the blob to userspace if the firmware command failed. If the failure was due to an invalid length, i.e. the userspace buffer+length was too small, copying the number of bytes _firmware_ requires will overflow the kernel-allocated buffer and leak data to userspace. BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline] BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline] BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26 Read of size 2084 at addr ffff898144612e20 by task syz.9.219/21405 CPU: 14 UID: 0 PID: 21405 Comm: syz.9.219 Tainted: G U O 7.0.0-smp-DEV #28 PREEMPTLAZY Tainted: [U]=USER, [O]=OOT_MODULE Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.62.0-0 11/19/2025 Call Trace: <TASK> dump_stack_lvl+0xc5/0x110 ../lib/dump_stack.c:120 print_address_description ../mm/kasan/report.c:378 [inline] print_report+0xbc/0x260 ../mm/kasan/report.c:482 kasan_report+0xa2/0xe0 ../mm/kasan/report.c:595 check_region_inline ../mm/kasan/generic.c:-1 [inline] kasan_check_range+0x264/0x2c0 ../mm/kasan/generic.c:200 instrument_copy_to_user ../include/linux/instrumented.h:129 [inline] _inline_copy_to_user ../include/linux/uaccess.h:205 [inline] _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26 copy_to_user ../include/linux/uaccess.h:236 [inline] sev_ioctl_do_pek_csr+0x31f/0x590 ../drivers/crypto/ccp/sev-dev.c:1872 sev_ioctl+0x3a4/0x490 ../drivers/crypto/ccp/sev-dev.c:2562 vfs_ioctl ../fs/ioctl.c:51 [inline] __do_sys_ioctl ../fs/ioctl.c:597 [inline] __se_sys_ioctl+0x11d/0x1b0 ../fs/ioctl.c:583 do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xe0/0x800 ../arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e </TASK> WARN if the driver says the command succeeded, but the firmware error code says otherwise, as __sev_do_cmd_locked() is expected to return -EIO on any firwmware error.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: validate ND option lengths br_nd_send() walks ND options according to option-provided lengths. A malformed option can make the parser advance beyond the computed option span or use a too-short source LLADDR option payload. Validate option lengths against the remaining NS option area before advancing, and only read source LLADDR when the option is large enough for an Ethernet address.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: ulpi: fix double free in ulpi_register_interface() error path When device_register() fails, ulpi_register() calls put_device() on ulpi->dev. The device release callback ulpi_dev_release() drops the OF node reference and frees ulpi, but the current error path in ulpi_register_interface() then calls kfree(ulpi) again, causing a double free. Let put_device() handle the cleanup through ulpi_dev_release() and avoid freeing ulpi again in ulpi_register_interface().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: move wake reason storage into validated event handlers hci_store_wake_reason() is called from hci_event_packet() immediately after stripping the HCI event header but before hci_event_func() enforces the per-event minimum payload length from hci_ev_table. This means a short HCI event frame can reach bacpy() before any bounds check runs. Rather than duplicating skb parsing and per-event length checks inside hci_store_wake_reason(), move wake-address storage into the individual event handlers after their existing event-length validation has succeeded. Convert hci_store_wake_reason() into a small helper that only stores an already-validated bdaddr while the caller holds hci_dev_lock(). Use the same helper after hci_event_func() with a NULL address to preserve the existing unexpected-wake fallback semantics when no validated event handler records a wake address. Annotate the helper with __must_hold(&hdev->lock) and add lockdep_assert_held(&hdev->lock) so future call paths keep the lock contract explicit. Call the helper from hci_conn_request_evt(), hci_conn_complete_evt(), hci_sync_conn_complete_evt(), le_conn_complete_evt(), hci_le_adv_report_evt(), hci_le_ext_adv_report_evt(), hci_le_direct_adv_report_evt(), hci_le_pa_sync_established_evt(), and hci_le_past_received_evt().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject sleepable kprobe_multi programs at attach time kprobe.multi programs run in atomic/RCU context and cannot sleep. However, bpf_kprobe_multi_link_attach() did not validate whether the program being attached had the sleepable flag set, allowing sleepable helpers such as bpf_copy_from_user() to be invoked from a non-sleepable context. This causes a "sleeping function called from invalid context" splat: BUG: sleeping function called from invalid context at ./include/linux/uaccess.h:169 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1787, name: sudo preempt_count: 1, expected: 0 RCU nest depth: 2, expected: 0 Fix this by rejecting sleepable programs early in bpf_kprobe_multi_link_attach(), before any further processing.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists hci_cmd_sync_queue_once() needs to indicate whether a queue item was added, so caller can know if callbacks are called, so it can avoid leaking resources. Change the function to return -EEXIST if queue item already exists. Modify all callsites to handle that.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: fix race conditions in sco_sock_connect() sco_sock_connect() checks sk_state and sk_type without holding the socket lock. Two concurrent connect() syscalls on the same socket can both pass the check and enter sco_connect(), leading to use-after-free. The buggy scenario involves three participants and was confirmed with additional logging instrumentation: Thread A (connect): HCI disconnect: Thread B (connect): sco_sock_connect(sk) sco_sock_connect(sk) sk_state==BT_OPEN sk_state==BT_OPEN (pass, no lock) (pass, no lock) sco_connect(sk): sco_connect(sk): hci_dev_lock hci_dev_lock hci_connect_sco <- blocked -> hcon1 sco_conn_add->conn1 lock_sock(sk) sco_chan_add: conn1->sk = sk sk->conn = conn1 sk_state=BT_CONNECT release_sock hci_dev_unlock hci_dev_lock sco_conn_del: lock_sock(sk) sco_chan_del: sk->conn=NULL conn1->sk=NULL sk_state= BT_CLOSED SOCK_ZAPPED release_sock hci_dev_unlock (unblocked) hci_connect_sco -> hcon2 sco_conn_add -> conn2 lock_sock(sk) sco_chan_add: sk->conn=conn2 sk_state= BT_CONNECT // zombie sk! release_sock hci_dev_unlock Thread B revives a BT_CLOSED + SOCK_ZAPPED socket back to BT_CONNECT. Subsequent cleanup triggers double sock_put() and use-after-free. Meanwhile conn1 is leaked as it was orphaned when sco_conn_del() cleared the association. Fix this by: - Moving lock_sock() before the sk_state/sk_type checks in sco_sock_connect() to serialize concurrent connect attempts - Fixing the sk_type != SOCK_SEQPACKET check to actually return the error instead of just assigning it - Adding a state re-check in sco_connect() after lock_sock() to catch state changes during the window between the locks - Adding sco_pi(sk)->conn check in sco_chan_add() to prevent double-attach of a socket to multiple connections - Adding hci_conn_drop() on sco_chan_add failure to prevent HCI connection leaks


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject immediate NF_QUEUE verdict nft_queue is always used from userspace nftables to deliver the NF_QUEUE verdict. Immediately emitting an NF_QUEUE verdict is never used by the userspace nft tools, so reject immediate NF_QUEUE verdicts. The arp family does not provide queue support, but such an immediate verdict is still reachable. Globally reject NF_QUEUE immediate verdicts to address this issue.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: ensure names are nul-terminated Reject names that lack a \0 character before feeding them to functions that expect c-strings. Fixes tag is the most recent commit that needs this change.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: set backing store type from query type bnxt_hwrm_func_backing_store_qcaps_v2() stores resp->type from the firmware response in ctxm->type and later uses that value to index fixed backing-store metadata arrays such as ctx_arr[] and bnxt_bstore_to_trace[]. ctxm->type is fixed by the current backing-store query type and matches the array index of ctx->ctx_arr. Set ctxm->type from the current loop variable instead of depending on resp->type. Also update the loop to advance type from next_valid_type in the for statement, which keeps the control flow simpler for non-valid and unchanged entries.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak When building netlink messages, tc_chain_fill_node() never initializes the tcm_info field of struct tcmsg. Since the allocation is not zeroed, kernel heap memory is leaked to userspace through this 4-byte field. The fix simply zeroes tcm_info alongside the other fields that are already initialized.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: use skb_header_pointer() for TCPv4 GSO frag_off check Syzbot reported a KMSAN uninit-value warning in gso_features_check() called from netif_skb_features() [1]. gso_features_check() reads iph->frag_off to decide whether to clear mangleid_features. Accessing the IPv4 header via ip_hdr()/inner_ip_hdr() can rely on skb header offsets that are not always safe for direct dereference on packets injected from PF_PACKET paths. Use skb_header_pointer() for the TCPv4 frag_off check so the header read is robust whether data is already linear or needs copying. [1] https://syzkaller.appspot.com/bug?extid=1543a7d954d9c6d00407


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure Presently, if the force feedback initialisation fails when probing the Logitech G920 Driving Force Racing Wheel for Xbox One, an error number will be returned and propagated before the userspace infrastructure (sysfs and /dev/input) has been torn down. If userspace ignores the errors and continues to use its references to these dangling entities, a UAF will promptly follow. We have 2 options; continue to return the error, but ensure that all of the infrastructure is torn down accordingly or continue to treat this condition as a warning by emitting the message but returning success. It is thought that the original author's intention was to emit the warning but keep the device functional, less the force feedback feature, so let's go with that.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfs: close crash window in attr dabtree inactivation When inactivating an inode with node-format extended attributes, xfs_attr3_node_inactive() invalidates all child leaf/node blocks via xfs_trans_binval(), but intentionally does not remove the corresponding entries from their parent node blocks. The implicit assumption is that xfs_attr_inactive() will truncate the entire attr fork to zero extents afterwards, so log recovery will never reach the root node and follow those stale pointers. However, if a log shutdown occurs after the leaf/node block cancellations commit but before the attr bmap truncation commits, this assumption breaks. Recovery replays the attr bmap intact (the inode still has attr fork extents), but suppresses replay of all cancelled leaf/node blocks, maybe leaving them as stale data on disk. On the next mount, xlog_recover_process_iunlinks() retries inactivation and attempts to read the root node via the attr bmap. If the root node was not replayed, reading the unreplayed root block triggers a metadata verification failure immediately; if it was replayed, following its child pointers to unreplayed child blocks triggers the same failure: XFS (pmem0): Metadata corruption detected at xfs_da3_node_read_verify+0x53/0x220, xfs_da3_node block 0x78 XFS (pmem0): Unmount and run xfs_repair XFS (pmem0): First 128 bytes of corrupted metadata buffer: 00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ XFS (pmem0): metadata I/O error in "xfs_da_read_buf+0x104/0x190" at daddr 0x78 len 8 error 117 Fix this in two places: In xfs_attr3_node_inactive(), after calling xfs_trans_binval() on a child block, immediately remove the entry that references it from the parent node in the same transaction. This eliminates the window where the parent holds a pointer to a cancelled block. Once all children are removed, the now-empty root node is converted to a leaf block within the same transaction. This node-to-leaf conversion is necessary for crash safety. If the system shutdown after the empty node is written to the log but before the second-phase bmap truncation commits, log recovery will attempt to verify the root block on disk. xfs_da3_node_verify() does not permit a node block with count == 0; such a block will fail verification and trigger a metadata corruption shutdown. on the other hand, leaf blocks are allowed to have this transient state. In xfs_attr_inactive(), split the attr fork truncation into two explicit phases. First, truncate all extents beyond the root block (the child extents whose parent references have already been removed above). Second, invalidate the root block and truncate the attr bmap to zero in a single transaction. The two operations in the second phase must be atomic: as long as the attr bmap has any non-zero length, recovery can follow it to the root block, so the root block invalidation must commit together with the bmap-to-zero truncation.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c will kfree the epi->ep eventpoll struct while it still being used by another concurrent thread. Defer the kfree() to an RCU callback to prevent UAF.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Fix minimum RX size check for decryption The check for the minimum receive buffer size did not take the tag size into account during decryption. Fix this by adding the required extra length.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Skip discovery table for offline dies This warning can be triggered if NUMA is disabled and the system boots with fewer CPUs than the number of CPUs in die 0. WARNING: CPU: 9 PID: 7257 at uncore.c:1157 uncore_pci_pmu_register+0x136/0x160 [intel_uncore] Currently, the discovery table continues to be parsed even if all CPUs in the associated die are offline. This can lead to an array overflow at "pmu->boxes[die] = box" in uncore_pci_pmu_register(), which may trigger the warning above or cause other issues.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: l2tp: Drop large packets with UDP encap syzbot reported a WARN on my patch series [1]. The actual issue is an overflow of 16-bit UDP length field, and it exists in the upstream code. My series added a debug WARN with an overflow check that exposed the issue, that's why syzbot tripped on my patches, rather than on upstream code. syzbot's repro: r0 = socket$pppl2tp(0x18, 0x1, 0x1) r1 = socket$inet6_udp(0xa, 0x2, 0x0) connect$inet6(r1, &(0x7f00000000c0)={0xa, 0x0, 0x0, @loopback, 0xfffffffc}, 0x1c) connect$pppl2tp(r0, &(0x7f0000000240)=@pppol2tpin6={0x18, 0x1, {0x0, r1, 0x4, 0x0, 0x0, 0x0, {0xa, 0x4e22, 0xffff, @ipv4={'\x00', '\xff\xff', @empty}}}}, 0x32) writev(r0, &(0x7f0000000080)=[{&(0x7f0000000000)="ee", 0x34000}], 0x1) It basically sends an oversized (0x34000 bytes) PPPoL2TP packet with UDP encapsulation, and l2tp_xmit_core doesn't check for overflows when it assigns the UDP length field. The value gets trimmed to 16 bites. Add an overflow check that drops oversized packets and avoids sending packets with trimmed UDP length to the wire. syzbot's stack trace (with my patch applied): len >= 65536u WARNING: ./include/linux/udp.h:38 at udp_set_len_short include/linux/udp.h:38 [inline], CPU#1: syz.0.17/5957 WARNING: ./include/linux/udp.h:38 at l2tp_xmit_core net/l2tp/l2tp_core.c:1293 [inline], CPU#1: syz.0.17/5957 WARNING: ./include/linux/udp.h:38 at l2tp_xmit_skb+0x1204/0x18d0 net/l2tp/l2tp_core.c:1327, CPU#1: syz.0.17/5957 Modules linked in: CPU: 1 UID: 0 PID: 5957 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 RIP: 0010:udp_set_len_short include/linux/udp.h:38 [inline] RIP: 0010:l2tp_xmit_core net/l2tp/l2tp_core.c:1293 [inline] RIP: 0010:l2tp_xmit_skb+0x1204/0x18d0 net/l2tp/l2tp_core.c:1327 Code: 0f 0b 90 e9 21 f9 ff ff e8 e9 05 ec f6 90 0f 0b 90 e9 8d f9 ff ff e8 db 05 ec f6 90 0f 0b 90 e9 cc f9 ff ff e8 cd 05 ec f6 90 <0f> 0b 90 e9 de fa ff ff 44 89 f1 80 e1 07 80 c1 03 38 c1 0f 8c 4f RSP: 0018:ffffc90003d67878 EFLAGS: 00010293 RAX: ffffffff8ad985e3 RBX: ffff8881a6400090 RCX: ffff8881697f0000 RDX: 0000000000000000 RSI: 0000000000034010 RDI: 000000000000ffff RBP: dffffc0000000000 R08: 0000000000000003 R09: 0000000000000004 R10: dffffc0000000000 R11: fffff520007acf00 R12: ffff8881baf20900 R13: 0000000000034010 R14: ffff8881a640008e R15: ffff8881760f7000 FS: 000055557e81f500(0000) GS:ffff8882a9467000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000200000033000 CR3: 00000001612f4000 CR4: 00000000000006f0 Call Trace: <TASK> pppol2tp_sendmsg+0x40a/0x5f0 net/l2tp/l2tp_ppp.c:302 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg net/socket.c:742 [inline] sock_write_iter+0x503/0x550 net/socket.c:1195 do_iter_readv_writev+0x619/0x8c0 fs/read_write.c:-1 vfs_writev+0x33c/0x990 fs/read_write.c:1059 do_writev+0x154/0x2e0 fs/read_write.c:1105 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x14d/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f636479c629 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007ffffd4241c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000014 RAX: ffffffffffffffda RBX: 00007f6364a15fa0 RCX: 00007f636479c629 RDX: 0000000000000001 RSI: 0000200000000080 RDI: 0000000000000003 RBP: 00007f6364832b39 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007f6364a15fac R14: 00007f6364a15fa0 R15: 00007f6364a15fa0 </TASK> [1]: https://lore.kernel.org/all/20260226201600.222044-1-alice.kernel@fastmail.im/


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ Fix the field masks to match the hardware layout documented in downstream GSI (GSI_V3_0_EE_n_GSI_EE_GENERIC_CMD_*). Notably this fixes a WARN I was seeing when I tried to send "stop" to the MPSS remoteproc while IPA was up.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue->qdisc); This code can lead to an out-of-bounds access of the dev->_tx[] array when is_input is true. In such a case, the packet is on the RX path and skb->queue_mapping contains the RX queue index of the ingress device. If the ingress device has more RX queues than the egress device (dev) has TX queues, skb_get_queue_mapping(skb) will exceed dev->num_tx_queues. Add a check to avoid this situation since skb_get_tx_queue() does not clamp the index. This issue has also revealed that per queue visibility cannot be accurate and will be replaced later as a new feature. While at it, add missing lock around qdisc_qstats_qlen_backlog(). The function __ioam6_fill_trace_data() is called from both softirq and process contexts, hence the use of spin_lock_bh() here.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator When batching multiple NFLOG messages (inst->qlen > 1), __nfulnl_send() appends an NLMSG_DONE terminator with sizeof(struct nfgenmsg) payload via nlmsg_put(), but never initializes the nfgenmsg bytes. The nlmsg_put() helper only zeroes alignment padding after the payload, not the payload itself, so four bytes of stale kernel heap data are leaked to userspace in the NLMSG_DONE message body. Use nfnl_msg_put() to build the NLMSG_DONE terminator, which initializes the nfgenmsg payload via nfnl_fill_hdr(), consistent with how __build_packet_message() already constructs NFULNL_MSG_PACKET headers.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipvs: fix NULL deref in ip_vs_add_service error path When ip_vs_bind_scheduler() succeeds in ip_vs_add_service(), the local variable sched is set to NULL. If ip_vs_start_estimator() subsequently fails, the out_err cleanup calls ip_vs_unbind_scheduler(svc, sched) with sched == NULL. ip_vs_unbind_scheduler() passes the cur_sched NULL check (because svc->scheduler was set by the successful bind) but then dereferences the NULL sched parameter at sched->done_service, causing a kernel panic at offset 0x30 from NULL. Oops: general protection fault, [..] [#1] PREEMPT SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000030-0x0000000000000037] RIP: 0010:ip_vs_unbind_scheduler (net/netfilter/ipvs/ip_vs_sched.c:69) Call Trace: <TASK> ip_vs_add_service.isra.0 (net/netfilter/ipvs/ip_vs_ctl.c:1500) do_ip_vs_set_ctl (net/netfilter/ipvs/ip_vs_ctl.c:2809) nf_setsockopt (net/netfilter/nf_sockopt.c:102) [..] Fix by simply not clearing the local sched variable after a successful bind. ip_vs_unbind_scheduler() already detects whether a scheduler is installed via svc->scheduler, and keeping sched non-NULL ensures the error path passes the correct pointer to both ip_vs_unbind_scheduler() and ip_vs_scheduler_put(). While the bug is older, the problem popups in more recent kernels (6.2), when the new error path is taken after the ip_vs_start_estimator() call.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_mapping() struct xfrm_usersa_id has a one-byte padding hole after the proto field, which ends up never getting set to zero before copying out to userspace. Fix that up by zeroing out the whole structure before setting individual variables.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xsk: tighten UMEM headroom validation to account for tailroom and min frame The current headroom validation in xdp_umem_reg() could leave us with insufficient space dedicated to even receive minimum-sized ethernet frame. Furthermore if multi-buffer would come to play then skb_shared_info stored at the end of XSK frame would be corrupted. HW typically works with 128-aligned sizes so let us provide this value as bare minimum. Multi-buffer setting is known later in the configuration process so besides accounting for 128 bytes, let us also take care of tailroom space upfront.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ixgbevf: add missing negotiate_features op to Hyper-V ops table Commit a7075f501bd3 ("ixgbevf: fix mailbox API compatibility by negotiating supported features") added the .negotiate_features callback to ixgbe_mac_operations and populated it in ixgbevf_mac_ops, but forgot to add it to ixgbevf_hv_mac_ops. This leaves the function pointer NULL on Hyper-V VMs. During probe, ixgbevf_negotiate_api() calls ixgbevf_set_features(), which unconditionally dereferences hw->mac.ops.negotiate_features(). On Hyper-V this results in a NULL pointer dereference: BUG: kernel NULL pointer dereference, address: 0000000000000000 [...] Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine [...] Workqueue: events work_for_cpu_fn RIP: 0010:0x0 [...] Call Trace: ixgbevf_negotiate_api+0x66/0x160 [ixgbevf] ixgbevf_sw_init+0xe4/0x1f0 [ixgbevf] ixgbevf_probe+0x20f/0x4a0 [ixgbevf] local_pci_probe+0x50/0xa0 work_for_cpu_fn+0x1a/0x30 [...] Add ixgbevf_hv_negotiate_features_vf() that returns -EOPNOTSUPP and wire it into ixgbevf_hv_mac_ops. The caller already handles -EOPNOTSUPP gracefully.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() We need to check __in6_dev_get() for possible NULL value, as suggested by Yiming Qian. Also add skb_dst_dev_rcu() instead of skb_dst_dev(), and two missing READ_ONCE(). Note that @dev can't be NULL.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfrm: account XFRMA_IF_ID in aevent size calculation xfrm_get_ae() allocates the reply skb with xfrm_aevent_msgsize(), then build_aevent() appends attributes including XFRMA_IF_ID when x->if_id is set. xfrm_aevent_msgsize() does not include space for XFRMA_IF_ID. For states with if_id, build_aevent() can fail with -EMSGSIZE and hit BUG_ON(err < 0) in xfrm_get_ae(), turning a malformed netlink interaction into a kernel panic. Account XFRMA_IF_ID in the size calculation unconditionally and replace the BUG_ON with normal error unwinding.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., "/"), the current logic attempts to check *(cursor2 - 1) before cursor2 has advanced. This results in an out-of-bounds read. This patch adds an early exit check after stripping prepended delimiters. If no path content remains, the function returns NULL. The bug was identified via manual audit and verified using a standalone test case compiled with AddressSanitizer, which triggered a SEGV on affected inputs.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: annotate data-races around hdev->req_status __hci_cmd_sync_sk() sets hdev->req_status under hdev->req_lock: hdev->req_status = HCI_REQ_PEND; However, several other functions read or write hdev->req_status without holding any lock: - hci_send_cmd_sync() reads req_status in hci_cmd_work (workqueue) - hci_cmd_sync_complete() reads/writes from HCI event completion - hci_cmd_sync_cancel() / hci_cmd_sync_cancel_sync() read/write - hci_abort_conn() reads in connection abort path Since __hci_cmd_sync_sk() runs on hdev->req_workqueue while hci_send_cmd_sync() runs on hdev->workqueue, these are different workqueues that can execute concurrently on different CPUs. The plain C accesses constitute a data race. Add READ_ONCE()/WRITE_ONCE() annotations on all concurrent accesses to hdev->req_status to prevent potential compiler optimizations that could affect correctness (e.g., load fusing in the wait_event condition or store reordering).


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix double dma_buf_unpin in failure path In ib_umem_dmabuf_get_pinned_with_dma_device(), the call to ib_umem_dmabuf_map_pages() can fail. If this occurs, the dmabuf is immediately unpinned but the umem_dmabuf->pinned flag is still set. Then, when ib_umem_release() is called, it calls ib_umem_dmabuf_revoke() which will call dma_buf_unpin() again. Fix this by removing the immediate unpin upon failure and just let the ib_umem_release/revoke path handle it. This also ensures the proper unmap-unpin unwind ordering if the dmabuf_map_pages call happened to fail due to dma_resv_wait_timeout (and therefore has a non-NULL umem_dmabuf->sgt).


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() xfrm6_get_saddr() does not check the return value of ipv6_dev_get_saddr(). When ipv6_dev_get_saddr() fails to find a suitable source address (returns -EADDRNOTAVAIL), saddr->in6 is left uninitialized, but xfrm6_get_saddr() still returns 0 (success). This causes the caller xfrm_tmpl_resolve_one() to use the uninitialized address in xfrm_state_find(), triggering KMSAN warning: ===================================================== BUG: KMSAN: uninit-value in xfrm_state_find+0x2424/0xa940 xfrm_state_find+0x2424/0xa940 xfrm_resolve_and_create_bundle+0x906/0x5a20 xfrm_lookup_with_ifid+0xcc0/0x3770 xfrm_lookup_route+0x63/0x2b0 ip_route_output_flow+0x1ce/0x270 udp_sendmsg+0x2ce1/0x3400 inet_sendmsg+0x1ef/0x2a0 __sock_sendmsg+0x278/0x3d0 __sys_sendto+0x593/0x720 __x64_sys_sendto+0x130/0x200 x64_sys_call+0x332b/0x3e70 do_syscall_64+0xd3/0xf80 entry_SYSCALL_64_after_hwframe+0x77/0x7f Local variable tmp.i.i created at: xfrm_resolve_and_create_bundle+0x3e3/0x5a20 xfrm_lookup_with_ifid+0xcc0/0x3770 ===================================================== Fix by checking the return value of ipv6_dev_get_saddr() and propagating the error.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfs: fix freemap adjustments when adding xattrs to leaf blocks xfs/592 and xfs/794 both trip this assertion in the leaf block freemap adjustment code after ~20 minutes of running on my test VMs: ASSERT(ichdr->firstused >= ichdr->count * sizeof(xfs_attr_leaf_entry_t) + xfs_attr3_leaf_hdr_size(leaf)); Upon enabling quite a lot more debugging code, I narrowed this down to fsstress trying to set a local extended attribute with namelen=3 and valuelen=71. This results in an entry size of 80 bytes. At the start of xfs_attr3_leaf_add_work, the freemap looks like this: i 0 base 448 size 0 rhs 448 count 46 i 1 base 388 size 132 rhs 448 count 46 i 2 base 2120 size 4 rhs 448 count 46 firstused = 520 where "rhs" is the first byte past the end of the leaf entry array. This is inconsistent -- the entries array ends at byte 448, but freemap[1] says there's free space starting at byte 388! By the end of the function, the freemap is in worse shape: i 0 base 456 size 0 rhs 456 count 47 i 1 base 388 size 52 rhs 456 count 47 i 2 base 2120 size 4 rhs 456 count 47 firstused = 440 Important note: 388 is not aligned with the entries array element size of 8 bytes. Based on the incorrect freemap, the name area starts at byte 440, which is below the end of the entries array! That's why the assertion triggers and the filesystem shuts down. How did we end up here? First, recall from the previous patch that the freemap array in an xattr leaf block is not intended to be a comprehensive map of all free space in the leaf block. In other words, it's perfectly legal to have a leaf block with: * 376 bytes in use by the entries array * freemap[0] has [base = 376, size = 8] * freemap[1] has [base = 388, size = 1500] * the space between 376 and 388 is free, but the freemap stopped tracking that some time ago If we add one xattr, the entries array grows to 384 bytes, and freemap[0] becomes [base = 384, size = 0]. So far, so good. But if we add a second xattr, the entries array grows to 392 bytes, and freemap[0] gets pushed up to [base = 392, size = 0]. This is bad, because freemap[1] hasn't been updated, and now the entries array and the free space claim the same space. The fix here is to adjust all freemap entries so that none of them collide with the entries array. Note that this fix relies on commit 2a2b5932db6758 ("xfs: fix attr leaf header freemap.size underflow") and the previous patch that resets zero length freemap entries to have base = 0.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: EFI/CPER: don't dump the entire memory region The current logic at cper_print_fw_err() doesn't check if the error record length is big enough to handle offset. On a bad firmware, if the ofset is above the actual record, length -= offset will underflow, making it dump the entire memory. The end result can be: - the logic taking a lot of time dumping large regions of memory; - data disclosure due to the memory dumps; - an OOPS, if it tries to dump an unmapped memory region. Fix it by checking if the section length is too small before doing a hex dump. [ rjw: Subject tweaks ]


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfs: delete attr leaf freemap entries when empty Back in commit 2a2b5932db6758 ("xfs: fix attr leaf header freemap.size underflow"), Brian Foster observed that it's possible for a small freemap at the end of the end of the xattr entries array to experience a size underflow when subtracting the space consumed by an expansion of the entries array. There are only three freemap entries, which means that it is not a complete index of all free space in the leaf block. This code can leave behind a zero-length freemap entry with a nonzero base. Subsequent setxattr operations can increase the base up to the point that it overlaps with another freemap entry. This isn't in and of itself a problem because the code in _leaf_add that finds free space ignores any freemap entry with zero size. However, there's another bug in the freemap update code in _leaf_add, which is that it fails to update a freemap entry that begins midway through the xattr entry that was just appended to the array. That can result in the freemap containing two entries with the same base but different sizes (0 for the "pushed-up" entry, nonzero for the entry that's actually tracking free space). A subsequent _leaf_add can then allocate xattr namevalue entries on top of the entries array, leading to data loss. But fixing that is for later. For now, eliminate the possibility of confusion by zeroing out the base of any freemap entry that has zero size. Because the freemap is not intended to be a complete index of free space, a subsequent failure to find any free space for a new xattr will trigger block compaction, which regenerates the freemap. It looks like this bug has been in the codebase for quite a long time.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is already visible from TCP ehash table and other cpus might use it. Since newinet->pinet6 is still pointing to the listener ipv6_pinfo bad things can happen as syzbot found. Move the problematic code in tcp_v6_mapped_child_init() and call this new helper from tcp_v4_syn_recv_sock() before the ehash insertion. This allows the removal of one tcp_sync_mss(), since tcp_v4_syn_recv_sock() will call it with the correct context.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() In decode_choice(), the boundary check before get_len() uses the variable `len`, which is still 0 from its initialization at the top of the function: unsigned int type, ext, len = 0; ... if (ext || (son->attr & OPEN)) { BYTE_ALIGN(bs); if (nf_h323_error_boundary(bs, len, 0)) /* len is 0 here */ return H323_ERROR_BOUND; len = get_len(bs); /* OOB read */ When the bitstream is exactly consumed (bs->cur == bs->end), the check nf_h323_error_boundary(bs, 0, 0) evaluates to (bs->cur + 0 > bs->end), which is false. The subsequent get_len() call then dereferences *bs->cur++, reading 1 byte past the end of the buffer. If that byte has bit 7 set, get_len() reads a second byte as well. This can be triggered remotely by sending a crafted Q.931 SETUP message with a User-User Information Element containing exactly 2 bytes of PER-encoded data ({0x08, 0x00}) to port 1720 through a firewall with the nf_conntrack_h323 helper active. The decoder fully consumes the PER buffer before reaching this code path, resulting in a 1-2 byte heap-buffer-overflow read confirmed by AddressSanitizer. Fix this by checking for 2 bytes (the maximum that get_len() may read) instead of the uninitialized `len`. This matches the pattern used at every other get_len() call site in the same file, where the caller checks for 2 bytes of available data before calling get_len().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() Commit 38a6f0865796 ("net: sched: support hash selecting tx queue") added SKBEDIT_F_TXQ_SKBHASH support. The inclusive range size is computed as: mapping_mod = queue_mapping_max - queue_mapping + 1; The range size can be 65536 when the requested range covers all possible u16 queue IDs (e.g. queue_mapping=0 and queue_mapping_max=U16_MAX). That value cannot be represented in a u16 and previously wrapped to 0, so tcf_skbedit_hash() could trigger a divide-by-zero: queue_mapping += skb_get_hash(skb) % params->mapping_mod; Compute mapping_mod in a wider type and reject ranges larger than U16_MAX to prevent params->mapping_mod from becoming 0 and avoid the crash.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: smb: client: prevent races in ->query_interfaces() It was possible for two query interface works to be concurrently trying to update the interfaces. Prevent this by checking and updating iface_last_update under iface_lock.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt externally backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: clear page->private in free_pages_prepare() Several subsystems (slub, shmem, ttm, etc.) use page->private but don't clear it before freeing pages. When these pages are later allocated as high-order pages and split via split_page(), tail pages retain stale page->private values. This causes a use-after-free in the swap subsystem. The swap code uses page->private to track swap count continuations, assuming freshly allocated pages have page->private == 0. When stale values are present, swap_count_continued() incorrectly assumes the continuation list is valid and iterates over uninitialized page->lru containing LIST_POISON values, causing a crash: KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107] RIP: 0010:__do_sys_swapoff+0x1151/0x1860 Fix this by clearing page->private in free_pages_prepare(), ensuring all freed pages have clean state regardless of previous use.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: lib/crypto: chacha: Zeroize permuted_state before it leaves scope Since the ChaCha permutation is invertible, the local variable 'permuted_state' is sufficient to compute the original 'state', and thus the key, even after the permutation has been done. While the kernel is quite inconsistent about zeroizing secrets on the stack (and some prominent userspace crypto libraries don't bother at all since it's not guaranteed to work anyway), the kernel does try to do it as a best practice, especially in cases involving the RNG. Thus, explicitly zeroize 'permuted_state' before it goes out of scope.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent possible UaF in addrconf_permanent_addr() The mentioned helper try to warn the user about an exceptional condition, but the message is delivered too late, accessing the ipv6 after its possible deletion. Reorder the statement to avoid the possible UaF; while at it, place the warning outside the idev->lock as it needs no protection.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix event ring index not programmed for IPA v5.0+ For IPA v5.0+, the event ring index field moved from CH_C_CNTXT_0 to CH_C_CNTXT_1. The v5.0 register definition intended to define this field in the CH_C_CNTXT_1 fmask array but used the old identifier of ERINDEX instead of CH_ERINDEX. Without a valid event ring, GSI channels could never signal transfer completions. This caused gsi_channel_trans_quiesce() to block forever in wait_for_completion(). At least for IPA v5.2 this resolves an issue seen where runtime suspend, system suspend, and remoteproc stop all hanged forever. It also meant the IPA data path was completely non functional.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_monmap_decode() This patch fixes unnecessary implicit conversions that change signedness of blob_len and num_mon in ceph_monmap_decode(). Currently blob_len and num_mon are (signed) int variables. They are used to hold values that are always non-negative and get assigned in ceph_decode_32_safe(), which is meant to assign u32 values. Both variables are subsequently used as unsigned values, and the value of num_mon is further assigned to monmap->num_mon, which is of type u32. Therefore, both variables should be of type u32. This is especially relevant for num_mon. If the value read from the incoming message is very large, it is interpreted as a negative value, and the check for num_mon > CEPH_MAX_MON does not catch it. This leads to the attempt to allocate a very large chunk of memory for monmap, which will most likely fail. In this case, an unnecessary attempt to allocate memory is performed, and -ENOMEM is returned instead of -EINVAL.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ceph: fix i_nlink underrun during async unlink During async unlink, we drop the `i_nlink` counter before we receive the completion (that will eventually update the `i_nlink`) because "we assume that the unlink will succeed". That is not a bad idea, but it races against deletions by other clients (or against the completion of our own unlink) and can lead to an underrun which emits a WARNING like this one: WARNING: CPU: 85 PID: 25093 at fs/inode.c:407 drop_nlink+0x50/0x68 Modules linked in: CPU: 85 UID: 3221252029 PID: 25093 Comm: php-cgi8.1 Not tainted 6.14.11-cm4all1-ampere #655 Hardware name: Supermicro ARS-110M-NR/R12SPD-A, BIOS 1.1b 10/17/2023 pstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : drop_nlink+0x50/0x68 lr : ceph_unlink+0x6c4/0x720 sp : ffff80012173bc90 x29: ffff80012173bc90 x28: ffff086d0a45aaf8 x27: ffff0871d0eb5680 x26: ffff087f2a64a718 x25: 0000020000000180 x24: 0000000061c88647 x23: 0000000000000002 x22: ffff07ff9236d800 x21: 0000000000001203 x20: ffff07ff9237b000 x19: ffff088b8296afc0 x18: 00000000f3c93365 x17: 0000000000070000 x16: ffff08faffcbdfe8 x15: ffff08faffcbdfec x14: 0000000000000000 x13: 45445f65645f3037 x12: 34385f6369706f74 x11: 0000a2653104bb20 x10: ffffd85f26d73290 x9 : ffffd85f25664f94 x8 : 00000000000000c0 x7 : 0000000000000000 x6 : 0000000000000002 x5 : 0000000000000081 x4 : 0000000000000481 x3 : 0000000000000000 x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff08727d3f91e8 Call trace: drop_nlink+0x50/0x68 (P) vfs_unlink+0xb0/0x2e8 do_unlinkat+0x204/0x288 __arm64_sys_unlinkat+0x3c/0x80 invoke_syscall.constprop.0+0x54/0xe8 do_el0_svc+0xa4/0xc8 el0_svc+0x18/0x58 el0t_64_sync_handler+0x104/0x130 el0t_64_sync+0x154/0x158 In ceph_unlink(), a call to ceph_mdsc_submit_request() submits the CEPH_MDS_OP_UNLINK to the MDS, but does not wait for completion. Meanwhile, between this call and the following drop_nlink() call, a worker thread may process a CEPH_CAP_OP_IMPORT, CEPH_CAP_OP_GRANT or just a CEPH_MSG_CLIENT_REPLY (the latter of which could be our own completion). These will lead to a set_nlink() call, updating the `i_nlink` counter to the value received from the MDS. If that new `i_nlink` value happens to be zero, it is illegal to decrement it further. But that is exactly what ceph_unlink() will do then. The WARNING can be reproduced this way: 1. Force async unlink; only the async code path is affected. Having no real clue about Ceph internals, I was unable to find out why the MDS wouldn't give me the "Fxr" capabilities, so I patched get_caps_for_async_unlink() to always succeed. (Note that the WARNING dump above was found on an unpatched kernel, without this kludge - this is not a theoretical bug.) 2. Add a sleep call after ceph_mdsc_submit_request() so the unlink completion gets handled by a worker thread before drop_nlink() is called. This guarantees that the `i_nlink` is already zero before drop_nlink() runs. The solution is to skip the counter decrement when it is already zero, but doing so without a lock is still racy (TOCTOU). Since ceph_fill_inode() and handle_cap_grant() both hold the `ceph_inode_info.i_ceph_lock` spinlock while set_nlink() runs, this seems like the proper lock to protect the `i_nlink` updates. I found prior art in NFS and SMB (using `inode.i_lock`) and AFS (using `afs_vnode.cb_lock`). All three have the zero check as well.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave() kernel BUG at net/core/skbuff.c:2306! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:pskb_expand_head+0xa08/0xfe0 net/core/skbuff.c:2306 RSP: 0018:ffffc90004aff760 EFLAGS: 00010293 RAX: 0000000000000000 RBX: ffff88807e3c8780 RCX: ffffffff89593e0e RDX: ffff88807b7c4900 RSI: ffffffff89594747 RDI: ffff88807b7c4900 RBP: 0000000000000820 R08: 0000000000000005 R09: 0000000000000000 R10: 00000000961a63e0 R11: 0000000000000000 R12: ffff88807e3c8780 R13: 00000000961a6560 R14: dffffc0000000000 R15: 00000000961a63e0 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fe1a0ed8df0 CR3: 000000002d816000 CR4: 00000000003526f0 Call Trace: <TASK> ipgre_header+0xdd/0x540 net/ipv4/ip_gre.c:900 dev_hard_header include/linux/netdevice.h:3439 [inline] packet_snd net/packet/af_packet.c:3028 [inline] packet_sendmsg+0x3ae5/0x53c0 net/packet/af_packet.c:3108 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg net/socket.c:742 [inline] ____sys_sendmsg+0xa54/0xc30 net/socket.c:2592 ___sys_sendmsg+0x190/0x1e0 net/socket.c:2646 __sys_sendmsg+0x170/0x220 net/socket.c:2678 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x106/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fe1a0e6c1a9 When a non-Ethernet device (e.g. GRE tunnel) is enslaved to a bond, bond_setup_by_slave() directly copies the slave's header_ops to the bond device: bond_dev->header_ops = slave_dev->header_ops; This causes a type confusion when dev_hard_header() is later called on the bond device. Functions like ipgre_header(), ip6gre_header(),all use netdev_priv(dev) to access their device-specific private data. When called with the bond device, netdev_priv() returns the bond's private data (struct bonding) instead of the expected type (e.g. struct ip_tunnel), leading to garbage values being read and kernel crashes. Fix this by introducing bond_header_ops with wrapper functions that delegate to the active slave's header_ops using the slave's own device. This ensures netdev_priv() in the slave's header functions always receives the correct device. The fix is placed in the bonding driver rather than individual device drivers, as the root cause is bond blindly inheriting header_ops from the slave without considering that these callbacks expect a specific netdev_priv() layout. The type confusion can be observed by adding a printk in ipgre_header() and running the following commands: ip link add dummy0 type dummy ip addr add 10.0.0.1/24 dev dummy0 ip link set dummy0 up ip link add gre1 type gre local 10.0.0.1 ip link add bond1 type bond mode active-backup ip link set gre1 master bond1 ip link set gre1 up ip link set bond1 up ip addr add fe80::1/64 dev bond1


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Decrement re_receiving on the early exit paths In the event that rpcrdma_post_recvs() fails to create a work request (due to memory allocation failure, say) or otherwise exits early, we should decrement ep->re_receiving before returning. Otherwise we will hang in rpcrdma_xprt_drain() as re_receiving will never reach zero and the completion will never be triggered. On a system with high memory pressure, this can appear as the following hung task: INFO: task kworker/u385:17:8393 blocked for more than 122 seconds. Tainted: G S E 6.19.0 #3 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kworker/u385:17 state:D stack:0 pid:8393 tgid:8393 ppid:2 task_flags:0x4248060 flags:0x00080000 Workqueue: xprtiod xprt_autoclose [sunrpc] Call Trace: <TASK> __schedule+0x48b/0x18b0 ? ib_post_send_mad+0x247/0xae0 [ib_core] schedule+0x27/0xf0 schedule_timeout+0x104/0x110 __wait_for_common+0x98/0x180 ? __pfx_schedule_timeout+0x10/0x10 wait_for_completion+0x24/0x40 rpcrdma_xprt_disconnect+0x444/0x460 [rpcrdma] xprt_rdma_close+0x12/0x40 [rpcrdma] xprt_autoclose+0x5f/0x120 [sunrpc] process_one_work+0x191/0x3e0 worker_thread+0x2e3/0x420 ? __pfx_worker_thread+0x10/0x10 kthread+0x10d/0x230 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x273/0x2b0 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: unshare: fix unshare_fs() handling There's an unpleasant corner case in unshare(2), when we have a CLONE_NEWNS in flags and current->fs hadn't been shared at all; in that case copy_mnt_ns() gets passed current->fs instead of a private copy, which causes interesting warts in proof of correctness] > I guess if private means fs->users == 1, the condition could still be true. Unfortunately, it's worse than just a convoluted proof of correctness. Consider the case when we have CLONE_NEWCGROUP in addition to CLONE_NEWNS (and current->fs->users == 1). We pass current->fs to copy_mnt_ns(), all right. Suppose it succeeds and flips current->fs->{pwd,root} to corresponding locations in the new namespace. Now we proceed to copy_cgroup_ns(), which fails (e.g. with -ENOMEM). We call put_mnt_ns() on the namespace created by copy_mnt_ns(), it's destroyed and its mount tree is dissolved, but... current->fs->root and current->fs->pwd are both left pointing to now detached mounts. They are pinning those, so it's not a UAF, but it leaves the calling process with unshare(2) failing with -ENOMEM _and_ leaving it with pwd and root on detached isolated mounts. The last part is clearly a bug. There is other fun related to that mess (races with pivot_root(), including the one between pivot_root() and fork(), of all things), but this one is easy to isolate and fix - treat CLONE_NEWNS as "allocate a new fs_struct even if it hadn't been shared in the first place". Sure, we could go for something like "if both CLONE_NEWNS *and* one of the things that might end up failing after copy_mnt_ns() call in create_new_namespaces() are set, force allocation of new fs_struct", but let's keep it simple - the cost of copy_fs_struct() is trivial. Another benefit is that copy_mnt_ns() with CLONE_NEWNS *always* gets a freshly allocated fs_struct, yet to be attached to anything. That seriously simplifies the analysis... FWIW, that bug had been there since the introduction of unshare(2) ;-/


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registration per node Current code does no bound checking on the number of servers added per node. A malicious client can flood NEW_SERVER messages and exhaust memory. Fix this issue by limiting the maximum number of server registrations to 256 per node. If the NEW_SERVER message is received for an old port, then don't restrict it as it will get replaced. While at it, also rate limit the error messages in the failure path of qrtr_ns_worker(). Note that the limit of 256 is chosen based on the current platform requirements. If requirement changes in the future, this limit can be increased.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming reports an integer underflow in mpi_read_raw_from_sgl() when subtracting "lzeros" from the unsigned "nbytes". For this to happen, the scatterlist "sgl" needs to occupy more bytes than the "nbytes" parameter and the first "nbytes + 1" bytes of the scatterlist must be zero. Under these conditions, the while loop iterating over the scatterlist will count more zeroes than "nbytes", subtract the number of zeroes from "nbytes" and cause the underflow. When commit 2d4d1eea540b ("lib/mpi: Add mpi sgl helpers") originally introduced the bug, it couldn't be triggered because all callers of mpi_read_raw_from_sgl() passed a scatterlist whose length was equal to "nbytes". However since commit 63ba4d67594a ("KEYS: asymmetric: Use new crypto interface without scatterlists"), the underflow can now actually be triggered. When invoking a KEYCTL_PKEY_ENCRYPT system call with a larger "out_len" than "in_len" and filling the "in" buffer with zeroes, crypto_akcipher_sync_prep() will create an all-zero scatterlist used for both the "src" and "dst" member of struct akcipher_request and thereby fulfil the conditions to trigger the bug: sys_keyctl() keyctl_pkey_e_d_s() asymmetric_key_eds_op() software_key_eds_op() crypto_akcipher_sync_encrypt() crypto_akcipher_sync_prep() crypto_akcipher_encrypt() rsa_enc() mpi_read_raw_from_sgl() To the user this will be visible as a DoS as the kernel spins forever, causing soft lockup splats as a side effect. Fix it.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently infers zerocopy state from rm->m_rs, so an unqueued message can be cleaned up as if it owned normal payload pages. However, zerocopy ownership is really determined by the presence of op_mmp_znotifier, regardless of whether the message has reached the socket queue. Capture op_mmp_znotifier up front in rds_message_purge() and use it as the cleanup discriminator. If the message is already associated with a socket, keep the existing completion path. Otherwise, drop the pinned page accounting directly and release the notifier before putting the payload pages. This keeps early send failure cleanup consistent with the zerocopy lifetime rules without changing the normal queued completion path.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bpf: fix end-of-list detection in cgroup_storage_get_next_key() list_next_entry() never returns NULL -- when the current element is the last entry it wraps to the list head via container_of(). The subsequent NULL check is therefore dead code and get_next_key() never returns -ENOENT for the last element, instead reading storage->key from a bogus pointer that aliases internal map fields and copying the result to userspace. Replace it with list_entry_is_head() so the function correctly returns -ENOENT when there are no more entries.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: openvswitch: cap upcall PID array size and pre-size vport replies The vport netlink reply helpers allocate a fixed-size skb with nlmsg_new(NLMSG_DEFAULT_SIZE, ...) but serialize the full upcall PID array via ovs_vport_get_upcall_portids(). Since ovs_vport_set_upcall_portids() accepts any non-zero multiple of sizeof(u32) with no upper bound, a CAP_NET_ADMIN user can install a PID array large enough to overflow the reply buffer, causing nla_put() to fail with -EMSGSIZE and hitting BUG_ON(err < 0). On systems with unprivileged user namespaces enabled (e.g., Ubuntu default), this is reachable via unshare -Urn since OVS vport mutation operations use GENL_UNS_ADMIN_PERM. kernel BUG at net/openvswitch/datapath.c:2414! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 1 UID: 0 PID: 65 Comm: poc Not tainted 7.0.0-rc7-00195-geb216e422044 #1 RIP: 0010:ovs_vport_cmd_set+0x34c/0x400 Call Trace: <TASK> genl_family_rcv_msg_doit (net/netlink/genetlink.c:1116) genl_rcv_msg (net/netlink/genetlink.c:1194) netlink_rcv_skb (net/netlink/af_netlink.c:2550) genl_rcv (net/netlink/genetlink.c:1219) netlink_unicast (net/netlink/af_netlink.c:1344) netlink_sendmsg (net/netlink/af_netlink.c:1894) __sys_sendto (net/socket.c:2206) __x64_sys_sendto (net/socket.c:2209) do_syscall_64 (arch/x86/entry/syscall_64.c:63) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) </TASK> Kernel panic - not syncing: Fatal exception Reject attempts to set more PIDs than nr_cpu_ids in ovs_vport_set_upcall_portids(), and pre-compute the worst-case reply size in ovs_vport_cmd_msg_size() based on that bound, similar to the existing ovs_dp_cmd_msg_size(). nr_cpu_ids matches the cap already used by the per-CPU dispatch configuration on the datapath side (ovs_dp_cmd_fill_info() serialises at most nr_cpu_ids PIDs), so the two sides stay consistent.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO nf_osf_match_one() computes ctx->window % f->wss.val in the OSF_WSS_MODULO branch with no guard for f->wss.val == 0. A CAP_NET_ADMIN user can add such a fingerprint via nfnetlink; a subsequent matching TCP SYN divides by zero and panics the kernel. Reject the bogus fingerprint in nfnl_osf_add_callback() above the per-option for-loop. f->wss is per-fingerprint, not per-option, so the check must run regardless of f->opt_num (including 0). Also reject wss.wc >= OSF_WSS_MAX; nf_osf_match_one() already treats that as "should not happen". Crash: Oops: divide error: 0000 [#1] SMP KASAN NOPTI RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98) Call Trace: <IRQ> nf_osf_match (net/netfilter/nfnetlink_osf.c:220) xt_osf_match_packet (net/netfilter/xt_osf.c:32) ipt_do_table (net/ipv4/netfilter/ip_tables.c:348) nf_hook_slow (net/netfilter/core.c:622) ip_local_deliver (net/ipv4/ip_input.c:265) ip_rcv (include/linux/skbuff.h:1162) __netif_receive_skb_one_core (net/core/dev.c:6181) process_backlog (net/core/dev.c:6642) __napi_poll (net/core/dev.c:7710) net_rx_action (net/core/dev.c:7945) handle_softirqs (kernel/softirq.c:622)


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix NULL sock in aa_sock_file_perm Deal with the potential that sock and sock-sk can be NULL during socket setup or teardown. This could lead to an oops. The fix for NULL pointer dereference in __unix_needs_revalidation shows this is at least possible for af_unix sockets. While the fix for af_unix sockets applies for newer mediation this is still the fall back path for older af_unix mediation and other sockets, so ensure it is covered.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Flush cache for PASID table before using it When writing the address of a freshly allocated zero-initialized PASID table to a PASID directory entry, do that after the CPU cache flush for this PASID table, not before it, to avoid the time window when this PASID table may be already used by non-coherent IOMMU hardware while its contents in RAM is still some random old data, not zero-initialized.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths The gssx_dec_ctx(), gssx_dec_status(), and gssx_dec_name() functions allocate memory via gssx_dec_buffer(), which calls kmemdup(). When a subsequent decode operation fails, these functions return immediately without freeing previously allocated buffers, causing memory leaks. The leak in gssx_dec_ctx() is particularly relevant because the caller (gssp_accept_sec_context_upcall) initializes several buffer length fields to non-zero values, resulting in memory allocation: struct gssx_ctx rctxh = { .exported_context_token.len = GSSX_max_output_handle_sz, .mech.len = GSS_OID_MAX_LEN, .src_name.display_name.len = GSSX_max_princ_sz, .targ_name.display_name.len = GSSX_max_princ_sz }; If, for example, gssx_dec_name() succeeds for src_name but fails for targ_name, the memory allocated for exported_context_token, mech, and src_name.display_name remains unreferenced and cannot be reclaimed. Add error handling with goto-based cleanup to free any previously allocated buffers before returning an error.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix double free issue for tx spare buffer In hns3_set_ringparam(), a temporary copy (tmp_rings) of the ring structure is created for rollback. However, the tx_spare pointer in the original ring handle is incorrectly left pointing to the old backup memory. Later, if memory allocation fails in hns3_init_all_ring() during the setup, the error path attempts to free all newly allocated rings. Since tx_spare contains a stale (non-NULL) pointer from the backup, it is mistaken for a newly allocated buffer and is erroneously freed, leading to a double-free of the backup memory. The root cause is that the tx_spare field was not cleared after its value was saved in tmp_rings, leaving a dangling pointer. Fix this by setting tx_spare to NULL in the original ring structure when the creation of the new `tx_spare` fails. This ensures the error cleanup path only frees genuinely newly allocated buffers.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down PASID entry The Intel VT-d Scalable Mode PASID table entry consists of 512 bits (64 bytes). When tearing down an entry, the current implementation zeros the entire 64-byte structure immediately using multiple 64-bit writes. Since the IOMMU hardware may fetch these 64 bytes using multiple internal transactions (e.g., four 128-bit bursts), updating or zeroing the entire entry while it is active (P=1) risks a "torn" read. If a hardware fetch occurs simultaneously with the CPU zeroing the entry, the hardware could observe an inconsistent state, leading to unpredictable behavior or spurious faults. Follow the "Guidance to Software for Invalidations" in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake: 1. Clear only the 'Present' (P) bit of the PASID entry. 2. Use a dma_wmb() to ensure the cleared bit is visible to hardware before proceeding. 3. Execute the required invalidation sequence (PASID cache, IOTLB, and Device-TLB flush) to ensure the hardware has released all cached references. 4. Only after the flushes are complete, zero out the remaining fields of the PASID entry. Also, add a dma_wmb() in pasid_set_present() to ensure that all other fields of the PASID entry are visible to the hardware before the Present bit is set.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ext4: don't cache extent during splitting extent Caching extents during the splitting process is risky, as it may result in stale extents remaining in the status tree. Moreover, in most cases, the corresponding extent block entries are likely already cached before the split happens, making caching here not particularly useful. Assume we have an unwritten extent, and then DIO writes the first half. [UUUUUUUUUUUUUUUU] on-disk extent U: unwritten extent [UUUUUUUUUUUUUUUU] extent status tree |<- ->| ----> dio write this range First, when ext4_split_extent_at() splits this extent, it truncates the existing extent and then inserts a new one. During this process, this extent status entry may be shrunk, and calls to ext4_find_extent() and ext4_cache_extents() may occur, which could potentially insert the truncated range as a hole into the extent status tree. After the split is completed, this hole is not replaced with the correct status. [UUUUUUU|UUUUUUUU] on-disk extent U: unwritten extent [UUUUUUU|HHHHHHHH] extent status tree H: hole Then, the outer calling functions will not correct this remaining hole extent either. Finally, if we perform a delayed buffer write on this latter part, it will re-insert the delayed extent and cause an error in space accounting. In adition, if the unwritten extent cache is not shrunk during the splitting, ext4_cache_extents() also conflicts with existing extents when caching extents. In the future, we will add checks when caching extents, which will trigger a warning. Therefore, Do not cache extents that are being split.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix oops when split header is enabled For GMAC4, when split header is enabled, in some rare cases, the hardware does not fill buf2 of the first descriptor with payload. Thus we cannot assume buf2 is always fully filled if it is not the last descriptor. Otherwise, the length of buf2 of the second descriptor will be calculated wrong and cause an oops: Unable to handle kernel paging request at virtual address ffff00019246bfc0 ... x2 : 0000000000000040 x1 : ffff00019246bfc0 x0 : ffff00009246c000 Call trace: dcache_inval_poc+0x28/0x58 (P) dma_direct_sync_single_for_cpu+0x38/0x6c __dma_sync_single_for_cpu+0x34/0x6c stmmac_napi_poll_rx+0x8f0/0xb60 __napi_poll.constprop.0+0x30/0x144 net_rx_action+0x160/0x274 handle_softirqs+0x1b8/0x1fc ... To fix this, the PL bit-field in RDES3 register is used for all descriptors, whether it is the last descriptor or not.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leak in ext4_ext_shift_extents() In ext4_ext_shift_extents(), if the extent is NULL in the while loop, the function returns immediately without releasing the path obtained via ext4_find_extent(), leading to a memory leak. Fix this by jumping to the out label to ensure the path is properly released.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: gfs2: fix memory leaks in gfs2_fill_super error path Fix two memory leaks in the gfs2_fill_super() error handling path when transitioning a filesystem to read-write mode fails. First leak: kthread objects (thread_struct, task_struct, etc.) When gfs2_freeze_lock_shared() fails after init_threads() succeeds, the created kernel threads (logd and quotad) are never destroyed. This occurs because the fail_per_node label doesn't call gfs2_destroy_threads(). Second leak: quota bitmap buffer (8192 bytes) When gfs2_make_fs_rw() fails after gfs2_quota_init() succeeds but before other operations complete, the allocated quota bitmap is never freed. The fix moves thread cleanup to the fail_per_node label to handle all error paths uniformly. gfs2_destroy_threads() is safe to call unconditionally as it checks for NULL pointers. Quota cleanup is added in gfs2_make_fs_rw() to properly handle the withdrawal case where quota initialization succeeds but the filesystem is then withdrawn. Thread leak backtrace (gfs2_freeze_lock_shared failure): unreferenced object 0xffff88801d7bca80 (size 4480): copy_process+0x3a1/0x4670 kernel/fork.c:2422 kernel_clone+0xf3/0x6e0 kernel/fork.c:2779 kthread_create_on_node+0x100/0x150 kernel/kthread.c:478 init_threads+0xab/0x350 fs/gfs2/ops_fstype.c:611 gfs2_fill_super+0xe5c/0x1240 fs/gfs2/ops_fstype.c:1265 Quota leak backtrace (gfs2_make_fs_rw failure): unreferenced object 0xffff88812de7c000 (size 8192): gfs2_quota_init+0xe5/0x820 fs/gfs2/quota.c:1409 gfs2_make_fs_rw+0x7a/0xe0 fs/gfs2/super.c:149 gfs2_fill_super+0xfbb/0x1240 fs/gfs2/ops_fstype.c:1275


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path Commit 5940d1cf9f42 ("SUNRPC: Rebalance a kref in auth_gss.c") added a kref_get(&gss_auth->kref) call to balance the gss_put_auth() done in gss_release_msg(), but forgot to add a corresponding kref_put() on the error path when kstrdup_const() fails. If service_name is non-NULL and kstrdup_const() fails, the function jumps to err_put_pipe_version which calls put_pipe_version() and kfree(gss_msg), but never releases the gss_auth reference. This leads to a kref leak where the gss_auth structure is never freed. Add a forward declaration for gss_free_callback() and call kref_put() in the err_put_pipe_version error path to properly release the reference taken earlier.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix invalid deref of rawdata when export_binary is unset If the export_binary parameter is disabled on runtime, profiles that were loaded before that will still have their rawdata stored in apparmorfs, with a symbolic link to the rawdata on the policy directory. When one of those profiles are replaced, the rawdata is set to NULL, but when trying to resolve the symbolic links to rawdata for that profile, it will try to dereference profile->rawdata->name when profile->rawdata is now NULL causing an oops. Fix it by checking if rawdata is set. [ 168.653080] BUG: kernel NULL pointer dereference, address: 0000000000000088 [ 168.657420] #PF: supervisor read access in kernel mode [ 168.660619] #PF: error_code(0x0000) - not-present page [ 168.663613] PGD 0 P4D 0 [ 168.665450] Oops: Oops: 0000 [#1] SMP NOPTI [ 168.667836] CPU: 1 UID: 0 PID: 1729 Comm: ls Not tainted 6.19.0-rc7+ #3 PREEMPT(voluntary) [ 168.672308] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 168.679327] RIP: 0010:rawdata_get_link_base.isra.0+0x23/0x330 [ 168.682768] Code: 90 90 90 90 90 90 90 0f 1f 44 00 00 55 48 89 e5 41 57 41 56 41 55 41 54 53 48 83 ec 18 48 89 55 d0 48 85 ff 0f 84 e3 01 00 00 <48> 83 3c 25 88 00 00 00 00 0f 84 d4 01 00 00 49 89 f6 49 89 cc e8 [ 168.689818] RSP: 0018:ffffcdcb8200fb80 EFLAGS: 00010282 [ 168.690871] RAX: ffffffffaee74ec0 RBX: 0000000000000000 RCX: ffffffffb0120158 [ 168.692251] RDX: ffffcdcb8200fbe0 RSI: ffff88c187c9fa80 RDI: ffff88c186c98a80 [ 168.693593] RBP: ffffcdcb8200fbc0 R08: 0000000000000000 R09: 0000000000000000 [ 168.694941] R10: 0000000000000000 R11: 0000000000000000 R12: ffff88c186c98a80 [ 168.696289] R13: 00007fff005aaa20 R14: 0000000000000080 R15: ffff88c188f4fce0 [ 168.697637] FS: 0000790e81c58280(0000) GS:ffff88c20a957000(0000) knlGS:0000000000000000 [ 168.699227] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 168.700349] CR2: 0000000000000088 CR3: 000000012fd3e000 CR4: 0000000000350ef0 [ 168.701696] Call Trace: [ 168.702325] <TASK> [ 168.702995] rawdata_get_link_data+0x1c/0x30 [ 168.704145] vfs_readlink+0xd4/0x160 [ 168.705152] do_readlinkat+0x114/0x180 [ 168.706214] __x64_sys_readlink+0x1e/0x30 [ 168.708653] x64_sys_call+0x1d77/0x26b0 [ 168.709525] do_syscall_64+0x81/0x500 [ 168.710348] ? do_statx+0x72/0xb0 [ 168.711109] ? putname+0x3e/0x80 [ 168.711845] ? __x64_sys_statx+0xb7/0x100 [ 168.712711] ? x64_sys_call+0x10fc/0x26b0 [ 168.713577] ? do_syscall_64+0xbf/0x500 [ 168.714412] ? do_user_addr_fault+0x1d2/0x8d0 [ 168.715404] ? irqentry_exit+0xb2/0x740 [ 168.716359] ? exc_page_fault+0x90/0x1b0 [ 168.717307] entry_SYSCALL_64_after_hwframe+0x76/0x7e


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found If btrfs_search_slot_for_read() returns 1, it means we did not find any key greater than or equals to the key we asked for, meaning we have reached the end of the tree and therefore the path is not valid. If this happens we need to break out of the loop and stop, instead of continuing and accessing an invalid path.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O When allocating blocks during within-EOF DIO and writeback with dioread_nolock enabled, EXT4_GET_BLOCKS_PRE_IO was set to split an existing large unwritten extent. However, EXT4_GET_BLOCKS_CONVERT was set when calling ext4_split_convert_extents(), which may potentially result in stale data issues. Assume we have an unwritten extent, and then DIO writes the second half. [UUUUUUUUUUUUUUUU] on-disk extent U: unwritten extent [UUUUUUUUUUUUUUUU] extent status tree |<- ->| ----> dio write this range First, ext4_iomap_alloc() call ext4_map_blocks() with EXT4_GET_BLOCKS_PRE_IO, EXT4_GET_BLOCKS_UNWRIT_EXT and EXT4_GET_BLOCKS_CREATE flags set. ext4_map_blocks() find this extent and call ext4_split_convert_extents() with EXT4_GET_BLOCKS_CONVERT and the above flags set. Then, ext4_split_convert_extents() calls ext4_split_extent() with EXT4_EXT_MAY_ZEROOUT, EXT4_EXT_MARK_UNWRIT2 and EXT4_EXT_DATA_VALID2 flags set, and it calls ext4_split_extent_at() to split the second half with EXT4_EXT_DATA_VALID2, EXT4_EXT_MARK_UNWRIT1, EXT4_EXT_MAY_ZEROOUT and EXT4_EXT_MARK_UNWRIT2 flags set. However, ext4_split_extent_at() failed to insert extent since a temporary lack -ENOSPC. It zeroes out the first half but convert the entire on-disk extent to written since the EXT4_EXT_DATA_VALID2 flag set, but left the second half as unwritten in the extent status tree. [0000000000SSSSSS] data S: stale data, 0: zeroed [WWWWWWWWWWWWWWWW] on-disk extent W: written extent [WWWWWWWWWWUUUUUU] extent status tree Finally, if the DIO failed to write data to the disk, the stale data in the second half will be exposed once the cached extent entry is gone. Fix this issue by not passing EXT4_GET_BLOCKS_CONVERT when splitting an unwritten extent before submitting I/O, and make ext4_split_convert_extents() to zero out the entire extent range to zero for this case, and also mark the extent in the extent status tree for consistency.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfs: fix a resource leak in xfs_alloc_buftarg() In the error path, call fs_put_dax() to drop the DAX device reference.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - snapshot IV for async AEAD requests AF_ALG AEAD AIO requests currently use the socket-wide IV buffer during request processing. For async requests, later socket activity can update that shared state before the original request has fully completed, which can lead to inconsistent IV handling. Snapshot the IV into per-request storage when preparing the AEAD request, so in-flight operations no longer depend on mutable socket state.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: validate reply type before using icmp_pointers Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type. That value is outside the range covered by icmp_pointers[], which only describes the traditional ICMP types up to NR_ICMP_TYPES. Avoid consulting icmp_pointers[] for reply types outside that range, and use array_index_nospec() for the remaining in-range lookup. Normal ICMP replies keep their existing behavior unchanged.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: rds: fix MR cleanup on copy error __rds_rdma_map() hands sg/pages ownership to the transport after get_mr() succeeds. If copying the generated cookie back to user space fails after that point, the error path must not free those resources again before dropping the MR reference. Remove the duplicate unpin/free from the put_user() failure branch so that MR teardown is handled only through the existing final cleanup path.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: x86/shstk: Prevent deadlock during shstk sigreturn During sigreturn the shadow stack signal frame is popped. The kernel does this by reading the shadow stack using normal read accesses. When it can't assume the memory is shadow stack, it takes extra steps to makes sure it is reading actual shadow stack memory and not other normal readable memory. It does this by holding the mmap read lock while doing the access and checking the flags of the VMA. Unfortunately that is not safe. If the read of the shadow stack sigframe hits a page fault, the fault handler will try to recursively grab another mmap read lock. This normally works ok, but if a writer on another CPU is also waiting, the second read lock could fail and cause a deadlock. Fix this by not holding mmap lock during the read access to userspace. Instead use mmap_lock_speculate_...() to watch for changes between dropping mmap lock and the userspace access. Retry if anything grabbed an mmap write lock in between and could have changed the VMA. These mmap_lock_speculate_...() helpers use mm::mm_lock_seq, which is only available when PER_VMA_LOCK is configured. So make X86_USER_SHADOW_STACK depend on it. On x86, PER_VMA_LOCK is a default configuration for SMP kernels. So drop support for the other configs under the assumption that the !SMP shadow stack user base does not exist. Currently there is a check that skips the lookup work when the SSP can be assumed to be on a shadow stack. While reorganizing the function, remove the optimization to make the tricky code flows more common, such that issues like this cannot escape detection for so long.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info Hold state of deferred I/O in struct fb_deferred_io_state. Allocate an instance as part of initializing deferred I/O and remove it only after the final mapping has been closed. If the fb_info and the contained deferred I/O meanwhile goes away, clear struct fb_deferred_io_state.info to invalidate the mapping. Any access will then result in a SIGBUS signal. Fixes a long-standing problem, where a device hot-unplug happens while user space still has an active mapping of the graphics memory. The hot- unplug frees the instance of struct fb_info. Accessing the memory will operate on undefined state.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() The mwifiex_adapter_cleanup() function uses timer_delete() (non-synchronous) for the wakeup_timer before the adapter structure is freed. This is incorrect because timer_delete() does not wait for any running timer callback to complete. If the wakeup_timer callback (wakeup_timer_fn) is executing when mwifiex_adapter_cleanup() is called, the callback will continue to access adapter fields (adapter->hw_status, adapter->if_ops.card_reset, etc.) which may be freed by mwifiex_free_adapter() called later in the mwifiex_remove_card() path. Use timer_delete_sync() instead to ensure any running timer callback has completed before returning.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 svm_copy_lbrs() always marks VMCB_LBR dirty in the destination VMCB. However, nested_svm_vmexit() uses it to copy LBRs to vmcb12, and clearing clean bits in vmcb12 is not architecturally defined. Move vmcb_mark_dirty() to callers and drop it for vmcb12. This also facilitates incoming refactoring that does not pass the entire VMCB to svm_copy_lbrs().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 Explicitly synthesize a #UD for VMMCALL if L2 is active, L1 does NOT want to intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the hypercall is something other than one of the supported Hyper-V hypercalls. When all of the above conditions are met, KVM will intercept VMMCALL but never forward it to L1, i.e. will let L2 make hypercalls as if it were L1. The TLFS says a whole lot of nothing about this scenario, so go with the architectural behavior, which says that VMMCALL #UDs if it's not intercepted. Opportunistically do a 2-for-1 stub trade by stub-ifying the new API instead of the helpers it uses. The last remaining "single" stub will soon be dropped as well. [sean: rewrite changelog and comment, tag for stable, remove defunct stubs]


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: reject zero shift in nft_bitwise Reject zero shift operands for nft_bitwise left and right shift expressions during initialization. The carry propagation logic computes the carry from the adjacent 32-bit word using BITS_PER_TYPE(u32) - shift. A zero shift operand turns this into a 32-bit shift, which is undefined behaviour. Reject zero shift operands in the control plane, alongside the existing check for values greater than or equal to 32, so malformed rules never reach the packet path.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() Sashiko points out that hns_roce_qp_remove() requires the caller to hold locks. The error flow in hns_roce_create_qp_common() doesn't hold those locks for the error unwind so it risks corrupting memory. Grab the same locks the other two callers use.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s hlist_del_rcu calls under syzkaller load on linux-6.12.y stable (reproduced on 6.12.47, also reachable via the same code path on torvalds/master and on the ipsec tree). Nine unique signatures cluster in the xfrm_state lifecycle, the load-bearing one being: BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline] BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline] BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435 Workqueue: netns cleanup_net Call Trace: __hlist_del / hlist_del_rcu __xfrm_state_delete xfrm_state_delete xfrm_state_flush xfrm_state_fini ops_exit_list cleanup_net The other observed signatures hit the same slab object from __xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB write variant of __xfrm_state_delete, all on the byseq/byspi hash chains. __xfrm_state_delete() guards its byseq and byspi unhashes with value-based predicates: if (x->km.seq) hlist_del_rcu(&x->byseq); if (x->id.spi) hlist_del_rcu(&x->byspi); while everywhere else in the file (e.g. state_cache, state_cache_input) the safer hlist_unhashed() check is used. xfrm_alloc_spi() sets x->id.spi = newspi inside xfrm_state_lock and then immediately inserts into byspi, but a path that observes x->id.spi != 0 outside of xfrm_state_lock can still skip-or-hit the byspi unhash inconsistently with whether x is actually on the list. The same holds for x->km.seq versus byseq, and the bydst/bysrc unhashes have no predicate at all, so a second __xfrm_state_delete() on the same object writes through LIST_POISON pprev. The defensive change here: - Use hlist_del_init_rcu() instead of hlist_del_rcu() on bydst, bysrc, byseq and byspi so a second deletion is a no-op rather than a write through LIST_POISON pprev. The byseq/byspi nodes are already initialised in xfrm_state_alloc(). - Test hlist_unhashed() rather than the value predicate for byseq/byspi, so the unhash decision tracks list state rather than mutable scalar fields. Empirical verification: applied this patch on top of v6.12.47, rebuilt, and re-ran the same syzkaller harness for 1h16m on a previously-crashy configuration that produced ~100 hits each of slab-use-after-free Read in xfrm_alloc_spi / Read in __xfrm_state_lookup / Write in __xfrm_state_delete. After the patch, 7.1M execs across 32 VMs at ~1550 exec/sec produced zero xfrm_state UAF/OOB hits. /proc/slabinfo confirms the xfrm_state slab is actively allocated and freed during the run (~143 KiB resident), so the fuzzer is still exercising those code paths -- they just no longer crash. Reproduction: - Linux 6.12.47 x86_64 + KASAN_GENERIC + KASAN_INLINE + KCOV - syzkaller @ 746545b8b1e4c3a128db8652b340d3df90ce61db - 32 QEMU/KVM VMs x 2 vCPU on AWS c5.metal bare metal - 9 unique signatures collected in ~9h, all within xfrm_state lifecycle


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth message processing If a (potentially corrupted) message of type CEPH_MSG_AUTH_REPLY contains a positive value in its result field, it is treated as an error code by ceph_handle_auth_reply() and returned to handle_auth_reply(). Thereafter, an attempt is made to send the preallocated message of type CEPH_MSG_AUTH, where the returned value is interpreted as the size of the front segment to send. If the result value in the message is greater than the size of the memory buffer allocated for the front segment, an out-of-bounds access occurs, and the content of the memory region beyond this buffer is sent out. This patch fixes the issue by treating only negative values in the result field as errors. Positive values are therefore treated as success in the same way as a zero value. Additionally, a BUG_ON is added to __send_prepared_auth_request() comparing the len parameter to front_alloc_len to prevent sending the message if it exceeds the bounds of the allocation and to make it easier to catch any logic flaws leading to this.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ip6_gre: Use cached t->net in ip6erspan_changelink(). After commit 5e72ce3e3980 ("net: ipv6: Use link netns in newlink() of rtnl_link_ops"), ip6erspan_newlink() correctly resolves the per-netns ip6gre hash via link_net. ip6erspan_changelink() was not converted in that series and still uses dev_net(dev), which diverges from the device's creation netns after IFLA_NET_NS_FD migration. This re-inserts the tunnel into the wrong per-netns hash. The original netns keeps a stale entry. When that netns is later destroyed, ip6gre_exit_rtnl_net() walks the stale entry, producing a slab-use-after-free reported by KASAN, followed by a kernel BUG at net/core/dev.c (LIST_POISON1) in unregister_netdevice_many_notify(). Reachable from an unprivileged user namespace (unshare --user --map-root-user --net). ip6gre_changelink() earlier in the same file already uses the cached t->net; only ip6erspan_changelink() has the wrong shape.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: clamp rx length before skb_put virtbt_rx_work() calls skb_put(skb, len) where len comes directly from virtqueue_get_buf() with no validation against the buffer we posted to the device. The RX skb is allocated in virtbt_add_inbuf() and exposed to virtio as exactly 1000 bytes via sg_init_one(). Checking len against skb_tailroom(skb) is not sufficient because alloc_skb() can leave more tailroom than the 1000 bytes actually handed to the device. A malicious or buggy backend can therefore report used.len between 1001 and skb_tailroom(skb), causing skb_put() to include uninitialized kernel heap bytes that were never written by the device. The same path also accepts len == 0, in which case skb_put(skb, 0) leaves the skb empty but virtbt_rx_handle() still reads the pkt_type byte from skb->data, consuming uninitialized memory. Define VIRTBT_RX_BUF_SIZE once and reuse it in alloc_skb() and sg_init_one(), and gate virtbt_rx_work() on that same constant so the bound checked matches the buffer actually exposed to the device. Reject used.len == 0 in the same gate so an empty completion can no longer reach virtbt_rx_handle(). Use bt_dev_err_ratelimited() because the length value comes from an untrusted backend that can otherwise flood the kernel log. Same class of bug as commit c04db81cd028 ("net/9p: Fix buffer overflow in USB transport layer"), which hardened the USB 9p transport against unchecked device-reported length.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: isofs: validate block number from NFS file handle in isofs_export_iget isofs_fh_to_dentry() and isofs_fh_to_parent() pass an attacker- controlled block number (ifid->block or ifid->parent_block) from the NFS file handle to isofs_export_iget(), which only rejects block == 0 before calling isofs_iget() and ultimately sb_bread(). A crafted file handle with fh_len sufficient to pass the check added by commit 0405d4b63d08 ("isofs: Prevent the use of too small fid") can still drive the server to read any in-range block on the backing device as if it were an iso_directory_record. That earlier fix was assigned CVE-2025-37780. sb_bread() on an out-of-range block returns NULL cleanly via the EIO path, so there is no memory-safety violation. For in-range reads of adjacent-partition data on the same block device, the unrelated bytes end up in iso_inode_info fields that reach the NFS client as dentry metadata. The deployment surface (isofs exported over NFS from loop-mounted images) is narrow and requires an authenticated NFS peer, but the malformed-file-handle class is reportable as hardening next to the existing CVE-2025-37780 fix. Reject block >= ISOFS_SB(sb)->s_nzones in isofs_export_iget() so the check covers both isofs_fh_to_dentry() and isofs_fh_to_parent() call sites with a single line.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Reject unknown opcodes before ICRC processing Even after applying commit 7244491dab34 ("RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv"), a single unauthenticated UDP packet can still trigger panic. That patch handled payload_size() underflow only for valid opcodes with short packets, not for packets carrying an unknown opcode. The unknown-opcode OOB read described below predates that commit and reaches back to the initial Soft RoCE driver. The check added there reads pkt->paylen < header_size(pkt) + bth_pad(pkt) + RXE_ICRC_SIZE where header_size(pkt) expands to rxe_opcode[pkt->opcode].length. The rxe_opcode[] array has 256 entries but is only populated for defined IB opcodes; any other entry (for example opcode 0xff) is zero-initialized, so length == 0 and the check degenerates to pkt->paylen < 0 + bth_pad(pkt) + RXE_ICRC_SIZE which does not constrain pkt->paylen enough. rxe_icrc_hdr() then computes rxe_opcode[pkt->opcode].length - RXE_BTH_BYTES which underflows when length == 0 and passes a huge value to rxe_crc32(), causing an out-of-bounds read of the skb payload. Reproduced on v7.0-rc7 with that fix applied, QEMU/KVM with CONFIG_RDMA_RXE=y and CONFIG_KASAN=y, after rdma link add rxe0 type rxe netdev eth0 A single 48-byte UDP packet to port 4791 with BTH opcode=0xff and QPN=IB_MULTICAST_QPN triggers: BUG: KASAN: slab-out-of-bounds in crc32_le+0x115/0x170 Read of size 1 at addr ... The buggy address is located 0 bytes to the right of allocated 704-byte region Call Trace: crc32_le+0x115/0x170 rxe_icrc_hdr.isra.0+0x226/0x300 rxe_icrc_check+0x13f/0x3a0 rxe_rcv+0x6e1/0x16e0 rxe_udp_encap_recv+0x20a/0x320 udp_queue_rcv_one_skb+0x7ed/0x12c0 Subsequent packets with the same shape fault on unmapped memory and panic the kernel. The trigger requires only module load and "rdma link add"; no QP, no connection, and no authentication. Fix this by rejecting packets whose opcode has no rxe_opcode[] entry, detected via the zero mask or zero length, before any length arithmetic runs.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission events fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check. Fix by skipping over detached marks that are not in the current group.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix missing last_unlink_trans update when removing a directory When removing a directory we are not updating its last_unlink_trans field, which can result in incorrect fsync behaviour in case some one fsyncs the directory after it was removed because it's holding a file descriptor on it. Example scenario: mkdir /mnt/dir1 mkdir /mnt/dir1/dir2 mkdir /mnt/dir3 sync -f /mnt # Do some change to the directory and fsync it. chmod 700 /mnt/dir1 xfs_io -c fsync /mnt/dir1 # Move dir2 out of dir1 so that dir1 becomes empty. mv /mnt/dir1/dir2 /mnt/dir3/ open fd on /mnt/dir1 call rmdir(2) on path "/mnt/dir1" fsync fd <trigger power failure> When attempting to mount the filesystem, the log replay will fail with an -EIO error and dmesg/syslog has the following: [445771.626482] BTRFS info (device dm-0): first mount of filesystem 0368bbea-6c5e-44b5-b409-09abe496e650 [445771.626486] BTRFS info (device dm-0): using crc32c checksum algorithm [445771.627912] BTRFS info (device dm-0): start tree-log replay [445771.628335] page: refcount:2 mapcount:0 mapping:0000000061443ddc index:0x1d00 pfn:0x7072a5 [445771.629453] memcg:ffff89f400351b00 [445771.629892] aops:btree_aops [btrfs] ino:1 [445771.630737] flags: 0x17fffc00000402a(uptodate|lru|private|writeback|node=0|zone=2|lastcpupid=0x1ffff) [445771.632359] raw: 017fffc00000402a fffff47284d950c8 fffff472907b7c08 ffff89f458e412b8 [445771.633713] raw: 0000000000001d00 ffff89f6c51d1a90 00000002ffffffff ffff89f400351b00 [445771.635029] page dumped because: eb page dump [445771.635825] BTRFS critical (device dm-0): corrupt leaf: root=5 block=30408704 slot=10 ino=258, invalid nlink: has 2 expect no more than 1 for dir [445771.638088] BTRFS info (device dm-0): leaf 30408704 gen 10 total ptrs 17 free space 14878 owner 5 [445771.638091] BTRFS info (device dm-0): refs 4 lock_owner 0 current 3581087 [445771.638094] item 0 key (256 INODE_ITEM 0) itemoff 16123 itemsize 160 [445771.638097] inode generation 3 transid 9 size 16 nbytes 16384 [445771.638098] block group 0 mode 40755 links 1 uid 0 gid 0 [445771.638100] rdev 0 sequence 2 flags 0x0 [445771.638102] atime 1775744884.0 [445771.660056] ctime 1775744885.645502983 [445771.660058] mtime 1775744885.645502983 [445771.660060] otime 1775744884.0 [445771.660062] item 1 key (256 INODE_REF 256) itemoff 16111 itemsize 12 [445771.660064] index 0 name_len 2 [445771.660066] item 2 key (256 DIR_ITEM 1843588421) itemoff 16077 itemsize 34 [445771.660068] location key (259 1 0) type 2 [445771.660070] transid 9 data_len 0 name_len 4 [445771.660075] item 3 key (256 DIR_ITEM 2363071922) itemoff 16043 itemsize 34 [445771.660076] location key (257 1 0) type 2 [445771.660077] transid 9 data_len 0 name_len 4 [445771.660078] item 4 key (256 DIR_INDEX 2) itemoff 16009 itemsize 34 [445771.660079] location key (257 1 0) type 2 [445771.660080] transid 9 data_len 0 name_len 4 [445771.660081] item 5 key (256 DIR_INDEX 3) itemoff 15975 itemsize 34 [445771.660082] location key (259 1 0) type 2 [445771.660083] transid 9 data_len 0 name_len 4 [445771.660084] item 6 key (257 INODE_ITEM 0) itemoff 15815 itemsize 160 [445771.660086] inode generation 9 transid 9 size 8 nbytes 0 [445771.660087] block group 0 mode 40777 links 1 uid 0 gid 0 [445771.660088] rdev 0 sequence 2 flags 0x0 [445771.660089] atime 1775744885.641174097 [445771.660090] ctime 1775744885.645502983 [445771.660091] mtime 1775744885.645502983 [445771.660105] otime 1775744885.641174097 [445771.660106] item 7 key (257 INODE_REF 256) itemoff 15801 itemsize 14 [445771.660107] index 2 name_len 4 [445771.660108] item 8 key (257 DIR_ITEM 2676584006) itemoff 15767 itemsize 34 [445771.660109] location key (2 ---truncated---


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ice: fix double free in ice_sf_eth_activate() error path When auxiliary_device_add() fails, ice_sf_eth_activate() jumps to aux_dev_uninit and calls auxiliary_device_uninit(&sf_dev->adev). The device release callback ice_sf_dev_release() frees sf_dev, but the current error path falls through to sf_dev_free and calls kfree(sf_dev) again, causing a double free. Keep kfree(sf_dev) for the auxiliary_device_init() failure path, but avoid falling through to sf_dev_free after auxiliary_device_uninit().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() xfrm6_rcv_encap() performs an IPv6 route lookup when the skb does not already have a dst attached. ip6_route_input_lookup() returns a referenced dst entry even when the lookup resolves to an error route. If dst->error is set, xfrm6_rcv_encap() drops the skb without attaching the dst to the skb and without releasing the reference returned by the lookup. Repeated packets hitting this path therefore leak dst entries. Release the dst before jumping to the drop path.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: exit: prevent preemption of oopsing TASK_DEAD task When an already-exiting task oopses, make_task_dead() currently calls do_task_dead() with preemption enabled. That is forbidden: do_task_dead() calls __schedule(), which has a comment saying "WARNING: must be called with preemption disabled!". If an oopsing task is preempted in do_task_dead(), between becoming TASK_DEAD and entering the scheduler explicitly, bad things happen: finish_task_switch() assumes that once the scheduler has switched away from a TASK_DEAD task, the task can never run again and its stack is no longer needed; but that assumption apparently doesn't hold if the dead task was preempted (the SM_PREEMPT case). This means that the scheduler ends up repeatedly dropping references on the dead task's stack, which can lead to use-after-free or double-free of the entire task stack; in other words, two tasks can end up running on the same stack, resulting in various kinds of memory corruption. (This does not just affect "recursively oopsing" tasks; it is enough to oops once during task exit, for example in a file_operations::release handler)


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data() Since smb2_check_message() returns success without length validation for the symlink error response, in symlink_data() it is possible for iov->iov_len to be smaller than sizeof(struct smb2_err_rsp). If the buffer only contains the base SMB2 header (64 bytes), accessing err->ErrorContextCount (at offset 66) or err->ByteCount later in symlink_data() will cause an out-of-bounds read.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: validate SVM ioctl nattr against buffer size Validate nattr field against the buffer size, preventing out-of-bounds buffer access via user-controlled attribute count. (cherry picked from commit 5eca8bfdfa456c3304ca77523718fe24254c172f)


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix accept queue count leak on transport mismatch virtio_transport_recv_listen() calls sk_acceptq_added() before vsock_assign_transport(). If vsock_assign_transport() fails or selects a different transport, the error path returns without calling sk_acceptq_removed(), permanently incrementing sk_ack_backlog. After approximately backlog+1 such failures, sk_acceptq_is_full() returns true, causing the listener to reject all new connections. Fix by moving sk_acceptq_added() to after the transport validation, matching the pattern used by vmci_transport and hyperv_transport.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL The SCTP_SENDALL path in sctp_sendmsg() iterates ep->asocs with list_for_each_entry_safe(), which caches the next entry in @tmp before the loop body runs. The body calls sctp_sendmsg_to_asoc(), which may drop the socket lock inside sctp_wait_for_sndbuf(). While the lock is dropped, another thread can SCTP_SOCKOPT_PEELOFF the association cached in @tmp, migrating it to a new endpoint via sctp_sock_migrate() (list_del_init() + list_add_tail() to newep->asocs), and optionally close the new socket which frees the association via kfree_rcu(). The cached @tmp can also be freed by a network ABORT for that association, processed in softirq while the lock is dropped. sctp_wait_for_sndbuf() revalidates @asoc (the current entry) on re-lock via the "sk != asoc->base.sk" and "asoc->base.dead" checks, but nothing revalidates @tmp. After a successful return, the iterator advances to the stale @tmp, yielding either a use-after-free (if the peeled socket was closed) or a list-walk onto the new endpoint's list head (type confusion of &newep->asocs as a struct sctp_association *). Both are reachable from CapEff=0; the type-confusion path gives controlled indirect call via the outqueue.sched->init_sid pointer. Fix by re-deriving @tmp from @asoc after sctp_sendmsg_to_asoc() returns. @asoc is known to still be on ep->asocs at that point: the only callers that list_del an association from ep->asocs are sctp_association_free() (which sets asoc->base.dead) and sctp_assoc_migrate() (which changes asoc->base.sk), and sctp_wait_for_sndbuf() checks both under the lock before any successful return; a tripped check propagates as err < 0 and the loop bails before the re-derive. The SCTP_ABORT path in sctp_sendmsg_check_sflags() returns 0 and the loop hits 'continue' before sctp_sendmsg_to_asoc() is ever called, so the @tmp cached by list_for_each_entry_safe() still covers the lock-held free that ba59fb027307 ("sctp: walk the list of asoc safely") was added for.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure KFD VRAM allocations set AMDGPU_GEM_CREATE_VRAM_WIPE_ON_RELEASE but not AMDGPU_GEM_CREATE_VRAM_CLEARED, leaving freshly allocated VRAM with stale data from prior use observable by compute kernels. The GEM ioctl path already sets VRAM_CLEARED for all userspace allocations via amdgpu_gem_create_ioctl() and amdgpu_mode_dumb_create(). The KFD path was missing this flag, allowing stale page table remnants to leak into user buffers. This causes crashes in RCCL P2P transport where non-zero data in ptrExchange/head/tail fields corrupts the protocol handshake.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset traversing all extension headers, but the result is immediately overwritten with nhoff + sizeof(_ip6h) (40 bytes), which only accounts for the IPv6 base header. This creates a desync between inner_thoff (wrong - points to extension header start) and l4proto (correct - e.g., IPPROTO_TCP), enabling transport header forgery and potential firewall bypass. This issue affects stable versions from Linux 6.2. For comparison, the normal (non-inner) IPv6 path correctly preserves ipv6_find_hdr()'s result. Removing the incorrect overwrite ensures that ipv6_find_hdr()'s calculated transport header offset is preserved, thereby fixing the desynchronization.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: pstore/ram: fix buffer overflow in persistent_ram_save_old() persistent_ram_save_old() can be called multiple times for the same persistent_ram_zone (e.g., via ramoops_pstore_read -> ramoops_get_next_prz for PSTORE_TYPE_DMESG records). Currently, the function only allocates prz->old_log when it is NULL, but it unconditionally updates prz->old_log_size to the current buffer size and then performs memcpy_fromio() using this new size. If the buffer size has grown since the first allocation (which can happen across different kernel boot cycles), this leads to: 1. A heap buffer overflow (OOB write) in the memcpy_fromio() calls 2. A subsequent OOB read when ramoops_pstore_read() accesses the buffer using the incorrect (larger) old_log_size The KASAN splat would look similar to: BUG: KASAN: slab-out-of-bounds in ramoops_pstore_read+0x... Read of size N at addr ... by task ... The conditions are likely extremely hard to hit: 0. Crash with a ramoops write of less-than-record-max-size bytes. 1. Reboot: ramoops registers, pstore_get_records(0) reads old crash, allocates old_log with size X 2. Crash handler registered, timer started (if pstore_update_ms >= 0) 3. Oops happens (non-fatal, system continues) 4. pstore_dump() writes oops via ramoops_pstore_write() size Y (>X) 5. pstore_new_entry = 1, pstore_timer_kick() called 6. System continues running (not a panic oops) 7. Timer fires after pstore_update_ms milliseconds 8. pstore_timefunc() -> schedule_work() -> pstore_dowork() -> pstore_get_records(1) 9. ramoops_get_next_prz() -> persistent_ram_save_old() 10. buffer_size() returns Y, but old_log is X bytes 11. Y > X: memcpy_fromio() overflows heap Requirements: - a prior crash record exists that did not fill the record size (almost impossible since the crash handler writes as much as it can possibly fit into the record, capped by max record size and the kmsg buffer almost always exceeds the max record size) - pstore_update_ms >= 0 (disabled by default) - Non-fatal oops (system survives) Free and reallocate the buffer when the new size differs from the previously allocated size. This ensures old_log always has sufficient space for the data being copied.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: AppArmor: Allow apparmor to handle unaligned dfa tables The dfa tables can originate from kernel or userspace and 8-byte alignment isn't always guaranteed and as such may trigger unaligned memory accesses on various architectures. Resulting in the following [ 73.901376] WARNING: CPU: 0 PID: 341 at security/apparmor/match.c:316 aa_dfa_unpack+0x6cc/0x720 [ 74.015867] Modules linked in: binfmt_misc evdev flash sg drm drm_panel_orientation_quirks backlight i2c_core configfs nfnetlink autofs4 ext4 crc16 mbcache jbd2 hid_generic usbhid sr_mod hid cdrom sd_mod ata_generic ohci_pci ehci_pci ehci_hcd ohci_hcd pata_ali libata sym53c8xx scsi_transport_spi tg3 scsi_mod usbcore libphy scsi_common mdio_bus usb_common [ 74.428977] CPU: 0 UID: 0 PID: 341 Comm: apparmor_parser Not tainted 6.18.0-rc6+ #9 NONE [ 74.536543] Call Trace: [ 74.568561] [<0000000000434c24>] dump_stack+0x8/0x18 [ 74.633757] [<0000000000476438>] __warn+0xd8/0x100 [ 74.696664] [<00000000004296d4>] warn_slowpath_fmt+0x34/0x74 [ 74.771006] [<00000000008db28c>] aa_dfa_unpack+0x6cc/0x720 [ 74.843062] [<00000000008e643c>] unpack_pdb+0xbc/0x7e0 [ 74.910545] [<00000000008e7740>] unpack_profile+0xbe0/0x1300 [ 74.984888] [<00000000008e82e0>] aa_unpack+0xe0/0x6a0 [ 75.051226] [<00000000008e3ec4>] aa_replace_profiles+0x64/0x1160 [ 75.130144] [<00000000008d4d90>] policy_update+0xf0/0x280 [ 75.201057] [<00000000008d4fc8>] profile_replace+0xa8/0x100 [ 75.274258] [<0000000000766bd0>] vfs_write+0x90/0x420 [ 75.340594] [<00000000007670cc>] ksys_write+0x4c/0xe0 [ 75.406932] [<0000000000767174>] sys_write+0x14/0x40 [ 75.472126] [<0000000000406174>] linux_sparc_syscall+0x34/0x44 [ 75.548802] ---[ end trace 0000000000000000 ]--- [ 75.609503] dfa blob stream 0xfff0000008926b96 not aligned. [ 75.682695] Kernel unaligned access at TPC[8db2a8] aa_dfa_unpack+0x6e8/0x720 Work around it by using the get_unaligned_xx() helpers.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: procfs: fix missing RCU protection when reading real_parent in do_task_stat() When reading /proc/[pid]/stat, do_task_stat() accesses task->real_parent without proper RCU protection, which leads to: cpu 0 cpu 1 ----- ----- do_task_stat var = task->real_parent release_task call_rcu(delayed_put_task_struct) task_tgid_nr_ns(var) rcu_read_lock <--- Too late to protect task->real_parent! task_pid_ptr <--- UAF! rcu_read_unlock This patch uses task_ppid_nr_ns() instead of task_tgid_nr_ns() to add proper RCU protection for accessing task->real_parent.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reported that simply having one RAW socket on protocol IPPROTO_RAW (255) was dangerous. socket(AF_INET, SOCK_RAW, 255); A malicious incoming ICMP packet can set the protocol field to 255 and match this socket, leading to FNHE cache changes. inner = IP(src="192.168.2.1", dst="8.8.8.8", proto=255)/Raw("TEST") pkt = IP(src="192.168.1.1", dst="192.168.2.1")/ICMP(type=3, code=4, nexthopmtu=576)/inner "man 7 raw" states: A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able to send any IP protocol that is specified in the passed header. Receiving of all IP protocols via IPPROTO_RAW is not possible using raw sockets. Make sure we drop these malicious packets.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power systems do not support segmentation offload when the MSS is less than 224 bytes. Attempting to send such packets causes the adapter to freeze, stopping all traffic until manually reset. Implement ndo_features_check to disable GSO for packets with small MSS values. The network stack will perform software segmentation instead. The 224-byte minimum matches ibmvnic commit <f10b09ef687f> ("ibmvnic: Enforce stronger sanity checks on GSO packets") which uses the same physical adapters in SEA configurations. The issue occurs specifically when the hardware attempts to perform segmentation (gso_segs > 1) with a small MSS. Single-segment GSO packets (gso_segs == 1) do not trigger the problematic LSO code path and are transmitted normally without segmentation. Add an ndo_features_check callback to disable GSO when MSS < 224 bytes. Also call vlan_features_check() to ensure proper handling of VLAN packets, particularly QinQ (802.1ad) configurations where the hardware parser may not support certain offload features. Validated using iptables to force small MSS values. Without the fix, the adapter freezes. With the fix, packets are segmented in software and transmission succeeds. Comprehensive regression testing completedd (MSS tests, performance, stability).


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: io-wq: check that the predecessor is hashed in io_wq_remove_pending() io_wq_remove_pending() needs to fix up wq->hash_tail[] if the cancelled work was the tail of its hash bucket. When doing this, it checks whether the preceding entry in acct->work_list has the same hash value, but never checks that the predecessor is hashed at all. io_get_work_hash() is simply atomic_read(&work->flags) >> IO_WQ_HASH_SHIFT, and the hash bits are never set for non-hashed work, so it returns 0. Thus, when a hashed bucket-0 work is cancelled while a non-hashed work is its list predecessor, the check spuriously passes and a pointer to the non-hashed io_kiocb is stored in wq->hash_tail[0]. Because non-hashed work is dequeued via the fast path in io_get_next_work(), which never touches hash_tail[], the stale pointer is never cleared. Therefore, after the non-hashed io_kiocb completes and is freed back to req_cachep, wq->hash_tail[0] is a dangling pointer. The io_wq is per-task (tctx->io_wq) and survives ring open/close, so the dangling pointer persists for the lifetime of the task; the next hashed bucket-0 enqueue dereferences it in io_wq_insert_work() and wq_list_add_after() writes through freed memory. Add the missing io_wq_is_hashed() check so a non-hashed predecessor never inherits a hash_tail[] slot.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract_kvec_to_sg Patch series "Fix bugs in extract_iter_to_sg()", v3. Fix bugs in the kvec and user variants of extract_iter_to_sg. This series is growing due to useful remarks made by sashiko.dev. The main bugs are: - The length for an sglist entry when extracting from a kvec can exceed the number of bytes in the page. This is obviously not intended. - When extracting a user buffer the sglist is temporarily used as a scratch buffer for extracted page pointers. If the sglist already contains some elements this scratch buffer could overlap with existing entries in the sglist. The series adds test cases to the kunit_iov_iter test that demonstrate all of these bugs. Additionally, there is a memory leak fix for the test itself. The bugs were orignally introduced into kernel v6.3 where the function lived in fs/netfs/iterator.c. It was later moved to lib/scatterlist.c in v6.5. Thus the actual fix is only marked for backports to v6.5+. This patch (of 5): When extracting from a kvec to a scatterlist, do not cross page boundaries. The required length was already calculated but not used as intended. Adjust the copied length if the loop runs out of sglist entries without extracting everything. While there, return immediately from extract_iter_to_sg if there are no sglist entries at all. A subsequent commit will add kunit test cases that demonstrate that the patch is necessary.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: caam - guard HMAC key hex dumps in hash_digest_key Use print_hex_dump_devel() for dumping sensitive HMAC key bytes in hash_digest_key() to avoid leaking secrets at runtime when CONFIG_DYNAMIC_DEBUG is enabled.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying it to userspace IORING_OP_WAITID stores its result fields in struct io_waitid::info and later copies them to userspace siginfo. The prep path initializes the request arguments, but it does not initialize info itself. If the wait operation completes without reporting a child event, the common wait code can return without writing wo_info. In that case io_waitid_finish() still copies iw->info to userspace, exposing stale bytes from the reused io_kiocb command storage. Clear the result storage during prep so the io_uring path matches the regular waitid syscall, which uses a zero-initialized struct waitid_info.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: Only release RCU read lock after ct_ft When looking up a flow table in act_ct in tcf_ct_flow_table_get(), rhashtable_lookup_fast() internally opens and closes an RCU read critical section before returning ct_ft. The tcf_ct_flow_table_cleanup_work() can complete before refcount_inc_not_zero() is invoked on the returned ct_ft resulting in a UAF on the already freed ct_ft object. This vulnerability can lead to privilege escalation. Analysis from zdi-disclosures@trendmicro.com: When initializing act_ct, tcf_ct_init() is called, which internally triggers tcf_ct_flow_table_get(). static int tcf_ct_flow_table_get(struct net *net, struct tcf_ct_params *params) { struct zones_ht_key key = { .net = net, .zone = params->zone }; struct tcf_ct_flow_table *ct_ft; int err = -ENOMEM; mutex_lock(&zones_mutex); ct_ft = rhashtable_lookup_fast(&zones_ht, &key, zones_params); // [1] if (ct_ft && refcount_inc_not_zero(&ct_ft->ref)) // [2] goto out_unlock; ... } static __always_inline void *rhashtable_lookup_fast( struct rhashtable *ht, const void *key, const struct rhashtable_params params) { void *obj; rcu_read_lock(); obj = rhashtable_lookup(ht, key, params); rcu_read_unlock(); return obj; } At [1], rhashtable_lookup_fast() looks up and returns the corresponding ct_ft from zones_ht . The lookup is performed within an RCU read critical section through rcu_read_lock() / rcu_read_unlock(), which prevents the object from being freed. However, at the point of function return, rcu_read_unlock() has already been called, and there is nothing preventing ct_ft from being freed before reaching refcount_inc_not_zero(&ct_ft->ref) at [2]. This interval becomes the race window, during which ct_ft can be freed. Free Process: tcf_ct_flow_table_put() is executed through the path tcf_ct_cleanup() call_rcu() tcf_ct_params_free_rcu() tcf_ct_params_free() tcf_ct_flow_table_put(). static void tcf_ct_flow_table_put(struct tcf_ct_flow_table *ct_ft) { if (refcount_dec_and_test(&ct_ft->ref)) { rhashtable_remove_fast(&zones_ht, &ct_ft->node, zones_params); INIT_RCU_WORK(&ct_ft->rwork, tcf_ct_flow_table_cleanup_work); // [3] queue_rcu_work(act_ct_wq, &ct_ft->rwork); } } At [3], tcf_ct_flow_table_cleanup_work() is scheduled as RCU work static void tcf_ct_flow_table_cleanup_work(struct work_struct *work) { struct tcf_ct_flow_table *ct_ft; struct flow_block *block; ct_ft = container_of(to_rcu_work(work), struct tcf_ct_flow_table, rwork); nf_flow_table_free(&ct_ft->nf_ft); block = &ct_ft->nf_ft.flow_block; down_write(&ct_ft->nf_ft.flow_block_lock); WARN_ON(!list_empty(&block->cb_list)); up_write(&ct_ft->nf_ft.flow_block_lock); kfree(ct_ft); // [4] module_put(THIS_MODULE); } tcf_ct_flow_table_cleanup_work() frees ct_ft at [4]. When this function executes between [1] and [2], UAF occurs. This race condition has a very short race window, making it generally difficult to trigger. Therefore, to trigger the vulnerability an msleep(100) was inserted after[1]


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects a frame shorter than ETH_HLEN with -EINVAL, and returns -ENOMEM when build_skb() fails. Both paths jump to the err label without freeing the page that vhost_net_build_xdp() allocated for the frame. tap_sendmsg() discards the per-buffer return value and always returns 0, so vhost_tx_batch() takes the success path and never frees the page; each rejected frame in a batch leaks one page-frag chunk. Free the page on both error paths, before the skb is built. This is the tap counterpart of the same leak in tun_xdp_one().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cpu timers requires an additional step beyond setting the rlimit. Refactor the code so its clear when what code is setting the limit and conditionally update the posix cpu timers when appropriate.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_REREG_ACCESS changes from RO to RW then the umem has to be re-evaluated to ensure it is properly pinned as RW. Since the umem is hidden inside each driver's mr struct add a ib_umem_check_rereg() function that each driver has to call before processing IB_MR_REREG_ACCESS. mlx4 has to retain its duplicate ib_access_writable check because it implements IB_MR_REREG_ACCESS | IB_MR_REREG_TRANS by changing both items in place sequentially while the MR is live, so it will continue to not support this combination.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device. john1988 and Noam Rathaus reported that vti6_init_net() does not set the netns_immutable flag on the per-netns fallback tunnel device (ip6_vti0). Other similar tunnel drivers (like ip6_tunnel, sit, ip6_gre, and ip_tunnel) correctly set this flag during their fallback device initialization to prevent them from being moved to another network namespace.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access bt_sock_poll() walks the accept queue without synchronization, while child teardown can unlink the same socket and drop its last reference. The unsynchronized accept queue walk has existed since the initial Bluetooth import. Protect accept_q with a dedicated lock for queue updates and polling. Also rework bt_accept_dequeue() to take temporary child references under the queue lock before dropping it and locking the child socket.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysctl path can request the next SysV IPC id through ids->next_id. ipc_idr_alloc() currently forwards that request to idr_alloc() with an open-ended upper bound. If the valid tail of the SysV IPC id space is full, the allocation can spill beyond ipc_mni. The returned SysV IPC id still uses the normal index encoding, so later lookup and removal can target the wrong slot. This leaves the real IDR entry behind and breaks the IDR state for the object. The bug is in ipc_idr_alloc() in the checkpoint/restore path. 1. ids->next_id is passed to: idr_alloc(&ids->ipcs_idr, new, ipcid_to_idx(next_id), 0, ...) 2. The zero upper bound makes the allocation effectively open-ended. Once the valid SysV IPC tail is occupied, idr_alloc() can spill past ipc_mni and allocate an entry beyond the valid IPC id range. 3. The new object id is still encoded with the narrower SysV IPC index width: new->id = (new->seq << ipcmni_seq_shift()) + idx 4. Later removal goes through ipc_rmid(), which uses: ipcid_to_idx(ipcp->id) That truncates the real IDR index. An object actually stored at a high index can then be removed as if it lived at a low in-range index. 5. For shared memory, shm_destroy() frees the current object anyway, but the real high IDR slot is left behind as a dangling pointer. 6. A subsequent walk of /proc/sysvipc/shm reaches the stale IDR entry and dereferences freed memory. Prevent this by bounding the requested allocation to ipc_mni so the checkpoint/restore path fails once the valid range is exhausted.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb_carve helpers pskb_carve_inside_header() and pskb_carve_inside_nonlinear() both copy the old skb_shared_info header into a new buffer via memcpy(), which includes the destructor_arg pointer (uarg) for MSG_ZEROCOPY skbs. Neither function calls net_zcopy_get() for the new shinfo, creating an unaccounted holder: every skb_shared_info with destructor_arg set will call skb_zcopy_clear() once when freed, but the corresponding net_zcopy_get() was never called for the new copy. Repeated calls drive uarg->refcnt to zero prematurely, freeing ubuf_info_msgzc while TX skbs still hold live destructor_arg pointers. KASAN reports use-after-free on a freed ubuf_info_msgzc: BUG: KASAN: slab-use-after-free in skb_release_data+0x77b/0x810 Read of size 8 at addr ffff88801574d3e8 by task poc/220 Call Trace: skb_release_data+0x77b/0x810 kfree_skb_list_reason+0x13e/0x610 skb_release_data+0x4cd/0x810 sk_skb_reason_drop+0xf3/0x340 skb_queue_purge_reason+0x282/0x440 rds_tcp_inc_free+0x1e/0x30 rds_recvmsg+0x354/0x1780 __sys_recvmsg+0xdf/0x180 Allocated by task 219: msg_zerocopy_realloc+0x157/0x7b0 tcp_sendmsg_locked+0x2892/0x3ba0 Freed by task 219: ip_recv_error+0x74a/0xb10 tcp_recvmsg+0x475/0x530 The skb consuming the late access still referenced the same uarg via shinfo->destructor_arg copied by pskb_carve_inside_nonlinear() without a refcount bump. This has been verified to be reliably exploitable: a working proof-of-concept achieves full root privilege escalation from an unprivileged local user on a default kernel configuration. The fix follows the pattern of pskb_expand_head() which has the same memcpy/cloned structure. For pskb_carve_inside_header(), net_zcopy_get() is placed after skb_orphan_frags() succeeds, so the orphan error path needs no cleanup. For pskb_carve_inside_nonlinear(), net_zcopy_get() is placed after all failure points and just before skb_release_data(), so no error path needs cleanup at all -- matching pskb_expand_head() more closely and avoiding the need for a balancing net_zcopy_put().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. The received CRUSH map may optionally contain choose_args that get decoded in decode_choose_args(). In this function, num_choose_arg_maps is read from the message, and a corresponding number of crush_choose_arg_maps gets decoded afterwards. Each crush_choose_arg_map has a choose_args_index, which serves as the key when inserting it into the choose_args rbtree of the decoded crush_map. If a (potentially corrupted) message contains two crush_choose_arg_maps with the same index, the assertion in insert_choose_arg_map() triggers a kernel BUG when trying to insert the second crush_choose_arg_map. This patch fixes the issue by switching to the non-asserting rbtree insertion function and rejecting the message if the insertion fails. [ idryomov: changelog ]


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential null-ptr-deref in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. When decoding this CRUSH map in crush_decode(), an array of max_buckets CRUSH buckets is decoded, where some indices may not refer to actual buckets and are therefore set to NULL. The received CRUSH map may optionally contain choose_args that get decoded in decode_choose_args(). When decoding a crush_choose_arg_map, a series of choose_args for different buckets is decoded, with the bucket_index being read from the incoming message. It is only checked that the bucket index does not exceed max_buckets, but not that it doesn't point to an index with a NULL bucket. If a (potentially corrupted) message contains a crush_choose_arg_map including such a bucket_index, a null pointer dereference may occur in the subsequent processing when attempting to access the bucket with the given index. This patch fixes the issue by extending the affected check. Now, it is only attempted to access the bucket if it is not NULL.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ceph: fix a buffer leak in __ceph_setxattr() The old_blob in __ceph_setxattr() can store ci->i_xattrs.prealloc_blob value during the retry. However, it is never called the ceph_buffer_put() for the old_blob object. This patch fixes the issue of the buffer leak.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() kvm_reset_dirty_gfn() guards the gfn range with if (!memslot || (offset + __fls(mask)) >= memslot->npages) return; but offset is u64 and the addition is unchecked. The check can be silently bypassed by a u64 wrap. The dirty ring backing those entries is MAP_SHARED at KVM_DIRTY_LOG_PAGE_OFFSET of the vcpu fd, so the VMM can rewrite the slot and offset fields of any entry between when the kernel pushes them and when KVM_RESET_DIRTY_RINGS consumes them. On reset, kvm_dirty_ring_reset() re-reads the values via READ_ONCE() and feeds them straight back into this check; only the flags handshake is treated as the handover, the slot/offset payload is taken on trust. Crafting two entries entry[i].offset = 0xffffffffffffffc1 entry[i+1].offset = 0 makes the coalescing loop in kvm_dirty_ring_reset() compute delta = (s64)(0 - 0xffffffffffffffc1) = 63 which falls in [0, BITS_PER_LONG), so it folds entry[i+1] into the existing mask by setting bit 63. The trailing kvm_reset_dirty_gfn() call then sees offset = 0xffffffffffffffc1 and __fls(mask) = 63; the sum is 0 in u64 and the bounds check passes. That offset propagates into kvm_arch_mmu_enable_log_dirty_pt_masked() unchanged. On the legacy MMU path -- kvm_memslots_have_rmaps() == true, i.e. shadow paging, any VM that has allocated shadow roots, or a write-tracked slot -- it reaches gfn_to_rmap(), which indexes slot->arch.rmap[0][] with a near-U64_MAX gfn. That is an out-of-bounds load of a kvm_rmap_head, followed by a conditional clear of PT_WRITABLE_MASK in whatever the loaded pointer points at. The path is reachable from any process holding /dev/kvm. Range-check offset on its own first, so the addition cannot wrap. memslot->npages is bounded well below U64_MAX, so once offset < npages holds, offset + __fls(mask) (with __fls(mask) < BITS_PER_LONG) stays in range.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Cap AEAD AD length to 0x80000000 In order to prevent arithmetic overflows when checking the TX buffer size, cap the associated data length to 0x80000000.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver. ccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV buffer while RFC3686 skciphers expose an 8-byte IV, so the restore overruns the provided buffer. Use crypto_skcipher_ivsize() to copy only the algorithm's IV length.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate bg_bits during freefrag scan [BUG] A crafted filesystem can trigger an out-of-bounds bitmap walk when OCFS2_IOC_INFO is issued with OCFS2_INFO_FL_NON_COHERENT. BUG: KASAN: use-after-free in instrument_atomic_read include/linux/instrumented.h:68 [inline] BUG: KASAN: use-after-free in _test_bit include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline] BUG: KASAN: use-after-free in test_bit_le include/asm-generic/bitops/le.h:21 [inline] BUG: KASAN: use-after-free in ocfs2_info_freefrag_scan_chain fs/ocfs2/ioctl.c:495 [inline] BUG: KASAN: use-after-free in ocfs2_info_freefrag_scan_bitmap fs/ocfs2/ioctl.c:588 [inline] BUG: KASAN: use-after-free in ocfs2_info_handle_freefrag fs/ocfs2/ioctl.c:662 [inline] BUG: KASAN: use-after-free in ocfs2_info_handle_request+0x1c66/0x3370 fs/ocfs2/ioctl.c:754 Read of size 8 at addr ffff888031bce000 by task syz.0.636/1435 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0xbe/0x130 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xd1/0x650 mm/kasan/report.c:482 kasan_report+0xfb/0x140 mm/kasan/report.c:595 check_region_inline mm/kasan/generic.c:186 [inline] kasan_check_range+0x11c/0x200 mm/kasan/generic.c:200 __kasan_check_read+0x11/0x20 mm/kasan/shadow.c:31 instrument_atomic_read include/linux/instrumented.h:68 [inline] _test_bit include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline] test_bit_le include/asm-generic/bitops/le.h:21 [inline] ocfs2_info_freefrag_scan_chain fs/ocfs2/ioctl.c:495 [inline] ocfs2_info_freefrag_scan_bitmap fs/ocfs2/ioctl.c:588 [inline] ocfs2_info_handle_freefrag fs/ocfs2/ioctl.c:662 [inline] ocfs2_info_handle_request+0x1c66/0x3370 fs/ocfs2/ioctl.c:754 ocfs2_info_handle+0x18d/0x2a0 fs/ocfs2/ioctl.c:828 ocfs2_ioctl+0x632/0x6e0 fs/ocfs2/ioctl.c:913 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl fs/ioctl.c:583 [inline] __x64_sys_ioctl+0x197/0x1e0 fs/ioctl.c:583 ... [CAUSE] ocfs2_info_freefrag_scan_chain() uses on-disk bg_bits directly as the bitmap scan limit. The coherent path reads group descriptors through ocfs2_read_group_descriptor(), which validates the descriptor before use. The non-coherent path uses ocfs2_read_blocks_sync() instead and skips that validation, so an impossible bg_bits value can drive the bitmap walk past the end of the block. [FIX] Compute the bitmap capacity from the filesystem format with ocfs2_group_bitmap_size(), report descriptors whose bg_bits exceeds that limit, and clamp the scan to the computed capacity. This keeps the freefrag report going while avoiding reads beyond the buffer.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix listxattr handling when the buffer is full [BUG] If an OCFS2 inode has both inline and block-based xattrs, listxattr() can return a size larger than the caller's buffer when the inline names consume that buffer exactly. kernel BUG at mm/usercopy.c:102! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:usercopy_abort+0xb7/0xd0 mm/usercopy.c:102 Call Trace: __check_heap_object+0xe3/0x120 mm/slub.c:8243 check_heap_object mm/usercopy.c:196 [inline] __check_object_size mm/usercopy.c:250 [inline] __check_object_size+0x5c5/0x780 mm/usercopy.c:215 check_object_size include/linux/ucopysize.h:22 [inline] check_copy_size include/linux/ucopysize.h:59 [inline] copy_to_user include/linux/uaccess.h:219 [inline] listxattr+0xb0/0x170 fs/xattr.c:926 filename_listxattr fs/xattr.c:958 [inline] path_listxattrat+0x137/0x320 fs/xattr.c:988 __do_sys_listxattr fs/xattr.c:1001 [inline] __se_sys_listxattr fs/xattr.c:998 [inline] __x64_sys_listxattr+0x7f/0xd0 fs/xattr.c:998 ... [CAUSE] Commit 936b8834366e ("ocfs2: Refactor xattr list and remove ocfs2_xattr_handler().") replaced the old per-handler list accounting with ocfs2_xattr_list_entry(), but it kept using size == 0 to detect probe mode. That assumption stops being true once ocfs2_listxattr() finishes the inline-xattr pass. If the inline names fill the caller buffer exactly, the block-xattr pass runs with a non-NULL buffer and a remaining size of zero. ocfs2_xattr_list_entry() then skips the bounds check, keeps counting block names, and returns a positive size larger than the supplied buffer. [FIX] Detect probe mode by testing whether the destination buffer pointer is NULL instead of whether the remaining size is zero. That restores the pre-refactor behavior and matches the OCFS2 getxattr helpers. Once the remaining buffer reaches zero while more names are left, the block-xattr pass now returns -ERANGE instead of reporting a size larger than the allocated list buffer.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: qdsp6: topology: check widget type before accessing data Check widget type before accessing the private data, as this could a virtual widget which is no associated with a dsp graph, container and module. Accessing witout check could lead to incorrect memory access.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix clone_alias() to use the original device's devid Currently clone_alias() assumes first argument (pdev) is always the original device pointer. This function is called by pci_for_each_dma_alias() which based on topology decides to send original or alias device details in first argument. This meant that the source devid used to look up and copy the DTE may be incorrect, leading to wrong or stale DTE entries being propagated to alias device. Fix this by passing the original pdev as the opaque data argument to both the direct clone_alias() call and pci_for_each_dma_alias(). Inside clone_alias(), retrieve the original device from data and compute devid from it.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file acquires the lock first. A remote BLE device can send a crafted L2CAP ECRED reconfiguration response to corrupt the channel list while another thread is iterating it. Add l2cap_chan_hold() and l2cap_chan_lock() before l2cap_chan_del(), and l2cap_chan_unlock() and l2cap_chan_put() after, matching the pattern used in l2cap_ecred_conn_rsp() and l2cap_conn_del().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER When protocol sets HCI_PROTO_DEFER, hci_conn_request_evt() calls hci_connect_cfm(conn) without hdev->lock. Generally hci_connect_cfm() assumes it is held, and if conn is deleted concurrently -> UAF. Only SCO and ISO set HCI_PROTO_DEFER and only for defer setup listen, and HCI_EV_CONN_REQUEST is not generated for ISO. In the non-deferred listening socket code paths, hci_connect_cfm(conn) is called with hdev->lock held. Fix by holding the lock.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit When using the flushoncommit mount option, we can have a deadlock between a transaction commit and a reflink operation that copied an inline extent to an offset beyond the current i_size of the destination node. The deadlock happens like this: 1) Task A clones an inline extent from inode X to an offset of inode Y that is beyond Y's current i_size. This means we copied the inline extent's data to a folio of inode Y that is beyond its EOF, using a call to copy_inline_to_page(); 2) Task B starts a transaction commit and calls btrfs_start_delalloc_flush() to flush delalloc; 3) The delalloc flushing sees the new dirty folio of inode Y and when it attempts to flush it, it ends up at extent_writepage() and sees that the offset of the folio is beyond the i_size of inode Y, so it attempts to invalidate the folio by calling folio_invalidate(), which ends up at btrfs' folio invalidate callback - btrfs_invalidate_folio(). There it tries to lock the folio's range in inode Y's extent io tree, but it blocks since it's currently locked by task A - during a reflink we lock the inodes and the source and destination ranges after flushing all delalloc and waiting for ordered extent completion - after that we don't expect to have dirty folios in the ranges, the exception is if we have to copy an inline extent's data (because the destination offset is not zero); 4) Task A then attempts to start a transaction to update the inode item, and then it's blocked since the current transaction is in the TRANS_STATE_COMMIT_START state. Therefore task A has to wait for the current transaction to become unblocked (its state >= TRANS_STATE_UNBLOCKED). So task A is waiting for the transaction commit done by task B, and the later waiting on the extent lock of inode Y that is currently held by task A. Syzbot recently reported this with the following stack traces: INFO: task kworker/u8:7:1053 blocked for more than 143 seconds. Not tainted syzkaller #0 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kworker/u8:7 state:D stack:23520 pid:1053 tgid:1053 ppid:2 task_flags:0x4208060 flags:0x00080000 Workqueue: writeback wb_workfn (flush-btrfs-46) Call Trace: <TASK> context_switch kernel/sched/core.c:5298 [inline] __schedule+0x1553/0x5240 kernel/sched/core.c:6911 __schedule_loop kernel/sched/core.c:6993 [inline] schedule+0x164/0x360 kernel/sched/core.c:7008 wait_extent_bit fs/btrfs/extent-io-tree.c:811 [inline] btrfs_lock_extent_bits+0x59c/0x700 fs/btrfs/extent-io-tree.c:1914 btrfs_lock_extent fs/btrfs/extent-io-tree.h:152 [inline] btrfs_invalidate_folio+0x43d/0xc40 fs/btrfs/inode.c:7704 extent_writepage fs/btrfs/extent_io.c:1852 [inline] extent_write_cache_pages fs/btrfs/extent_io.c:2580 [inline] btrfs_writepages+0x12ff/0x2440 fs/btrfs/extent_io.c:2713 do_writepages+0x32e/0x550 mm/page-writeback.c:2554 __writeback_single_inode+0x133/0x11a0 fs/fs-writeback.c:1750 writeback_sb_inodes+0x995/0x19d0 fs/fs-writeback.c:2042 wb_writeback+0x456/0xb70 fs/fs-writeback.c:2227 wb_do_writeback fs/fs-writeback.c:2374 [inline] wb_workfn+0x41a/0xf60 fs/fs-writeback.c:2414 process_one_work kernel/workqueue.c:3276 [inline] process_scheduled_works+0xb6e/0x18c0 kernel/workqueue.c:3359 worker_thread+0xa53/0xfc0 kernel/workqueue.c:3440 kthread+0x388/0x470 kernel/kthread.c:436 ret_from_fork+0x51e/0xb90 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> INFO: task syz.4.64:6910 blocked for more than 143 seconds. Not tainted syzkaller #0 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:syz.4.64 state:D stack:22752 pid:6910 tgid: ---truncated---


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for block sizes >= 4G When the iommu is used the linearization of the mapping can give a single block that is very large split across multiple SG entries. When __rdma_block_iter_next() reassembles the split SG entries it is overflowing the 32 bit stack values and computed the wrong DMA addresses for blocks after the truncation. Use the right types to hold DMA addresses.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS record-chain walk loops [Why & How] All record-chain walk loops in bios_parser.c and bios_parser2.c use for(;;) and only terminate on a 0xFF record_type sentinel or zero record_size. A malformed VBIOS image missing the terminator record causes unbounded iteration at probe time, potentially hundreds of thousands of iterations with record_size=1. In the final iterations near the BIOS image boundary, struct casts beyond the 2-byte header validated by GET_IMAGE can also read out of bounds. Cap all 14 record-chain walk loops to BIOS_MAX_NUM_RECORD (256) iterations. The atombios.h defines up to 22 distinct record types and atomfirmware.h has 13. Assuming an average of less than 10 records per type (which is reasonable since most are connector- based) 256 is a generous upper bound. (cherry picked from commit 95700a3d660287ed657d6892f7be9ffc0e294a93)


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject oversized EMA RNR lists nl80211_parse_rnr_elems() stores the parsed element count in a u8-backed cfg80211_rnr_elems::cnt field and uses that count to size the flexible array allocation. Reject nested NL80211_ATTR_EMA_RNR_ELEMS input once the count reaches 255, before incrementing it again. This keeps the parser aligned with the data structure it fills and matches the existing bound check used by nl80211_parse_mbssid_elems().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: reject short frames before parsing A BNEP peer can send a short BNEP SDU. bnep_rx_frame() reads the packet type byte immediately and, for control packets, reads the control opcode and setup UUID-size byte before proving that those bytes are present. bnep_rx_control() also dereferences the control opcode without rejecting an empty control payload. Use skb_pull_data() for the fixed fields in bnep_rx_frame() so a NULL return gates each dereference. Split the control handler so the frame path can pass an opcode that has already been pulled, and keep the byte-buffer wrapper for extension control payloads. For BNEP_SETUP_CONN_REQ, name the UUID-size byte before pulling the setup payload. struct bnep_setup_conn_req carries destination and source service UUIDs after that byte, each uuid_size bytes, so the parser now documents that tuple explicitly instead of leaving the pull length as an opaque multiplication. Validation reproduced this kernel report: KASAN slab-out-of-bounds in bnep_rx_frame.isra.0+0x130c/0x1790 The buggy address belongs to the object at ffff88800c0f7908 which belongs to the cache kmalloc-8 of size 8 The buggy address is located 0 bytes to the right of allocated 1-byte region [ffff88800c0f7908, ffff88800c0f7909) Read of size 1 Call trace: dump_stack_lvl+0xb3/0x140 (?:?) print_address_description+0x57/0x3a0 (?:?) bnep_rx_frame+0x130c/0x1790 (net/bluetooth/bnep/core.c:306) print_report+0xb9/0x2b0 (?:?) __virt_addr_valid+0x1ba/0x3a0 (?:?) srso_alias_return_thunk+0x5/0xfbef5 (?:?) kasan_addr_to_slab+0x21/0x60 (?:?) kasan_report+0xe0/0x110 (?:?) process_one_work+0xfce/0x17e0 (kernel/workqueue.c:3200) worker_thread+0x65c/0xe40 (?:?) __kthread_parkme+0x184/0x230 (?:?) kthread+0x35e/0x470 (?:?) _raw_spin_unlock_irq+0x28/0x50 (?:?) ret_from_fork+0x586/0x870 (?:?) __switch_to+0x74f/0xdc0 (?:?) ret_from_fork_asm+0x1a/0x30 (?:?)


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption Commit 60f030f7418d ("iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE") fixed a NULL pointer dereference in an unlikely situation partly. If dev_pasid is not found in the dev_pasids list, it remains NULL. However, the teardown operations are executed unconditionally, this lead to a NULL pointer dereference or refcount corruption. If the domain was never attached to this IOMMU, info will be NULL, which would cause an immediate dereference when checking --info->refcnt. Even if info is not NULL, decrementing the refcount without having removed a valid PASID might unbalance the count. This could lead to premature dropping of the refcount to 0, potentially causing a use-after-free for the remaining active devices sharing the domain. Fix it by returning early if dev_pasid is NULL, before executing the teardown operations. Issue found by AI review and suggested by Kevin Tian. https://sashiko.dev/#/patchset/20260421031347.1408890-1-zhenzhong.duan%40intel.com


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: audit: fix incorrect inheritable capability in CAPSET records __audit_log_capset() records the effective capability set into the inheritable field due to a copy-paste error. Every CAPSET audit record therefore reports cap_pi (process inheritable) with the value of cap_effective instead of cap_inheritable. This silently corrupts audit data used for compliance and forensic analysis: an attacker who modifies inheritable capabilities to prepare for a privilege-escalating exec would have the change masked in the audit trail. The bug has been present since the original introduction of CAPSET audit records in 2008.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. The rmap_remove() call would miss entries created after the PDE change because the GFN of the leaf SPTE does not match the GFN of the struct kvm_mmu_page. A similar hole however remains if the modified PDE points to a non-leaf page. In this case the gfn can be made to match, but the role does not match: the original large 2MB page creates a kvm_mmu_page with direct=1, while the new 4KB needs a kvm_mmu_page with direct=0. However, kvm_mmu_get_child_sp() does not compare the role, and therefore reuses the page. The next step is installing a leaf (4KB) SPTE on the new path which records an rmap entry under the gfn resolved by the walk. But when that child is zapped its parent kvm_mmu_page has direct=1 and kvm_mmu_page_get_gfn() computes the gfn for the 4KB page as sp->gfn + index instead of using sp->shadowed_translation[] (or sp->gfns[] in older kernels). It therefore fails to remove the recorded entry. When the memslot is dropped the shadow page is freed but the rmap entry survives, as in the scenario that was already fixed. Code that later walks that gfn (dirty logging, MMU notifier invalidation, and so on) dereferences an sptep that lies in the freed page, causing the use-after-free.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1
SUSE Real Time Module 15 SP7:cluster-md-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:dlm-kmp-rt-6.4.0-150700.7.62.1
SUSE Real Time Module 15 SP7:gfs2-kmp-rt-6.4.0-150700.7.62.1

Ссылки